South Korea bank data breach: Same hacker behind 7 attacks?

Shinhan, KB Kookmin and Hana confirmed leaks as President Lee ordered a probe into financial cyberattacks

|
Published October 04, 2026
South Korea bank data breach: Same hacker behind 7 attacks?

The way in wasn't a mobile app or a customer login. It was a service built for loan agents. Shinhan Bank says an unauthorised party bypassed authentication there and walked out with data on about 25,000 customers.

That was the start of a South Korea bank data breach that has now reached the president's desk. On Sunday, President Lee Jae Myung ordered a thorough investigation and response measures across banks, finance companies and public agencies. Shinhan reported its breach on September 30.

Others followed within days. KB Kookmin said 119 customers were affected through a mobile system used by its employees, while Hana Bank reported 89 after an attack on its sales support system. Woori and NH NongHyup say they were targeted but stopped the intruders.

Then it moved down the ladder. Hyundai Capital reported leaks involving 146 housing loan agents, and local media put the toll at roughly 40,000 customers at Yegaram Savings Bank. Authorities say IP addresses tied to the same attacker turned up at seven firms.

Was AI behind the attacks?

Chairman Lee Eog-weon of the Financial Services Commission advocates "attacks on AI defended by AI", while South Korean media outlets mention that artificial intelligence agents have been employed against the less secure system.

According to Yonhap, the traffic originated from Internet Protocol addresses in the US, Japan, Singapore, Vietnam and Britain. It is likely that the regulators see an effort to locate vulnerable points in the network instead of singling out any particular bank. The People Power Party demands to investigate North Korea's possible participation in the attack despite the lack of such evidence in available reports.

FSC instructs financial institutions to perform a security check-up, tighten the access control and limit external access to their systems. Types of attacks and IP addresses will be exchanged in the industry.

The emergency meeting scheduled for October 7 was moved up to Sunday due to new cases of attack revealed among small lenders.

Pareesa Afreen
Pareesa Afreen is a reporter and sub editor specialising in technology coverage, with 3 years of experience. She reports on digital innovation, gadgets, and emerging tech trends while ensuring clarity and accuracy through her editorial role, delivering accessible and engaging stories for a fast-evolving digital audience.
Share this story: