P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Korea's bank breaches: AI use is unconfirmed on the record, and the faults described are old ones

Three Korean bank notices name about 25,000, 99 and 89 customers, and none of them mentions AI. The regulator says AI use cannot be ruled out; the faults officials describe are missing identity checks, neglected side systems and unpatched web flaws.

By Parminder Kumar Sharma · · 21 min read

A dark bank back-office after hours: a laptop open on an incident board of blank rounded tiles, a row of them hollow amber outlines, in front of a closed server rack, with an empty banking hall visible through a glass wall.

25,000, 99, 89 and 11

Four Korean banks have said how many people were affected, and the numbers are not close. Shinhan Bank's notice, dated Thursday 1 October, says about 25,000 customers. KB Kookmin's notice, dated 2 October, says 99 customers and 20 current or former staff. Hana's notice, dated 3 October, says 89 customers. BNK Busan has told the press 11 outsourced developers and no customers. Add the customers the three notices name and the total is about 25,188 (derived: 25,000 + 99 + 89, approximate because Shinhan says "about"). Shinhan is 99.3 per cent of it, and about 253 times KB Kookmin's customer count. The figure often printed for KB Kookmin, 119 customers, is the notice's 99 customers plus its 20 staff.

What the spread suggests, as inference. The count follows the system that was exposed, not the attacker's skill. A lookup service that answers any caller who supplies the right inputs can return tens of thousands of records. A staff app behind a login returns what the few accounts that got in could see. The Korean authorities' own description of the faults, below, fits that reading. The numbers do not prove it.

What that does not establish. It does not show that the incidents share a cause or an actor: the head of the Financial Security Institute, the sector's security agency, said on 4 October that the attacker addresses were almost identical at the four banks and different at the savings banks, and that one person cannot be concluded from that. It does not show that an AI tool was used: the same official said AI use is presumed, not confirmed, and that no direct trace of an AI agent has been confirmed. It does not name the flaw at any bank, say whether data was only exposed or carried away, or make any count final. The claim that travelled furthest in English, a named Chinese AI penetration-testing tool, began as one security vendor's reading of a page title and was repeated by an unnamed official. The officials on the record were more careful.

This site has tested other claims that an attacker was an AI agent. DIVD's claim rested on tempo and code comments, and its root cause was two ordinary product flaws. Microsoft's Azure evidence said automated or scripted, and the agentic label came from a vendor's report. Gambit's 27 compromised companies were 48 projects minus 21 that never left reconnaissance. The method here is the same: find who said it, and what they said.

What each bank published, in its own words

The three notices were read in Korean on the banks' own sites on 5 October. They are short, and they differ from the press accounts in ways that matter.

What the four banks have said, and where each statement sits. Notices read at about 07:45 to 08:00 BST on 5 October 2026; BNK Busan from press reports of its statement.

  1. Bank and statement
    Shinhan: notice dated 1 Oct, shinhan.com
    People named
    About 25,000 customers. Items: name, phone, CI (a linked identifier), annual income, calculated loan limit
    System, as the bank puts it
    "Some services", reached from outside by an "abnormal method". No system or mechanism named
    Mentions AI?
    No
  2. Bank and statement
    KB Kookmin: notice dated 2 Oct, kbstar.com
    People named
    99 customers and 20 current or former staff, confirmed 30 Sep
    System, as the bank puts it
    The staff mobile work-support system, unrelated to internet banking
    Mentions AI?
    No
  3. Bank and statement
    Hana: notice dated 3 Oct, hanabank.com
    People named
    89 customers. Items include resident registration number, name, address, contact details, workplace
    System, as the bank puts it
    Illegal intrusion into the sales-support system on 30 Sep, confirmed 2 Oct; separate from internet and mobile banking
    Mentions AI?
    No
  4. Bank and statement
    BNK Busan: statement to the press, 2 Oct. No notice found
    People named
    11 outsourced developers. No customers
    System, as the bank puts it
    Some web pages with insufficient session verification
    Mentions AI?
    Yes: an attempt "using an AI agent" at about 21:00 on 1 Oct, main attack blocked

Three things the table shows. First, none of the three notices says AI, a tool, a scanner or a technique. The Korean press sometimes says otherwise: Hankook Ilbo wrote on 2 October that Shinhan itself had said an AI agent was used, and Shinhan's notice does not say that. Second, the 66 resident registration numbers and 97 linked identifiers reported for Shinhan, and the exact figure of 25,727 (News1) or 25,729 (Herald, Financial News), come from press accounts of the bank's reports to the authorities, not from the notice, which says about 25,000. Third, only Busan's account mentions AI, and it is a bank describing an attempt it says it mostly blocked, not an attribution of the leak.

