Skip to content

Invest2 publishers3 min readPublished

Korean police need a financial regulator's ruling to decide who investigates the Shinhan Bank hack

Korea's National Police Agency booked the AI-driven attack on Shinhan Bank as a criminal case and assigned 28 cyberterrorism investigators to it. Whether the case moves to the new Serious Crimes Investigation Agency turns on how the Financial Services Commission classifies the bank's system.

The Investor · Invest desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying Korean police need a financial regulator's ruling to decide who investigates the Shinhan Bank hack
Photo: koreajoongangdaily.com

What happened

  • The case was booked under the Information and Communications Network Act and handed to four teams from the police cyberterrorism investigation unit.
  • By Tuesday the Financial Supervisory Service had tied the attack to 19 IP addresses spread over 12 countries, among them the United States, Japan, Hong Kong, Singapore and Vietnam.
  • Some pointed at China because of traces left by Artex AI, a penetration-testing tool in the Chinese language. Experts cited by the Korea JoongAng Daily say the tool, which is open source, cannot reveal who the attacker is.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • precedent The commission's reading of electronic financial infrastructure will set whether later AI-driven attacks on bank systems go to the SCIA by rule, so its answer reaches past Shinhan.
  • constraint Whichever agency holds the file, tracing addresses spread across 12 countries depends on foreign authorities, so a referral to the SCIA does not by itself shorten the trace.
  • cost Four teams of seven on one bank case is a staffing level the police could not repeat for each of the roughly seven breach reports KISA receives a day.

"If the affected system qualifies as electronic financial infrastructure under the Electronic Financial Transactions Act, the case must be reported to the SCIA," a police official said, according to the Korea JoongAng Daily [5]. "We have asked the Financial Services Commission for an official interpretation of whether the system qualifies," the official said [6]. The charge already filed comes under a different law, the network act [2]. So which agency runs a criminal case now depends on a financial regulator reading a financial statute [6]. The Serious Crimes Investigation Agency launched on Friday with cybercrime in its remit [4], four days before the case was booked [13]. The Sept. 28 attack came about three days before the agency existed [15].

If the commission says the system qualifies, referral is mandatory on the official's account [5]. If it says no, the file stays with the National Office of Investigation [3] and its four teams of seven [14]. A third outcome holds either way. Investigators are working with foreign authorities to track the addresses located overseas [8], and that work is the same whichever Korean agency holds the file.

I think the commission's answer matters more for the next attack than for this one. The referral test is written into statute [5]. A yes would send AI-driven attacks on any bank system that meets the same definition to the SCIA. A no would keep them with the police as network-act cases [2]. The counter-case is that attribution decides whether anyone is ever charged, and attribution runs through foreign cooperation regardless [8]. The view is wrong if the commission's interpretation turns on features of this one system, leaving the next bank's system to be classified from scratch.

The report does not identify the attacker or say what, if anything, was taken from Shinhan Bank [1]. With the Artex AI traces discounted [9], identification rests on the address trace [8]. The 28 investigators assigned [2] compare with a national flow of about seven breach reports a day. The Korea Internet & Security Agency received 1,236 reports in the first half of this year, up 19.5 percent [12], from roughly 1,034 a year earlier [16].

IBM's Cost of a Data Breach Report 2026 found AI involved in one in four malicious breaches at 602 organizations between March 2025 and February 2026, a share up 56 percent on the previous year [11]. That puts the prior year at roughly 16 percent [17]. "Hackers attack every security vulnerability they can find, and AI makes them dramatically faster," said Kwak Jin, a professor of cybersecurity at Ajou University [10]. "A breach at even one point means data gets out, so the burden on defenders can only grow." [10]

What to watch

  • The Financial Services Commission's official interpretation of whether Shinhan Bank's affected system counts as electronic financial infrastructure, and whether the case then goes to the SCIA.
  • Whether foreign authorities in any of the 12 countries, which include the United States and Japan, return enough on the 19 addresses to identify an operator.
  • Any disclosure from Shinhan Bank or the Financial Supervisory Service of what, if anything, the attack took.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories