South Korea’s financial-sector update on October 7 listed nine firms with reported breaches. Authorities had received no reports of additional leaks through their checks by that point, while police investigated suspected attacks. President Lee Jae Myung said signs suggested AI models might have been used in some of them.

South Korea’s October 7 breach update

The nine firms listed were KB Kookmin Bank, Shinhan Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank, Hyundai Capital, PFCT and Mooda. The update described the status of checks as of October 7; authorities were still analyzing results.

Reported impact at three banks

The reported affected populations differed across Shinhan Bank, KB Kookmin Bank and Hana Bank. For KB Kookmin Bank, the reported total included both customers and employees.

BankReported affected populationSystem described
Shinhan Bank25,729 customersA service used by loan agents to check application status
KB Kookmin Bank119 people: 99 customers and 20 current or former employeesEmployee mobile-support system
Hana Bank89 customersSales-support system

Reported information involved different categories at each bank. For Shinhan Bank, those included names, phone numbers, annual income, loan limits and other loan-application information. Information reported exposed at Hana Bank included names, addresses, email addresses, phone numbers, workplace information and resident registration numbers.

Police investigate possible AI involvement

The Korean National Police Agency opened a full-scale investigation into suspected attacks on financial institutions and assigned 28 investigators across four teams. Lee Jae Myung said signs indicated that AI models might have been used and directed his cabinet to establish what happened and limit harm.

The Financial Supervisory Service shared 28 distinct IP addresses linked to attempted attacks with financial firms for security checks. The checks were part of a wider review of the financial sector, with remaining categories scheduled to complete them by October 8.

The systems described in the reports

The reported incidents involved employee or business-support systems, including mobile support for bank staff, loan-agent tools and sales-support services. At KB Kookmin Bank and Hana Bank, the affected systems were separate from internet and mobile banking transaction platforms. Both banks said no customer transaction information had been leaked from those systems.