South Korea Investigates Cyberattacks on Shinhan and KB Kookmin Banks
South Korea’s Financial Services Commission (FSC) has launched an emergency response to a series of cyberattacks targeting the country’s financial institutions.
Officials confirmed a data breach at Shinhan Bank and said other cybersecurity incidents have affected South Korean banks, including KB Kookmin Bank. Hana Bank also reported a limited compromise of its sales support system.
Shinhan Bank and KB Kookmin Bank are two of South Korea’s leading private commercial banks, with each holding more than $400 billion in assets.
South Korean authorities order bank security inspections
Following the incident report, the FSC began an on-site investigation and shared actionable information with relevant authorities, including KISA.
The agency instructed domestic financial companies to take the following measures:
- Inspect all externally accessible IT systems and services, including systems that are not customer-facing.
- Reduce unnecessary information exposure and identify missing or insufficient authentication and access controls.
- Rapidly share threat information and coordinate incident responses.
- Submit internal security inspection results as soon as possible.
The FSC also pledged to oversee consumer protection and compensation efforts while analyzing the incidents to identify necessary regulatory improvements.
South Korean President Lee also ordered a thorough investigation into the leakage of personal information at financial institutions and public institutions, according to local media reports.
Credit card data reportedly exposed
According to the report, credit card information belonging to approximately 25,000 Shinhan Bank customers and 119,000 KB Kookmin Bank customers was leaked.
The reported incidents have prompted increased scrutiny of the security controls protecting South Korea’s banking infrastructure and customer information.
Was AI used in the bank attacks?
Officials have not publicly identified the attacker or released definitive technical details about the Shinhan Bank breach. However, Yonhap News reported that the server used in the attack contained HTML page titles with Chinese strings related to ARTEX AI.
ARTEX AI is an open-source penetration-testing system that uses agents to automate information gathering, vulnerability discovery, attack-path planning, security-tool execution, and vulnerability validation.
South Korean banking and financial authorities have not confirmed that ARTEX AI was used in the Shinhan incident. The presence of Chinese-language strings also does not connect the attack to a specific threat actor.
Moon Jeong-hyun, director of the Genian Security Center, said that several threat analysts believe the breach may have involved AI-based attack automation tools. His comments were shared in a LinkedIn post.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit on AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



