South Korea bank hacks: President Lee orders probe into data leaks at Hana, Shinhan, KB

Share:
Audio Loading voice…
South Korea bank hacks: President Lee orders probe into data leaks at Hana, Shinhan, KB

Synopsis

South Korea's largest banks — Hana, Shinhan, and KB Kookmin — have been hit by a rapid succession of AI-assisted hacking attacks, leaking data on thousands of customers and prompting President Lee Jae Myung to personally demand a thorough investigation. With regulators pulling forward an emergency meeting and AI tools confirmed in at least one breach, this signals a dangerous new frontier in financial cybercrime.

Key Takeaways

South Korean President Lee Jae Myung on 4 October 2026 ordered a thorough investigation into hacking attacks on major financial institutions.
Shinhan Bank confirmed personal data of approximately 25,000 customers — including names, phone numbers and annual income — was leaked, reportedly via AI-assisted hacking tools.
Hana Bank confirmed data of 89 customers was exposed; Woori Bank and NH Nonghyup Bank were targeted but blocked unauthorised access before any data was taken.
KB Kookmin Bank was also among the institutions affected in the back-to-back series of attacks.
An emergency meeting between Financial Services Commission Chairman Lee Eog-weon and Financial Supervisory Service Governor Lee Chan-jin and affected bank heads was convened on Sunday , brought forward from a planned Wednesday session as the attacks spread.

South Korean President Lee Jae Myung on Sunday, 4 October 2026, ordered authorities to conduct a thorough investigation into a spate of AI-assisted hacking attacks that have compromised customer data at several of the country's largest financial institutions, including Hana Bank, Shinhan Bank, and KB Kookmin Bank. The directive signals the highest level of government attention to what is fast becoming one of South Korea's most serious financial cybersecurity crises in recent memory.

What the President Said

Presidential spokesperson Kang Yu-jung confirmed the instruction in a press release. 'President Lee was briefed on the recent data breaches at financial and public institutions and the measures taken in response,' she said. 'He instructed authorities to take the matter seriously, conduct a thorough investigation and spare no effort in coming up with measures to address the issue,' she added.

Scale of the Breaches

The most significant confirmed leak occurred at Shinhan Bank, where personal information of approximately 25,000 customers — including names, phone numbers, and annual income data — was compromised. According to reports, the attackers reportedly exploited advanced artificial intelligence tools to breach the bank's defences. At Hana Bank, data belonging to 89 customers was confirmed to have been exposed. Separately, Woori Bank and NH Nonghyup Bank were also targeted in similar intrusion attempts, though both institutions reported that no customer data was exfiltrated, as unauthorised access was detected and blocked in time.

Emergency Regulatory Meeting Convened

Financial Services Commission Chairman Lee Eog-weon and Lee Chan-jin, governor of the Financial Supervisory Service, were scheduled to convene an emergency meeting on Sunday to discuss the situation directly with the heads of the affected firms. Notably, the meeting had originally been planned for Wednesday but was brought forward after hacking attempts spread to additional institutions over the intervening days — a detail that underscores the rapid escalation of the threat.

AI-Assisted Attacks Raise the Stakes

The reported use of advanced AI tools in the Shinhan Bank attack marks a qualitative shift in the sophistication of financial cyber threats in South Korea. This comes amid a broader global trend of threat actors leveraging machine learning to probe and exploit vulnerabilities in banking infrastructure at scale. Critics and cybersecurity experts are likely to press regulators on whether existing frameworks — built for an earlier generation of attack vectors — are adequate against AI-augmented intrusions. The back-to-back nature of the incidents, hitting multiple institutions within a compressed timeframe, also raises questions about whether there is a coordinated actor or a common vulnerability being systematically exploited.

What Happens Next

The emergency regulatory meeting is expected to produce a set of immediate remedial directives for the affected banks, as well as a broader assessment of systemic vulnerabilities across the sector. Investigators will likely work to determine whether the attacks are linked and whether a single threat actor or group is responsible. Affected customers at Shinhan Bank and Hana Bank are expected to be formally notified and offered protective measures. The outcome of the probe ordered by President Lee will be closely watched as a benchmark for South Korea's response to the emerging threat of AI-driven financial cyberattacks.

Point of View

And that compliance frameworks designed for conventional intrusion methods may already be obsolete. President Lee's directive is symbolically important, but the harder question is structural — South Korea's financial sector needs to determine quickly whether these attacks share a common vector, and whether its threat-intelligence sharing between banks and regulators is fast enough to prevent the next wave. The public notification gap for the 25,000 Shinhan customers is also a test of the country's data protection culture.
NationPress
4 Oct 2026

Frequently Asked Questions

Which South Korean banks were hacked and what data was leaked?
Shinhan Bank, Hana Bank, and KB Kookmin Bank were among the institutions targeted. Shinhan Bank confirmed that personal data of around 25,000 customers — including names, phone numbers and annual income — was leaked. Hana Bank reported data of 89 customers was exposed. Woori Bank and NH Nonghyup Bank were also targeted but successfully blocked unauthorised access before any data was taken.
What did South Korean President Lee Jae Myung say about the bank hacks?
President Lee Jae Myung directed authorities to take the breaches seriously and conduct a thorough investigation, ordering them to spare no effort in finding solutions. His spokesperson Kang Yu-jung confirmed the presidential instruction in a press release on Sunday, 4 October 2026.
How were the banks hacked — what role did AI play?
Reports indicate that the hackers who breached Shinhan Bank reportedly used advanced artificial intelligence tools to carry out the attack. The precise method has not been publicly disclosed in full, but the use of AI-assisted intrusion techniques marks a significant escalation in the sophistication of the threat.
What is South Korea's financial regulator doing in response?
The Financial Services Commission and the Financial Supervisory Service convened an emergency meeting on Sunday with the heads of affected banks. The meeting was originally scheduled for Wednesday but was moved forward as the damage spread to additional institutions. Immediate remedial directives and a broader review of systemic vulnerabilities are expected to follow.
What should customers of the affected banks do?
Customers of Shinhan Bank and Hana Bank — where data was confirmed to have been leaked — should monitor their accounts for unusual activity and await formal notification from their respective banks. Regulators are expected to mandate protective measures for affected customers as part of the emergency response.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 3 hours ago
  2. Yesterday
  3. 7 months ago
  4. 9 months ago
  5. 11 months ago
  6. 1 year ago
  7. 1 year ago
  8. 1 year ago
Google Prefer NP
On Google