The clocks: 15 hours, 42 hours and 68 hours

The notices give dates. The times come from the banks' incident reports to the National Assembly, which News1 relayed on 5 October. The reports themselves were not read, so every bar and diamond in the diagram is secondary and is labelled that way.

Timeline in Korea time from 27 September to 7 October 2026. Shinhan's attacker contact ran 28 September 18:04 to 30 September 00:15 and the bank noticed after 15 hours 26 minutes; notice dated 1 October, about 25,000 customers. KB Kookmin's ran 27 September 23:19 to 29 September 18:00, noticed after 67 hours 41 minutes; notice 2 October, 99 customers and 20 staff. Hana's ran 30 September, noticed 2 October; notice 3 October, 89 customers. Busan: 11 developers. FSC meetings 47 hours apart.
Drawn from the banks' own notices (dates), the FSC and FSS releases (meetings) and News1's account of the banks' incident reports to the National Assembly (windows and detection times, not read directly).

Derived from those times. Shinhan noticed the attack 15 hours 26 minutes after the first attacker address appeared (28 September 18:04 to 29 September 09:30). By News1's account it blocked the address at once, shut the targeted service at 13:43, and saw a second wave with new addresses begin at 20:30; the last address was blocked at 00:15 on 30 September, 30 hours 11 minutes after the first. KB Kookmin's contact lasted 42 hours 41 minutes, and the bank noticed at about 19:00 on 30 September, 67 hours 41 minutes after it began and 25 hours after it ended. Hana's lasted 10 hours 36 minutes, and the bank confirmed the leak 41 hours 44 minutes after it began. Shinhan's and KB Kookmin's windows overlapped for 23 hours 56 minutes (28 September 18:04 to 29 September 18:00). News1 reads that as an attacker working several firms at once rather than one after another. That reading is inference from reports we have not seen.

The public clocks. The FSC's 4 October release says Shinhan's incident report reached the supervisors on 30 September, which is between about 14 and 38 hours after the bank first noticed (derived; the time of the report is not stated). Shinhan's notice followed on 1 October. From first notice to last of the four is 2 days (1 to 3 October). The two FSC meetings are 47 hours apart, 15:00 on 2 October and 14:00 on 4 October. For a defender the useful comparison is the detection clock, not the AI label: 15, 42 and 68 hours between first contact and the bank knowing, on systems that the regulator describes as having had less management attention.

Seven firms, and what the authorities did

Press tallies list seven firms with confirmed leaks: the four banks, Yegaram Savings Bank (about 40,000 customers, an estimate in its 3 October notice as reported), Hyundai Capital (146 housing-loan recruiters) and Welcome Savings Bank (up to 2,200 corporate-client records). Financial News puts the people at about 66,000, which checks out: 25,729 + 40,000 + 119 + 89 + 146 + 11 = 66,094 (derived, Welcome's records excluded). Woori Bank and NH NongHyup were targeted and report no leak. Yegaram, Welcome and Hyundai Capital were read only through the press.

Two releases, read in Korean, are the official record of the response. On 2 October at 15:00 the FSC's secretary-general chaired an emergency meeting and ordered banks and card issuers to start checking all externally exposed IT systems and services at once, customer-facing or not, and their authentication and access control. On 4 October at 14:00 the FSC chairman and the FSS met all sectors, with the science ministry, the Personal Information Protection Commission (PIPC) and the National Police Agency present. That release extends the check to every sector, says external access should be blocked unless essential, and warns that firms which ignore shared attack information and then suffer a similar incident will be held to account. According to Sidae, the FSS sent 25 attacker addresses and a 12-item checklist to about 500 firms, due back by 6 October for banks and card issuers and 8 October for the rest.

