Skip to content

Invest1 publisher2 min readPublished

AI-linked hackers reached Korean bank customer data through staff and broker tools

Korea's Financial Services Commission ordered a sector-wide security review after suspected AI-agent hackers hit the country's five largest banks. The three biggest leaks ran through employee, sales and broker tools, so the review's cost lands on systems customers never see.

The Investor · Invest desk

Photograph accompanying AI-linked hackers reached Korean bank customer data through staff and broker tools
Photo: koreajoongangdaily.com

What happened

  • At KB Kookmin, an AI agent is believed to have hacked an employee mobile work system and reached customers' names, phone numbers, addresses and encrypted resident numbers.
  • Hana Bank said an external hacking agent tried to break into its sales support system, and the attempt leaked the personal information of 89 customers.
  • Shinhan Bank disclosed on Thursday that hackers got into a service used only by loan brokers, exposing data on more than 25,000 customers.
  • BNK Financial Group reported 11 cases of exposed client data, while Woori and NH Nonghyup said no customer information leaked.
  • The FSC told firms to list and test every outward-facing IT asset, AI systems included, and to find any path into internal data that skips authentication.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • cost The review covers the whole financial industry, so firms that reported no leak, Woori and NH Nonghyup among them, still pay to inventory and test their outward-facing systems.
  • decision Banks now have to split security money between customer banking apps, which held, and the employee, sales and broker tools through which the data actually left.
  • capability Pooling attack IP addresses and intrusion logs with KISA lets one bank's intrusion record warn the others, provided the same attackers reused infrastructure across banks.

One channel accounts for almost all of the disclosed exposure. KB Kookmin's 119 customers [2] and Hana's 89 [5] come to 208 [1]. Shinhan's broker-only service gave up data on more than 25,000 [8], about 120 times those two cases combined [2], and even with BNK's 11 cases [7] counted, Shinhan accounts for more than 99% of the disclosed total [3].

The AI attribution gets thinner at the level of each bank. Korea JoongAng Daily, which reported the series, describes AI agents repeatedly probing employee mobile platforms, sales support tools and loan broker services [15]. In KB's case the paper says an AI agent is believed to have done the hacking [3]. Hana's statement refers to "an external hacking agent" [5]. Shinhan's disclosure, as reported, refers only to hackers [8].

For budgets, the entry point matters more than the attacker. The customer channels held: the paper reports that the attackers failed to reach financial transaction data [15], and KB's breach did not involve internet or mobile banking [3]. The data left through systems behind staff logins, or rather, in Shinhan's case, behind broker logins [8], and that layer is what the FSC's checklist targets [10]. KB shut the affected server and blocked the access route after spotting signs of a leak on Wednesday [4].

The cost depends on what the regulator finds when it looks for a pattern in the attacks [9]. If the attackers used one shared weakness, the fix is a single patch and a small bill. If the agents worked through many small gaps across many systems, the asset inventory becomes recurring spending on every outward-facing staff tool. And if lawmakers at this month's National Assembly audit [13] weigh failures by record count, Shinhan's 25,000 sets the political price and the agent cases become a footnote.

I'd expect the second outcome. The checklist is open-ended by design [10], and Secretary General Shin Jin-chang, who chaired Friday's emergency meeting [9], said the commission would "thoroughly analyze the causes of the breaches and the methods used in the attacks and develop the necessary regulatory measures" [12]. The banks did not disclose remediation costs. The view is wrong if the review finds entry points in customer apps too, or if the methods turn out to involve no autonomous element. Either finding would put the spending back into routine patching.

Park Sang-hyuk, a Democratic Party lawmaker on the National Assembly's National Policy Committee, posted on Facebook on Friday: "We cannot simply watch as customer data is repeatedly leaked from banks entrusted with the public's assets and credit information." [14]

What to watch

  • Whether the FSC's analysis of causes and attack methods finds a single entry pattern shared across the five banks or many separate gaps.
  • How lawmakers at this month's National Assembly audit treat Shinhan's 25,000-plus broker-channel exposure next to the smaller agent-linked cases.
  • Whether any bank or secondary financial firm reports new leaks or remediation spending once its externally reachable systems are inventoried.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories