Shinhan Bank loan-agent platform breach (suspected AI-assisted attack)
South Korea's Shinhan Bank disclosed that attackers bypassed authentication on a service used by loan agents and exposed the personal and loan data of about 25,000 customers, in an intrusion investigators suspect was driven by AI penetration-testing tools.
- Victim
- Shinhan Bank
- users
- 25.0K
On 1 October 2026, Shinhan Bank, one of South Korea's largest commercial banks, disclosed that hackers had accessed a service used by loan agents to check the status of loan applications and exposed the data of about 25,000 customers. The bank said its core banking systems for deposits and transfers were not affected.
According to Korean media, the unauthorized parties bypassed authentication on the platform, and investigators found traces of a Chinese-language AI penetration-testing tool. The intrusion is suspected to have been a credential-stuffing attack run at scale with AI agents, in which credentials leaked elsewhere are tested automatically against a new target. Sources described the attackers as based overseas, and some experts said Shinhan was probably caught in opportunistic, AI-driven scanning rather than singled out.
What was exposed
The leaked information included customer names, phone numbers, annual income, borrowing amounts and limits, and other personal and credit details from loan applications. Shinhan set up an emergency response team, blocked the attacking IP addresses, suspended the affected service and applied emergency safeguards.
Regulatory response
The Financial Supervisory Service launched an on-site inspection, and financial regulators shared the intrusion methods and IP addresses with other institutions. A day later, KB Kookmin Bank reported abnormal external access to an employee mobile system that exposed names, phone numbers, addresses and encrypted resident registration numbers of 119 customers. Together, the two cases prompted warnings from Korean officials that the whole financial sector is exposed to AI agent-assisted attacks.
Timeline
Attackers access a Shinhan Bank service used by loan agents to check application status and extract customer data.
Shinhan Bank discloses the breach; the Financial Supervisory Service begins an on-site inspection.
KB Kookmin Bank discloses a separate intrusion into an employee mobile system affecting 119 customers.
Sources
- koreaherald.comhttps://www.koreaherald.com/article/10891104
- koreatimes.co.krhttps://www.koreatimes.co.kr/business/banking-finance/20261002/shinhan-kb-kookmin-data-breaches-raise-concerns-over-ai-powered-cyberattacks
- claimsjournal.comhttps://www.claimsjournal.com/news/national/2026/10/02/340519.htm