The presidential office said on 4 October, as Yonhap quoted its spokesperson, that the president had been briefed on leaks at financial and public institutions and ordered a thorough investigation. It did not mention AI. The phrase "as AI-powered cyberattacks increasingly target them" in the Korea Times piece that DataBreaches.net relayed is the newspaper's. The police cyber terror response unit opened a pre-charge inquiry on 2 October, Shinhan's from 1 October, according to press reports of a police briefing; no police statement about a tool was found. The PIPC's press list showed nothing on the banks at 08:15 BST.

Who said AI, and what they said

The AI claim has a short chain, and each link is weaker or stronger than the headline. The table orders it by what each source is.

Statements about AI and tools, 1 to 5 October 2026, by source. Korean statements read in Korean; paraphrases are ours and quotes are short.

  1. Source and date (KST)
    Shinhan, KB Kookmin and Hana notices, 1 to 3 Oct
    What was said
    Nothing about AI or any tool
    Standing
    First-hand, read in full
  2. Source and date (KST)
    BNK Busan, statement to the press, 2 Oct
    What was said
    An attempt "using an AI agent" at about 21:00 on 1 Oct, mostly blocked
    Standing
    Bank statement relayed by a newspaper
  3. Source and date (KST)
    Head of a security vendor's research centre (Genians), LinkedIn post, 2 Oct
    What was said
    A page title on a web server used in credential-stuffing attacks on several Korean targets read ARTEX, autonomous penetration test console, in Chinese: a circumstance showing a possibility
    Standing
    One person's reading; post seen only through press quotes
  4. Source and date (KST)
    Unnamed Financial Security Institute official, phone call, 3 Oct 12:31
    What was said
    Shinhan's logs and attacker addresses showed traces of ARTEX, with a data signature common to its traffic. AI was used, but did not act independently
    Standing
    Anonymous; one newspaper; no published statement
  5. Source and date (KST)
    FSC chairman, remarks, 4 Oct 14:00
    What was said
    Difficult to say definitively, but AI-assisted hacking cannot be ruled out
    Standing
    Official text, read in full
  6. Source and date (KST)
    Financial Security Institute head, to reporters, 4 Oct
    What was said
    Not confirmed; AI use presumed from method and circumstances; no direct trace of an AI agent confirmed; investigation continues
    Standing
    On the record; one outlet read
  7. Source and date (KST)
    Presidential office, 4 Oct
    What was said
    Briefed on leaks at financial and public institutions; ordered a thorough investigation. No AI wording
    Standing
    Spokesperson, via Yonhap
  8. Source and date (KST)
    National Police Agency, 2 Oct
    What was said
    Pre-charge inquiry into the four banks, Shinhan from 1 Oct. No tool named
    Standing
    Press reports of a police briefing

How the wording moved. The anonymous official's "confirmed" appeared 25 hours 29 minutes before the chairman's remarks, and the institute head's "not confirmed" came the same afternoon, as the diagram shows. The two institute statements are hard to reconcile: one says traces of a named tool were found in Shinhan's logs, the other that no direct trace of an AI agent has been confirmed. They may differ in what they count as a trace. This briefing follows the statements on the record and says so. The anonymous one stays a lead until the institute publishes it.

Six boxes in time order. 2 October: a security vendor's researcher reads a page title as a possible AI penetration-testing console. 3 October: an unnamed institute official tells a newspaper the traces are confirmed. 4 October 14:00: the FSC chairman says AI use cannot be ruled out. 4 October afternoon: the institute head says it is presumed, not confirmed. 5 October: a press check finds no official confirmation. At 16:15 KST no published statement names the tool.
Drawn from Newsis and Segye (2 October), Herald Business (3 October), the FSC chairman's remarks published by the FSS (4 October), Newsway (4 October) and News1 (5 October).

News1 reported at 14:50 on 5 October that the string alone cannot show ARTEX was used at Shinhan, and that neither the authorities nor the bank has confirmed it. That was the position at the time of reading.

