Invest1 publisher3 min readPublished
Customers of seven hacked Korean lenders start recruiting for class-action suits
Victims of breaches at seven Korean lenders, Shinhan Bank among them, are recruiting members for class-action damages suits. With suspects in earlier Korean data cases still uncaught, the lenders look like the only parties those suits can reach.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The National Police Agency's Cyber Bureau is tracking traces of Artex AI, a Chinese-language open-source penetration-testing tool on GitHub, at addresses used to attack the banks.
- The attackers routed their traffic through overseas IP addresses, and authorities plan to seek international cooperation to identify them.
- Police probing SK Telecom's April 2025 USIM leak have reportedly traced over 100 IP addresses with 31 IT companies in 14 countries and still have no suspect.
- Police have suspects in the KT micropayment and Coupang data cases, but those suspects are widely expected to stay out of custody.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure Because suspects in Korean data cases are seldom caught, Shinhan, KB Kookmin, Hana and the other four firms carry the civil exposure on their own balance sheets.
- constraint Until the other five firms publish tolls and a filed suit names a damages figure, any reserve estimate for these lenders rests on two data points.
- precedent If attack tools are on sale to anyone who pays, the list of seven can lengthen, so breach frequency becomes a risk for every Korean lender holding customer data.
The damages claims will land on the lenders. Victims are organising to sue over the companies' failure to protect their information [3], and the police record on earlier breaches leaves the companies as the only party within reach. "In data leak investigations, even when we manage to find traces of the crime, identifying a suspect is very difficult," a police official said [9]. "We also have to weigh the risk of diplomatic friction during the investigation." [9]
Shinhan Bank's roughly 25,700 affected customers and Yegaram Savings Bank's roughly 40,000 [2] add up to about 65,700 people at two of the seven firms [13]. The larger toll, about 1.56 times Shinhan's [14], belongs to a savings bank. The reporting does not include a damages demand, a per-person figure or counts for the other five [15]. The suits are still at the recruiting stage [3]. "People in the same situation need to at least pool information," said a victim who opened an online community for a class action over the Shinhan breach on Friday [4].
The cost to price is the damages bill, or rather the number of lenders that end up owing one. If recruitment stalls, the bill stays inside each firm's own security spending. If the suits go ahead, the strongest claim of harm is the one Hwang Seong-ho, head of NordVPN's Korea branch, described. "This incident is very concerning in that previously leaked personal information can be combined with financial information," he said [10]. The third outcome is that seven becomes a larger number, since seven is only the count so far [1]. "Even without the skills, anyone who pays can use attack tools," said a software developer at one of Korea's five largest brokerages [16].
I think the third outcome matters most for anyone holding Korean lenders, because the toll at any one firm has an upper limit and the frequency of attacks across the sector does not. The counter-case is scale: about 65,700 people at two firms [13] may settle for modest sums, and a suit recruited through an online community may never be filed [4].
The AI label matters less than the coverage suggests. "It has not been confirmed whether Artex was the only tool used in the attacks, so no one should conclude at this point that 'Chinese AI did the hacking,'" said Kim Seung-joo, a professor at Korea University's Graduate School of Information Security [6]. "Whether AI was used is not the point," Kim said [11]. In my view a claim built on the companies' failure to protect data [3] will turn on the defences the attackers got through, whatever tool they carried. This view is wrong if police identify a suspect who can be held to account, or if the recruiting drives fold before any suit is filed.
What to watch
- Customer counts from KB Kookmin, Hana, BNK Busan, Welcome Savings Bank and Hyundai Capital, which would show whether the two known tolls are typical.
- An eighth Korean financial firm reporting a breach linked to the same attack infrastructure.
- The per-person damages demand in the first class action actually filed against Shinhan Bank or another of the seven.