Suspected AI-automated cyberattacks breached KB Kookmin, Hana and BNK Busan banks, exposing customer and worker data
A day after Shinhan Bank disclosed a breach, KB Kookmin Bank said data on 119 customers leaked through a mobile system used by employees. Hana Bank said data on 89 customers was exposed through its sales support system. BNK Busan Bank said data on 11 outsourced workers leaked, and Woori Bank and NH NongHyup Bank reported hacking attempts with no data exposed. The pattern of attacks on employee and sales-support systems raised suspicions that they were automated using AI; financial regulators dispatched investigators and police opened a preliminary inquiry.
What the AI did
Attackers are suspected of using AI to automate cyberattacks on employee and sales-support systems at several South Korean banks, but this has not been confirmed. Local media reported that traces of a Chinese-language AI penetration-testing tool were found on a server believed to have been used in the related attack on Shinhan Bank, suggesting a possible link to ARTEX AI, an open-source autonomous penetration-testing system. Regulators are still investigating.
First reported October 2, 2026 · Added to the register October 7, 2026 · 1 source
- BNK Busan outsourced workers whose data leaked
- 11
- Hana customers whose data was exposed
- 89
- Kookmin customers whose data leaked
- 119
- Affected
- BNK Busan Bank, KB Kookmin Bank, Hana Bank
- Country
- South Korea
- When it happened
- Not stated in the sources
- First reported
- October 2, 2026
What this means for you
Could this affect you?
Customers of KB Kookmin Bank and Hana Bank and outsourced workers at BNK Busan Bank had personal data exposed, including resident registration numbers, and other banks and financial firms whose employee, sales-support or broker-facing systems can be reached from outside could be targeted the same way.
What to check
- Strengthen login checks on employee, sales-support and loan-broker systems.
- Monitor for automated attempts to log in with stolen passwords and for repeated probing for security weaknesses.
- Share signs of intrusion with regulators and peer firms.
- Block attacking internet addresses quickly.
Areas of your AI programme this touches
Every fact and its source (4)
- Police responsePreliminary police inquiry launched“Police also launched a preliminary inquiry into the cyberattacks on major banks”[1]
- AI linkAttack pattern raised suspicion of AI automation“This pattern has raised suspicions that the attacks were automated using AI”[1]
- Other banks targetedWoori Bank and NH NongHyup Bank attacked, no data exposed“Woori Bank and NH NongHyup Bank said they had also faced hacking attacks but no information had been exposed”[1]
- Regulator responseFSC and FSS dispatched investigators“had dispatched investigators to the affected firms as soon as the breaches were reported”[1]
Sources
- Shinhan, Kookmin, Hana data breaches fuel concerns over AI-powered cyberattacks in financial sectorkoreatimes.co.kr · October 2, 2026
How this record is classified. Severity S (4/5): real harm to one organisation, data exposed, or a containment failure. OECD level: incident, an event in which an AI system led to actual harm. Evidence: Reported, meaning press reporting only.
The facts in At a glance and in Every fact and its source are quoted from the sources listed. The summary, What the AI did and What this means for you are written from those sources and checked against them automatically before publication. Records reflect what has been disclosed, not everything that has happened. Incidents are found through news feeds and the GDELT Project.

