South Korea bank hacks: President Lee orders probe into data leaks at Hana, Shinhan, KB
Synopsis
Key Takeaways
South Korean President Lee Jae Myung on Sunday, 4 October 2026, ordered authorities to conduct a thorough investigation into a spate of AI-assisted hacking attacks that have compromised customer data at several of the country's largest financial institutions, including Hana Bank, Shinhan Bank, and KB Kookmin Bank. The directive signals the highest level of government attention to what is fast becoming one of South Korea's most serious financial cybersecurity crises in recent memory.
What the President Said
Presidential spokesperson Kang Yu-jung confirmed the instruction in a press release. 'President Lee was briefed on the recent data breaches at financial and public institutions and the measures taken in response,' she said. 'He instructed authorities to take the matter seriously, conduct a thorough investigation and spare no effort in coming up with measures to address the issue,' she added.
Scale of the Breaches
The most significant confirmed leak occurred at Shinhan Bank, where personal information of approximately 25,000 customers — including names, phone numbers, and annual income data — was compromised. According to reports, the attackers reportedly exploited advanced artificial intelligence tools to breach the bank's defences. At Hana Bank, data belonging to 89 customers was confirmed to have been exposed. Separately, Woori Bank and NH Nonghyup Bank were also targeted in similar intrusion attempts, though both institutions reported that no customer data was exfiltrated, as unauthorised access was detected and blocked in time.
Emergency Regulatory Meeting Convened
Financial Services Commission Chairman Lee Eog-weon and Lee Chan-jin, governor of the Financial Supervisory Service, were scheduled to convene an emergency meeting on Sunday to discuss the situation directly with the heads of the affected firms. Notably, the meeting had originally been planned for Wednesday but was brought forward after hacking attempts spread to additional institutions over the intervening days — a detail that underscores the rapid escalation of the threat.
AI-Assisted Attacks Raise the Stakes
The reported use of advanced AI tools in the Shinhan Bank attack marks a qualitative shift in the sophistication of financial cyber threats in South Korea. This comes amid a broader global trend of threat actors leveraging machine learning to probe and exploit vulnerabilities in banking infrastructure at scale. Critics and cybersecurity experts are likely to press regulators on whether existing frameworks — built for an earlier generation of attack vectors — are adequate against AI-augmented intrusions. The back-to-back nature of the incidents, hitting multiple institutions within a compressed timeframe, also raises questions about whether there is a coordinated actor or a common vulnerability being systematically exploited.
What Happens Next
The emergency regulatory meeting is expected to produce a set of immediate remedial directives for the affected banks, as well as a broader assessment of systemic vulnerabilities across the sector. Investigators will likely work to determine whether the attacks are linked and whether a single threat actor or group is responsible. Affected customers at Shinhan Bank and Hana Bank are expected to be formally notified and offered protective measures. The outcome of the probe ordered by President Lee will be closely watched as a benchmark for South Korea's response to the emerging threat of AI-driven financial cyberattacks.