What the tool's own page says it is

The tool is named in the press and has a public project page. Only that page was read: nothing was downloaded or run, no repository is linked here, and nothing about operating it is described. The page calls it an AI autonomous penetration-testing system, with a Go back end and a web front end, under the AGPL-3.0 licence, and its description says it is the champion project of a Baidu "agent+" attack and defence challenge, a claim the press repeats and this briefing has not checked. GitHub's public metadata shows the repository was created on 26 July 2026. Its README says it is for personal learning, code research and local technical validation only, and forbids using it to scan, probe, exploit or attack any website, online service or networked system, whether or not authorised. Those terms bind nobody who ignores them; they only mean the author disclaims misuse.

GitHub's public metadata listed 320 forks and about 1,500 stars at about 08:00 BST on 5 October, and a single search turns up several derivative copies with the same name, so a name or a page title does not say which copy ran. News1 reports that its published settings support hosted-model APIs from OpenAI and Anthropic as well as user-chosen providers, and quotes a security professor who says a model's country of origin does not identify an attacker. That is a fact about the tool's design. No source says which model, if any, was behind these attacks.

What a page title is. The title is what a console shows to whoever runs it, original or copy. It places that console on a web server. It does not by itself say what that server did, to whom, or when. The researcher's own post, as quoted, says possibility. The institute official's different evidence, a data signature in attack traffic, has not been published. And, as that official put it, there are "a great many open-source AI tools like ARTEX", so attribution to one tool is not the control point for a bank.

The label that does the work

"AI-powered attack" describes how an attack was carried out. It does not say what failed. What the authorities describe as failing is older. According to Seoul Economic Daily's account of the regulators' briefing on 4 October, a press account in which the three-way sort is not in the published release, the breaches fall into three kinds:

  • Lookup services built so that loan-application records and corporate-representative data could be retrieved without identity verification.
  • Staff support apps for private bankers and relationship managers, where mobile-device access control was missing or web flaws that allowed unauthorised access had not been patched.
  • Website services where known vulnerabilities were exploited to install malicious code and steal log files that held customer data.

The FSC chairman's published remarks say much the same. External web pages and servers used by loan brokers and staff were, he said, areas that had received less management attention. Some had pointed to missing basic measures such as authentication and to more information being stored and queried than business needed, and one unmanaged gap can become the weakness of the whole. The exact cause of each incident, he added, still needed closer analysis. Asked what separated the banks that were hit from those that were not, the institute head answered, as Sidae reported, whether multi-factor authentication was in place, and said the attack was querying and scraping through web pages, not injection into a database. Bank officials told Hankook Ilbo that Woori requires a separate certificate and a biometric check for work systems, and that NH NongHyup gives loan recruiters no route into its internal network and automatically blocks repeated logins from one address, which worked here.

The friendly-name fallacy. A scanner that runs without a human finds exposed systems that a person, or a plain script, could also find. The NCSC's EASM buyer's guide said in September 2025 that criminals can "indiscriminately probe millions of online assets with next to no effort". What AI changes, if it was used, is the cost of probing the neglected corners, which experts quoted by News1 say now pays for attackers. That is opinion, and no source shows that these banks' side doors were found faster because of AI. A related trap is the word agent. The staff systems reportedly attacked at KB Kookmin are named RM Agent and PB Agent. An agent in the target's name says nothing about the attacker's tooling.

The regulator's response is an attack-surface response. It asks banks to find every externally exposed asset, cut external access to what is essential, limit what each path can query, and share attacker addresses. That tells you the failure class the authorities suspect. It does not prove it for any one bank, because the cause of each incident is, in the chairman's words, still to be analysed.

Stated and not stated

What is on the record about the Korean bank breaches at 08:15 BST on 5 October 2026. Sources: the banks' notices, the FSC and FSS releases and the chairman's remarks, and press accounts where marked.

