Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
IncidentPeople used AI as a toolSeverity S: serious, 4/5Reported: press reporting only

Suspected AI-automated cyberattacks breached KB Kookmin, Hana and BNK Busan banks, exposing customer and worker data

A day after Shinhan Bank disclosed a breach, KB Kookmin Bank said data on 119 customers leaked through a mobile system used by employees. Hana Bank said data on 89 customers was exposed through its sales support system. BNK Busan Bank said data on 11 outsourced workers leaked, and Woori Bank and NH NongHyup Bank reported hacking attempts with no data exposed. The pattern of attacks on employee and sales-support systems raised suspicions that they were automated using AI; financial regulators dispatched investigators and police opened a preliminary inquiry.

What the AI did

Attackers are suspected of using AI to automate cyberattacks on employee and sales-support systems at several South Korean banks, but this has not been confirmed. Local media reported that traces of a Chinese-language AI penetration-testing tool were found on a server believed to have been used in the related attack on Shinhan Bank, suggesting a possible link to ARTEX AI, an open-source autonomous penetration-testing system. Regulators are still investigating.

First reported October 2, 2026 · Added to the register October 7, 2026 · 1 source

BNK Busan outsourced workers whose data leaked
11
Hana customers whose data was exposed
89
Kookmin customers whose data leaked
119
Affected
BNK Busan Bank, KB Kookmin Bank, Hana Bank
Country
South Korea
When it happened
Not stated in the sources
First reported
October 2, 2026

What this means for you

Could this affect you?

Yes

Customers of KB Kookmin Bank and Hana Bank and outsourced workers at BNK Busan Bank had personal data exposed, including resident registration numbers, and other banks and financial firms whose employee, sales-support or broker-facing systems can be reached from outside could be targeted the same way.

What to check

  • Strengthen login checks on employee, sales-support and loan-broker systems.
  • Monitor for automated attempts to log in with stolen passwords and for repeated probing for security weaknesses.
  • Share signs of intrusion with regulators and peer firms.
  • Block attacking internet addresses quickly.
Every fact and its source (4)
  1. Police responsePreliminary police inquiry launched
    “Police also launched a preliminary inquiry into the cyberattacks on major banks”[1]
  2. AI linkAttack pattern raised suspicion of AI automation
    “This pattern has raised suspicions that the attacks were automated using AI”[1]
  3. Other banks targetedWoori Bank and NH NongHyup Bank attacked, no data exposed
    “Woori Bank and NH NongHyup Bank said they had also faced hacking attacks but no information had been exposed”[1]
  4. Regulator responseFSC and FSS dispatched investigators
    “had dispatched investigators to the affected firms as soon as the breaches were reported”[1]

Sources

  1. Shinhan, Kookmin, Hana data breaches fuel concerns over AI-powered cyberattacks in financial sector
    koreatimes.co.kr · October 2, 2026

How this record is classified. Severity S (4/5): real harm to one organisation, data exposed, or a containment failure. OECD level: incident, an event in which an AI system led to actual harm. Evidence: Reported, meaning press reporting only.

The facts in At a glance and in Every fact and its source are quoted from the sources listed. The summary, What the AI did and What this means for you are written from those sources and checked against them automatically before publication. Records reflect what has been disclosed, not everything that has happened. Incidents are found through news feeds and the GDELT Project.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide