South Korea banks to raise cybersecurity spend after AI-assisted hacking hits Shinhan, Hana, KB
Synopsis
Key Takeaways
South Korean banks are moving to significantly increase cybersecurity budgets and headcount after a wave of AI-assisted hacking attacks struck major lenders this month, exposing customer data and prompting a government-level response. The incidents at Shinhan Bank, Hana Bank, and KB Kookmin Bank have raised serious concerns about the scale and sophistication of the breaches, according to industry sources.
What the Breaches Revealed
On 1 October 2026, Shinhan Bank disclosed that personal information belonging to approximately 25,000 customers — including names, phone numbers, and annual incomes — had been leaked. The hackers reportedly deployed advanced artificial intelligence (AI) tools to carry out the attack, marking a notable escalation in the methods used against financial institutions. Similar data leaks or customer information exposures were also reported at other banks, though the full scale of those incidents remains under assessment.
How Banks Plan to Respond
KB Kookmin Bank plans to raise its cybersecurity budget to more than 100 billion won (approximately US$74 million) in 2027, up from 86.07 billion won this year, according to industry sources. Shinhan Bank is reportedly set to allocate a record cybersecurity budget, while Hana Bank plans to invest tens of billions of won in bolstering its security infrastructure next year. All three lenders also intend to expand their cybersecurity personnel in 2026–27.
Government Steps In
South Korean President Lee Jae Myung called over the weekend for a thorough investigation into the attacks. The Financial Supervisory Service (FSS) subsequently identified Internet Protocol (IP) addresses across 12 countries that are suspected of being linked to the AI-assisted hacking campaign, though investigators were reportedly unable to determine physical locations tied to some of those addresses. South Korean police confirmed on Friday that they have assigned additional personnel to the probe, with the National Office of Investigation adding 15 more investigators to an existing 28-member team looking into the attacks against multiple financial companies.
Wider Implications for Financial Security
This comes amid a globally documented rise in AI-enhanced cyberattacks targeting financial institutions, where machine learning tools are increasingly used to automate phishing, bypass authentication, and accelerate data exfiltration. Notably, the simultaneous breach of three major South Korean lenders within a single month signals a coordinated campaign rather than isolated incidents. The cross-border nature of the IP trail — spanning 12 countries — complicates attribution and underscores the limits of domestic law enforcement in countering internationally orchestrated cyber threats. Investigators have not yet publicly attributed the attacks to any specific actor or nation-state.
What Comes Next
With the expanded investigation team now in place and bank budgets set to rise sharply, the key question is whether reactive spending can keep pace with attackers who are already leveraging next-generation tools. Cybersecurity experts have long argued that financial institutions need continuous red-team exercises and AI-native defence systems — not just periodic budget increases — to meaningfully reduce breach risk. South Korea's financial regulators and law enforcement are expected to provide further updates as the cross-border IP investigation progresses.