  1. Question
    Shared cause or actor
    Stated
    Institute head: attacker addresses almost identical at the four banks, different at the savings banks, methods somewhat similar; cannot conclude one person
    Not stated
    Any named actor, any attribution, or one shared flaw
  2. Question
    AI or a named tool
    Stated
    FSC chairman: cannot be ruled out. Institute head: presumed, not confirmed. An anonymous official and one vendor researcher: ARTEX traces
    Not stated
    Any published statement from an authority or bank that confirms a tool or an AI agent
  3. Question
    Route in
    Stated
    Loan-broker lookup (Shinhan), staff work-support (KB Kookmin), sales-support system (Hana), staff web pages (Busan). Authorities, via the press: missing identity checks, missing device control, unpatched web flaws
    Not stated
    The specific flaw at any bank, a CVE, or any mechanism in Shinhan's notice
  4. Question
    Exposed or taken
    Stated
    Banks say leaked. The institute says the attacker queried and extracted, not took over systems
    Not stated
    Where the data went, or whether it is for sale or in use
  5. Question
    Financial loss
    Stated
    FSC chairman: no sign yet of data usable for fraudulent payments. The institute sees direct loss as unlikely
    Not stated
    That no loss will occur, or that phishing will not follow
  6. Question
    Final counts
    Stated
    About 25,000 (Shinhan notice), 99 plus 20, 89 and 11. An institute official told Herald Business just under 26,000 confirmed, and could rise
    Not stated
    Any final figure. Yegaram's 40,000 is an estimate and Welcome's 2,200 a maximum

The UK reading

None of this is evidence about UK firms. It is a test of how a UK reader should act on positions published before these incidents.

NCSC. On 15 April 2026 the NCSC said AI will make weaknesses "easier, faster and cheaper" to find and exploit, and told organisations to reduce unnecessary exposure, apply updates quickly and monitor for malicious activity. On 1 May 2026 it said all organisations should identify and minimise their externally exposed attack surfaces as soon as possible, perimeter first and then inwards. Its EASM buyer's guide of 18 September 2025 says many organisations lack a complete record of their online estate.

FCA, Bank of England and HM Treasury. The joint statement of 15 May 2026 says current frontier AI cyber capabilities already exceed what a skilled practitioner could achieve, faster and at lower cost, and that firms should remediate vulnerabilities faster, manage third-party and supply-chain risk, and use access management, network security and data protection to shrink the attack surface a model might reach. The FCA's review of 2 September 2026 reports firms saying AI is exposing weaknesses in vulnerability management, access management controls, dependency mapping and remediation. Neither adds new rules.

Operational resilience. PRA SS1/21 applies to UK banks. The FCA's page says firms had until 31 March 2025 to operate important business services within impact tolerances, and that incident and third-party reporting requirements published on 18 March 2026 apply from 18 March 2027.

How that maps to Korea: the Korean authorities asked, within four to six days, for what these texts already ask for, an inventory of external exposure and tighter access. Judgement: a UK firm that cannot say within a day which externally exposed assets and services it has, staff and broker-facing ones included, has an operational resilience question before it has an AI question.

What a UK security lead should do about exposed systems now

The order below is our judgement, drawn from the Korean record and the UK texts above. No UK regulator has issued this list. It is defensive and does not describe how to attack anything.

Take this with you

In the order worth doing

  • Build the external inventory from the outside in. List everything on your domains and address ranges that answers the internet, including staff, broker, introducer, adviser and partner apps, and reconcile it against your asset register. Give every unowned item an owner or take it down.
  • Look for side doors first: staff mobile and web apps, broker and introducer portals, sales-support and reporting views, test, UAT, demo and legacy environments, and forgotten subdomains. Korea's regulator said it made no difference whether a system was customer-facing.
  • For each one, record in writing whether any path returns personal or credit data to a caller who has not proved who they are, whether access is checked per record or only per session, and whether a single factor is all that stands in the way. Date it and name the owner.
  • Remove or fix stale exposed services: known, unpatched web flaws on front ends, and anything out of vendor support. If it cannot be fixed this week, take it off the internet. Perimeter first is the NCSC's order.
  • Shrink what sits behind side systems. Strip personal, credit and identity fields from staff and broker views that do not need them, and cut retention.
  • Detect automation, not addresses. Set per-identifier and per-account rate limits and lockouts, alert on high-volume lookups and on many similar requests from many sources, and keep logs that let you reconstruct a night's activity. Blocking addresses is first aid: by News1's account Shinhan's second wave began about 11 hours after its first block.
  • Set and test a time target from the first anomalous request to a human decision. The reported clocks in Korea were 15, 42 and 68 hours between first contact and the bank knowing (Shinhan, Hana, KB Kookmin). Know your own.
  • Cover third-party and vendor-hosted portals. List every external party that holds or can reach customer data, including brokers, introducers and outsourced developers (Busan's 11 and Hyundai Capital's 146 recruiters were such groups), and hold them to your authentication, logging and incident-notification standards before the FCA's reporting rules start on 18 March 2027.
  • Keep the evidence a regulator will ask for: the inventory with owners, dated test results, detection and decision timestamps from an exercise, and a board paper linking exposed services to important business services and impact tolerances.

