Overview

Coordinated cyberattacks against seven South Korean financial institutions in early October 2026, with presidential confirmation of AI tool involvement and full police investigation underway.

Timeline

  • 2026-10-01: Shinhan Bank discloses ~25,729 customer records leaked
  • 2026-10-06: Seven institutions confirmed breached; ~68K people affected; President Lee Jae Myung confirms AI appears used; 28-member police cyber terror unit formed
  • 2026-10-06: FSS identifies 28 attacker IPs; firms ordered to complete security checks by Thursday

Key Players

  • shinhan-bank, KB Kookmin, Hana, BNK Busan, Yegaram/Welcome savings banks, Hyundai Capital
  • artex-ai tool traces on banking-sector attacker IPs

Analysis

First major AI-assisted financial sector breach with head-of-state confirmation. Demonstrates dual-use risk of open-source pentest agents. Attackers switched IPs across multiple countries; savings bank and commercial bank IPs differed but methods similar.

Warning

AI involvement is presidential characterization, not forensic conclusion. Humans directed attacks per officials.

Sources