KB Kookmin Bank data breach: 100+ customers hit by AI-powered hack

Share:
Audio Loading voice…
KB Kookmin Bank data breach: 100+ customers hit by AI-powered hack

Synopsis

Two of South Korea's biggest banks — Shinhan and KB Kookmin — have been hit by data breaches within 48 hours of each other, with overseas hackers reportedly using AI tools to exploit vulnerable platforms. With over 25,000 Shinhan customers and 100-plus KB Kookmin customers exposed, regulators are now sounding a sector-wide alarm about AI-assisted cyberattacks on financial institutions.

Key Takeaways

KB Kookmin Bank confirmed a data breach affecting over 100 customers , with names, phone numbers, and encrypted identification stolen.
Shinhan Bank disclosed a separate breach on 1 October , compromising data of approximately 25,000 customers including loan records and annual income details.
Hackers are reportedly suspected to be based overseas and used advanced AI tools in both attacks.
Shinhan Bank was likely caught in random AI-powered sweeps of vulnerable platforms, not a targeted attack, according to experts.
South Korea's financial watchdog has launched an on-site inspection of Shinhan Bank; broader regulatory scrutiny is expected.
Industry officials are calling for mandatory security audits across all financial institutions to address potential vulnerabilities.

KB Kookmin Bank, one of South Korea's largest commercial lenders, has suffered a data breach affecting the personal information of over 100 customers, industry sources said on Friday, 2 October 2026. The incident follows a similar attack on rival Shinhan Bank a day earlier, intensifying fears of a systemic cybersecurity crisis across South Korea's banking sector.

What Was Stolen

According to sources, the compromised data at KB Kookmin Bank includes customer names, phone numbers, and encrypted identification details. The bank confirmed the breach and stated that any damage caused by the leak would be fully compensated.

Shinhan Bank Breach: A Day Earlier

On Thursday, 1 October, Shinhan Bank disclosed that personal information of approximately 25,000 customers had been compromised via hacking. The leaked data included loan borrowing records, annual income details, names, and phone numbers. Shinhan said it took emergency steps to minimise potential damage, and South Korea's financial watchdog has since launched an on-site inspection of the lender.

AI-Powered Attacks Suspected

Cybersecurity experts believe the attackers, reportedly suspected to be based overseas, leveraged advanced artificial intelligence (AI) tools to extract sensitive information. Notably, Shinhan Bank does not appear to have been a specific target — experts suggest it was likely caught in randomised, AI-powered sweeps of vulnerable online platforms. This underscores the indiscriminate and scalable nature of next-generation cyberattacks on financial infrastructure.

'The entire financial industry is vulnerable to AI agent-assisted attacks. Financial institutions need to promptly conduct their own security inspections to address potential vulnerabilities,' an industry official said.

Wider Industry Alarm

The back-to-back breaches have triggered broader alarm across South Korea's financial sector. Insiders warn that other institutions may face similar exposure if they fail to immediately audit their systems and block abnormal access attempts. This is the second major banking data leak in Seoul within 48 hours, raising urgent questions about the adequacy of cybersecurity frameworks governing the country's financial institutions.

What Comes Next

Regulators are expected to widen their scrutiny beyond Shinhan Bank to other lenders, including KB Kookmin. Industry bodies have called for mandatory security inspections across all financial institutions. With AI-assisted attacks growing in sophistication and frequency, South Korean banks face mounting pressure to overhaul their digital defences before more customer data is put at risk.

Point of View

Which means any institution with exploitable vulnerabilities is equally at risk. That shifts the threat model entirely: the question is no longer whether a bank is prominent enough to be targeted, but whether it is secure enough to survive ambient, automated aggression. South Korean regulators launching a single on-site inspection of one bank is an inadequate response to a sector-wide vulnerability. The real test is whether financial watchdogs can move faster than the attackers are iterating.
NationPress
2 Oct 2026

Frequently Asked Questions

What happened in the KB Kookmin Bank data breach?
KB Kookmin Bank suffered a cyberattack in which personal data of over 100 customers — including names, phone numbers, and encrypted identification — was stolen. The bank confirmed the breach and pledged full compensation for any resulting damage.
How is the Shinhan Bank breach connected?
Shinhan Bank disclosed on 1 October that approximately 25,000 customers had their personal data — including loan records, annual income, names and phone numbers — compromised via hacking. Both breaches are believed to involve overseas hackers using AI tools, and the incidents occurred within 48 hours of each other.
Who is behind the attacks on South Korean banks?
Hackers are reportedly suspected to be based overseas and are believed to have used advanced artificial intelligence tools to execute the breaches. Experts say Shinhan Bank was likely caught in a random AI-powered sweep of vulnerable platforms rather than a deliberate, targeted attack.
What are regulators doing about the breaches?
South Korea's financial watchdog has initiated an on-site inspection of Shinhan Bank following its disclosure. Broader regulatory scrutiny of other lenders, including KB Kookmin Bank, is expected as authorities assess the scale of the threat.
Why are AI-powered cyberattacks on banks particularly dangerous?
AI-assisted attacks can autonomously scan and exploit vulnerabilities across large numbers of platforms simultaneously, making them indiscriminate and highly scalable. Experts warn that the entire financial industry is vulnerable and have called for prompt, sector-wide security inspections to identify and close gaps.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 1 month ago
  2. 1 month ago
  3. 2 months ago
  4. 4 months ago
  5. 5 months ago
  6. 8 months ago
  7. 9 months ago
  8. 1 year ago
Google Prefer NP
On Google