Back
AI-Linked Hacks Hit Korean Banks Through Loan-Agent Sites
SiTech AI Team3 min read

AI-Linked Hacks Hit Korean Banks Through Loan-Agent Sites

Attackers suspected of using AI tools breached at least seven South Korean banks since late September, stealing personal data through loan-agent portals and employee systems. Regulators ordered fixes by Thursday.

Breaches at Seven Korean Lenders

Attackers have broken into at least seven South Korean banks and lenders since late September, stealing personal data including loan-application details on about 25,000 Shinhan Bank customers. South Korean President Lee Jae Myung said Tuesday that there were signs AI had played a role in some of the attacks, without specifying what kind or model of AI.

Shinhan said about 25,000 customers were affected, with exposed data including names, phone numbers, annual incomes and calculated borrowing limits. KB Kookmin, South Korea's largest lender, said 99 customers and 20 current and former employees were affected, and Hana said 89 customers were. The other four firms include two savings banks, a regional bank and a consumer lender.

How the Attackers Got In

The attackers came in through side doors rather than complex vulnerabilities. At Shinhan, they targeted a lookup service the bank built for loan recruiters, outside agents who refer borrowers to the bank. Over about 30 hours starting Sept. 28, attackers fed random customer numbers into the service and got past a mobile-phone verification step. Reports conflict over the technique: Yonhap described credential stuffing, while Dong-A Ilbo described enumeration.

BNK Busan Bank, the regional lender caught up in the campaign, said some of its web pages had insufficient session validation, exposing data on 11 outsourced developers. The attackers did not obtain passwords or one-time authentication codes, and regulators have confirmed no cases of customers losing money.

Where AI Fits

BNK Busan said the attempt on its web servers used an AI agent. A South Korean security researcher found that a web server believed to have been used against Shinhan carried a page title matching ARTEX, an open-source penetration-testing tool that describes itself as an autonomous system driven by multiple AI agents running on models from Anthropic or OpenAI. An official at the Financial Security Institute told Herald Business that investigators traced Shinhan's attack logs and found evidence pointing to ARTEX, adding that the AI did not act independently without human involvement. No regulator has publicly named ARTEX as being involved in the attack.

Regulatory Response

South Korea's Financial Services Commission held emergency meetings on Friday and Sunday and ordered financial firms to inspect every internet-facing system, whether customer-facing or not, and to finish checks and fix gaps by Thursday. Police have opened a formal investigation. The commission also ordered firms to ensure personal credit data is not unnecessarily stored or viewable in systems used by outside personnel such as loan recruiters and outsourcing contractors, which it called the cause of the recent intrusions.

The failures mirror controls U.S. regulators have named for months. Federal Reserve Vice Chair for Supervision Michelle Bowman said in Sept. 29 remarks that defending against AI-powered threats begins with strong cyber hygiene, including phishing-resistant multifactor authentication, strong identity and access controls and up-to-date asset inventories. Interagency guidance on third-party risk issued in 2023 explicitly covers referral arrangements, the closest U.S. counterpart to Korea's loan recruiters.

Sources: americanbanker.com

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.