What could not be verified

The question this leaves

The banks that lost the most did not lose their core systems. They lost a lookup service, a staff app and a sales-support view that nobody had treated as a front door, and the two banks that held say they had extra authentication or automatic blocking on that kind of path. Which of your systems, customer-facing or not, will still answer a caller who has not proved who they are, and who would be paged if one asked 25,000 times in a night?

Key facts

Sources

  1. PrimaryCustomer apology notice 'Personal (credit) information leak', dated 1 October 2026, read in Korean on shinhan.com: about 25,000 customers, items, no mechanism, no mention of AIShinhan Bankaccessed 2026-10-05
  2. PrimaryNotice on the leak of personal (credit) information, dated 2 October 2026, read in Korean: 99 customers and 20 current or former staff, confirmed 30 September, the staff mobile work-support system, no mention of AIKB Kookmin Bankaccessed 2026-10-05
  3. PrimaryNotice and apology on the leak of personal (credit) information, dated 3 October 2026, read in Korean: 89 customers, intrusion into the sales-support system on 30 September, confirmed 2 October, no mention of AIHana Bankaccessed 2026-10-05
  4. PrimaryPress release of 2 October 2026 on the emergency response meeting at 15:00, read in Korean: Shinhan's incident dated 30 September, the order to check externally exposed IT systems and authenticationFinancial Services Commission (Korea)accessed 2026-10-05
  5. PrimaryPress release of 4 October 2026 on the all-sector emergency meeting at 14:00 with the PDF release and the chairman's opening remarks, read in Korean: attendees, the five requests, the AI wordingFinancial Supervisory Service (Korea)accessed 2026-10-05
  6. PrimaryFSS copy of the 2 October release, used to confirm the date and the meetingFinancial Supervisory Service (Korea)accessed 2026-10-05
  7. PrimaryEnglish release of 3 September 2026 on the second phase of the temporary easing of the network separation rule for AI cybersecurity testing (75 eligible firms); context onlyFinancial Services Commission (Korea)accessed 2026-10-05
  8. PrimaryPress release list read at about 08:00 BST on 5 October 2026: nothing about the banks; the latest item, 2 October, is a general plan for faster breach investigationsPersonal Information Protection Commission (Korea)accessed 2026-10-05
  9. PrimaryBlog of 15 April 2026 on retaining defensive advantage in the age of frontier AI cyber capabilities: AI makes weaknesses easier, faster and cheaper to find; reduce unnecessary exposureNCSCaccessed 2026-10-05
  10. PrimaryBlog of 1 May 2026 on preparing for a vulnerability patch wave: identify and minimise externally exposed attack surfaces, perimeter firstNCSCaccessed 2026-10-05
  11. PrimaryEASM buyer's guide announcement, 18 September 2025: many organisations lack a complete record of their online estate; criminals can probe millions of assets with next to no effortNCSCaccessed 2026-10-05
  12. PrimaryJoint statement of 15 May 2026 on frontier AI models and cyber resilience: expectations on vulnerabilities, third parties, access management and attack surfaceFCA, Bank of England and HM Treasuryaccessed 2026-10-05
  13. PrimaryMulti-firm review 'Frontier AI and cyber resilience', 2 September 2026: AI is exposing weaknesses in vulnerability management, access management, dependency mapping and remediation; no new rulesFCAaccessed 2026-10-05
  14. PrimaryOperational resilience page, updated 15 September 2026: the 31 March 2025 deadline for impact tolerances and the incident and third-party reporting rules from 18 March 2027FCAaccessed 2026-10-05
  15. PrimarySupervisory Statement SS1/21 on operational resilience and impact tolerances for important business services, relevant to UK banks, effective 31 March 2022Bank of England, Prudential Regulation Authorityaccessed 2026-10-05
