Overview
Coordinated cyberattacks against seven South Korean financial institutions in early October 2026, with presidential confirmation of AI tool involvement and full police investigation underway.
Timeline
- 2026-10-01: Shinhan Bank discloses ~25,729 customer records leaked
- 2026-10-06: Seven institutions confirmed breached; ~68K people affected; President Lee Jae Myung confirms AI appears used; 28-member police cyber terror unit formed
- 2026-10-06: FSS identifies 28 attacker IPs; firms ordered to complete security checks by Thursday
Key Players
- shinhan-bank, KB Kookmin, Hana, BNK Busan, Yegaram/Welcome savings banks, Hyundai Capital
- artex-ai tool traces on banking-sector attacker IPs
Analysis
First major AI-assisted financial sector breach with head-of-state confirmation. Demonstrates dual-use risk of open-source pentest agents. Attackers switched IPs across multiple countries; savings bank and commercial bank IPs differed but methods similar.
Warning
AI involvement is presidential characterization, not forensic conclusion. Humans directed attacks per officials.