Suspected AI-agent cyberattack on South Korea's Shinhan Bank exposed data on about 25,000 customers
Shinhan Bank said an unauthorized external party accessed certain services and obtained customer information, including names, phone numbers, annual income and borrowing limits, for about 25,000 customers. Yonhap News, citing cybersecurity experts, reported that attackers probably used sophisticated AI agents to probe for vulnerabilities and gain access to a service used by loan recruiters. The bank is investigating with authorities and outside experts, and South Korea's Financial Supervisory Service began an emergency on-site inspection.
What the AI did
Cybersecurity experts said attackers probably used sophisticated AI agents, meaning AI programs that can carry out tasks on their own, to probe for weak points and gain access to a service used by loan recruiters. It has not been reported which AI tools were used.
First reported October 1, 2026 · Added to the register October 4, 2026 · 2 sources
- Customers whose information was exposed
- About 25,000
- Customers whose data leaked
- around 25,000
- Affected
- Shinhan Bank
- Country
- South Korea
- When it happened
- Not stated in the sources
- First reported
- October 1, 2026
What this means for you
Could this affect you?
About 25,000 Shinhan Bank customers had names, phone numbers, annual income and borrowing limits taken, and other financial institutions whose online services can be probed automatically by AI agents could be reached the same way.
What to check
- Audit externally facing partner and recruiter portals for vulnerabilities.
- Monitor for high-volume automated probing of your online services.
- Warn affected customers about personalised scams that may use leaked income and borrowing data.
Areas of your AI programme this touches
Timeline
- October 1, 2026First reported
- October 1, 2026Sources said the hackers were suspected to be based overseas and used advanced AI tools; experts said the bank was likely caught in random AI-powered attacks. The Financial Supervisory Service sent a team for an on-site inspection expected to take months.[1]
Every fact and its source (9)
- Regulator responseFSS emergency on-site inspection“Financial Supervisory Service began an emergency on-site inspection”[2]
- Bank responseInvestigating with authorities and outside experts“The lender is investigating the cause, scope and potential impact with authorities and outside cybersecurity experts.”[2]
- Suspected AI roleAttackers probably used AI agents to probe for vulnerabilities“Attackers probably used sophisticated AI agents to probe for vulnerabilities”[2]
- Data exposedNames, phone numbers, annual income, borrowing limits“Information exposed in the breach included customer names, phone numbers, annual income and borrowing limits”[2]
- Bank responseBlocked external IPs and suspended affected services“blocking access from external IP addresses and suspending the affected services”[1]
- Regulator responseFSS on-site inspection, expected to take months“The Financial Supervisory Service, meanwhile, sent a team to examine the data leak earlier in the day, with the investigation expected to take months.”[1]
- AI involvementHackers suspected to have used advanced AI tools“utilized advanced artificial intelligence tools in the attacks”[1]
- Data leakedLoan borrowing, annual income, names, phone numbers“loan borrowing by customers, their annual income, names and phone numbers were leaked on Wednesday via hacking”[1]
- Suspected attacker locationOverseas“the hackers, currently suspected to be based overseas”[1]
Sources
- Some 25,000 customers' info leaked from Shinhan Bank in apparent AI agent-assisted hackingkoreaherald.com · October 1, 2026
- AI Tools Suspected in Korea's Shinhan Bank Hack, Yonhap Saysclaimsjournal.com · October 2, 2026
How this record is classified. Severity S (4/5): real harm to one organisation, data exposed, or a containment failure. OECD level: incident, an event in which an AI system led to actual harm. Evidence: Reported, meaning press reporting only.
The facts in At a glance and in Every fact and its source are quoted from the sources listed. The summary, What the AI did and What this means for you are written from those sources and checked against them automatically before publication. Records reflect what has been disclosed, not everything that has happened. Incidents are found through news feeds and the GDELT Project.