  16. Reported by5 October 2026 account of the banks' incident reports obtained by an MP's office: attack windows, detection times and Shinhan's response; the reports themselves were not readNews1 (via Nate)accessed 2026-10-05
  17. Reported by5 October 2026 explainer: 'old methods' with AI, no official confirmation of ARTEX at Shinhan, the tool's API support, expert commentsNews1 (via Nate)accessed 2026-10-05
  18. Reported by4 October 2026, 16:08 KST: the Financial Security Institute head's answers to reporters, read in Korean: addresses, similar methods, AI presumed not confirmed, no direct trace of an AI agentNewswayaccessed 2026-10-05
  19. Reported by4 October 2026, 17:25 KST: the institute head on multi-factor authentication as the difference, query-and-scrape rather than injection, 25 attacker addresses sent to about 500 firms, the 12-item checklist and deadlinesSidaeaccessed 2026-10-05
  20. Reported by4 October 2026, 16:33 KST, in Korean: the three kinds of breach, the shared attacker addresses, 500 firms, the 6 and 8 October deadlines; English edition read as wellSeoul Economic Dailyaccessed 2026-10-05
  21. Reported by3 October 2026, 12:31 KST, exclusive in Korean, English edition also read: an unnamed Financial Security Institute official on traces of ARTEX in Shinhan's logsThe Herald Businessaccessed 2026-10-05
  22. Reported by2 October 2026, in Korean: the security vendor researcher's LinkedIn post quoted, with the note that there was no official statement that the tool was used at ShinhanNewsisaccessed 2026-10-05
  23. Reported by2 October 2026, in Korean: KB Kookmin, Hana and Busan statements, the Woori and NH NongHyup blocks, and the researcher's postSegye Ilboaccessed 2026-10-05
  24. Reported by1 October 2026, in Korean: Shinhan's loan-recruiter inquiry service and the bank's explanation of how the inputs were guessedSegye Ilboaccessed 2026-10-05
  25. Reported by2 October 2026, in Korean: BNK Busan's statement on the 21:00 attempt 'using an AI agent', insufficient session verification and 11 outsourced developersBusan Ilboaccessed 2026-10-05
  26. Reported by4 October 2026, in Korean: why the damage differed, Woori's and NH NongHyup's controls, seven firms with the same attacker addressHankook Ilboaccessed 2026-10-05
  27. Reported by2 October 2026, in Korean: the police pre-charge inquiry, and the claim that Shinhan itself said an AI agent was usedHankook Ilboaccessed 2026-10-05
  28. Reported by4 October 2026, in Korean: the seven-firm tally, about 66,000 people, Yegaram, Hyundai Capital and Welcome figuresFinancial Newsaccessed 2026-10-05
  29. Reported by4 October 2026, English edition: the researcher's post, the tool's GitHub release dates, the institute head's remarks on attribution and IP addresses from eight countriesThe Kyunghyang Shinmunaccessed 2026-10-05
  30. Reported by4 October 2026, in Korean: the presidential office statement as quoted from the senior spokespersonSegye Ilbo (Yonhap)accessed 2026-10-05
  31. Reported by4 October 2026: the president's instruction as quoted from the spokesperson, the sequence of announcements, and the FSC chairman's remark that AI attacks cannot be ruled outKorea JoongAng Dailyaccessed 2026-10-05
  32. Reported by2 October 2026: security experts' basis for suspecting AI automation, the page-title string, and the counts at that dateThe Korea Timesaccessed 2026-10-05
  33. Reported by4 October 2026 repost of the DataBreaches.net item quoting the Korea Times: the 'AI-powered cyberattacks increasingly target them' framing and the Cheong Wa Dae briefingMalware News (repost of DataBreaches.net)accessed 2026-10-05

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.