Shinhan Bank leaked the details of 25,000 customers, while Kookmin Bank leaked credit card information of 119,000 clients, according to local reports — figures that prompted an emergency meeting of South Korea’s Financial Services Commission (FSC) and on-site probes at multiple banks.
FSC emergency meeting and on-site investigations
Officials convened an emergency session after a series of cyber incidents hit South Korean financial institutions. During that meeting the FSC confirmed a data breach at Shinhan Bank and said other cybersecurity incidents affected additional banks, including Kookmin Bank. Authorities said they launched on-site investigations after receiving incident reports and that they shared "all actionable information" with relevant agencies, explicitly naming KISA (Korea's data protection agency).
Banks named and the scale of the institutions involved
The incidents touched several major private banks. The source material names Shinhan Bank and KB Kookmin Bank and notes that each is a large private South Korean commercial bank holding more than $400 billion in assets. Hana Bank was also reported to have suffered a limited-scope breach after its sales-support system was compromised. Reported exposures include 25,000 customer details tied to Shinhan and credit card data for 119,000 customers of Kookmin Bank.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleAI-powered attacks suspected — ARTEX AI mentioned
While official channels provided no details about perpetrators or methods, Korean news agency Yonhap reported that a server used in the attacks had an HTML page title containing a Chinese-language string associated with ARTEX AI. The source describes ARTEX AI as an open-source penetration-testing system that uses agents to automate information gathering, vulnerability discovery, attack-path planning, security-tool execution, and vulnerability verification. Banks and financial authorities have not confirmed ARTEX AI was used in the Shinhan breach, and the presence of the Chinese-language string does not link the incidents to any particular threat actor.
Separately, Moon Jong-hyun, head of the Genian Security Center, posted on LinkedIn that several threat analysts believe the breaches involved AI-based attack automation tools. That professional assessment, as reported in the source material, aligns with the Yonhap detail but stops short of attribution or technical confirmation from the banks or regulators.
Regulatory direction: inspections, information sharing, and consumer remedies
Following the incidents, authorities issued a set of directives to financial companies. Firms were instructed to:
- Inspect all externally accessible IT systems and services, including those that are not customer-facing.
- Reduce unnecessary information exposure and check for missing or inadequate authentication and access controls.
- Quickly share threat information and coordinate their responses.
- Submit their internal security inspection results as soon as possible.
Authorities also pledged to oversee consumer protection and compensation, and to analyze the incidents to identify necessary regulatory improvements. Local media reports also said President Lee ordered a thorough investigation into personal data leaks at financial and public institutions.
How technologists, policymakers, and customers are likely to respond
Technologists and security teams will be focused on the immediate directives: sweeping inspections of externally facing systems (including internal, non-customer-facing services), verifying authentication and access controls, and accelerating threat-information sharing with peers and authorities — actions explicitly called for by regulators in the wake of these incidents.
Policymakers and regulators will be watching the on-site investigations and the data the FSC passes to KISA, and they have signaled an intent to analyze the breaches for regulatory improvements and to supervise consumer compensation; the president’s reported order for a thorough investigation indicates political attention at the highest levels.
Customers whose data were reported exposed — the 25,000 Shinhan customers and 119,000 Kookmin credit-card clients named by local reports — are the direct focus of the pledged consumer-protection and compensation efforts; they will look to their banks and regulators for clarity on scope, remedies, and monitoring against follow-on misuse.
The record assembled so far is operational rather than forensic: regulators have mobilized, banks have been identified as victims, media reports point to strings on an attack server and to expert suspicion of AI-assisted automation, and authorities have issued concrete instructions and promised oversight and compensation. The coming steps named in the official response — on-site probes, shared actionable data with KISA, and mandated internal inspections — will determine whether these incidents prompt technical fixes, faster information sharing, or regulatory change.




