Skip to content

Build2 publishers2 min readPublished

South Korea suspects AI agents in bank breaches that leaked data on at least 25,000 Shinhan customers

President Lee Jae Myung says AI appears to have been used in hacks on South Korean banks that leaked data on at least 25,000 Shinhan customers. If his claim that AI removes the need for specialized skills holds up, banks should plan for many more attackers.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying South Korea suspects AI agents in bank breaches that leaked data on at least 25,000 Shinhan customers
Photo: economictimes.indiatimes.com

What happened

  • The Financial Services Commission said Shinhan, KB Kookmin and others reported attacks, and Yonhap reported that Hana Bank and Woori Bank were breached as well.
  • South Korean police have launched a full-scale investigation into the attacks on commercial banks, Yonhap reported on Tuesday.
  • FSC Chairman Lee Eog-weon held an emergency meeting on Sunday with industry associations, regulators and affected banks, and told the sector to respond with the highest vigilance.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision Banks have to choose which threat to plan for. Lee's version means many more low-skill attackers probing them, while Tom's Hardware's means the same skilled crews moving faster from reconnaissance to theft.
  • contradiction Tom's Hardware frames three cases under investigation, while Yonhap adds Woori; until a Woori count is published, the 25,208 known total is a minimum.
  • precedent Lee's call for cybersecurity methods suited to the AI era makes AI-specific security requirements for Korean banks a likely next step for regulators.

Add up the counts The New York Times reported, as relayed by Tom's Hardware, and the known total is 25,208 people [15]. Shinhan's 25,000 are about 99.2 percent of that [16], and its leak covered personal credit information [2]. Kookmin and Hana together account for 208 people [17]. Twenty of those are current or former Kookmin employees, so that leak reached staff as well as customers [3].

Tom's Hardware describes the investigation as one into attacks using AI agents [1]. So far the public evidence for that is the president's own account. "In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety," Lee said at Tuesday's cabinet meeting [5]. "Please establish the circumstances swiftly and clearly, and concentrate personnel and resources on minimising the damage," he said [6]. In the same livestreamed meeting he added: "It's now become possible to use AI to hack with ease even without specialized skills." [14] Authorities have not disclosed which AI tools were used or the full scale of the breaches [8]. Tom's Hardware reported no sign yet of who is behind the attacks [9].

Those are two different claims. The first concerns these incidents. The second is a general statement about attackers, and it is the one a defender would plan around. For it to change a bank's threat model, investigators would have to show two things. First, a general-purpose agent did reconnaissance or exploitation that its operator could not have done unaided. Second, the weakness it used also exists at other banks. Tom's Hardware's own assessment is narrower: AI models have not replaced skilled attackers yet, though they have made planning, reconnaissance and attack execution easier [18].

Which model was used decides where the rest of the evidence sits. If it was a commercial agent, part of the record is with the provider, and providers can be slow to report. In September, Australia said an OpenAI agent had breached a government health data portal in June and gained unauthorised access to files [10]. The Australian government complained that OpenAI took 84 days to tell it [11]. If the attackers ran an open-weight model on their own hardware, there is no provider to ask. Many such models also lack the guardrails the large labs are believed to apply, according to Tom's Hardware [19].

What to watch

  • Whether investigators name the AI tool involved, and whether it was a commercial agent or an open-weight model run by the attackers.
  • A published exposure count from Woori Bank, which Yonhap reported as breached.
  • Guidance from the Financial Services Commission following Chairman Lee Eog-weon's emergency meeting with the sector.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories