AI-powered bank hacks in South Korea put cyber insurance gaps under scrutiny
Suspected AI-enabled cyberattacks on major South Korean banks exposed tens of thousands of customer records and raised questions about coverage adequacy
AI-powered bank hacks in South Korea put cyber insurance gaps under scrutiny
CYBER
By Roxanne Libatique
08 Oct 2026

A coordinated wave of cyberattacks has exposed personal data at seven South Korean financial institutions, with authorities investigating whether an artificial intelligence-based hacking tool was used to carry out the breaches.

South Korean President Lee Jae Myung raised the issue during a cabinet meeting on October 6, 2026. “In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety. Please establish the circumstances swiftly and clearly, and concentrate personnel and resources on minimizing the damage,” Lee said, according to Reuters.

Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Welcome Savings Bank, Yegaram Savings Bank, and Hyundai Capital were among the institutions affected. Woori Bank and NH NongHyup Bank detected intrusion attempts but reported no breaches, according to The Korea Herald.

Yegaram Savings Bank disclosed the largest single breach, with approximately 40,000 customer records compromised. Shinhan Bank reported data from roughly 25,000 customers exposed, the Korea JoongAng Daily reported.

Read next: What the Gemini and Claude hacking incidents mean for cyber insurers

What data was stolen and how?

The stolen information included names, phone numbers, resident registration numbers, loan application details and calculated credit limits, the Korea JoongAng Daily reported. Authorities found the same attacker IP address across all seven firms, pointing to a single coordinated campaign, according to The Korea Herald.

The Korea Herald reported that traces of a Chinese-developed AI-based penetration-testing platform called Artex were found in the attacks. The tool reportedly selects its next intrusion method based on the results of previous attempts. That attribution has not been confirmed by South Korean authorities.

The attackers targeted external-facing systems used by employees and loan agents rather than core transaction networks, the Korea JoongAng Daily reported.

Detection was slow. Shinhan Bank took approximately 15 hours to identify its breach, Hana Bank roughly 42 hours and KB Kookmin Bank about 68 hours, the same outlet reported.

How have regulators responded?

Financial Services Commission (FSC) chairman Lee Eog-weon convened an emergency meeting with financial industry leaders and ordered firms to block external access unless essential for business. “We cannot rule out the possibility of attacks using AI. We need to check the entire security framework to ensure there are no gaps,” Lee Eog-weon said, as reported by The Korea Herald.

The Financial Supervisory Service (FSS) alerted approximately 500 financial firms to malicious IP addresses tied to the attacks, the Korea JoongAng Daily reported. The FSS identified about 30 associated IP addresses across 12 countries and territories, The Korea Times reported.

South Korean financial authorities also issued a consumer alert and launched a monthlong fraud prevention effort. No customer financial losses had been confirmed as of October 6, 2026, The Korea Times reported.

Why should brokers care?

The South Korean breaches arrive at a time when cyber insurance pricing and cyber risk severity are moving in opposite directions across the region.

“Cyber insurance has rarely been more affordable, yet cyber risk has rarely been more consequential. That disconnect won’t exist forever,” Jack Bassett, cyber & technology regional leader for the Pacific at Howden, wrote in the firm’s H1 2026 cyber report.

Most cyber policies were written with human threat actors in mind. If an AI tool can autonomously probe systems, select attack methods, and exploit weaknesses without direct human instruction, brokers placing financial institution cyber risk will need to check whether current policy wordings cover that scenario.

A November 2025 survey by cybersecurity firm Delinea of more than 750 security leaders found that 42% of respondents said their cyber insurance policies specifically exclude AI misuse or liability.

Read next: South Korea targets AI insurance fraud as detection systems come under strain

Regulators across the region are already moving

The Hong Kong Monetary Authority (HKMA) warned financial institutions in a June 2026 letter that “frontier A.I. models could mark a step change in the global cyber risk landscape.” The letter directed banks to review whether existing controls remain adequate and announced a new Cyber Resilience Testing Framework.

In Singapore, the Monetary Authority of Singapore (MAS) proposed new AI risk management guidelines for all regulated financial institutions in November 2025, then partnered with 24 industry participants in March 2026 through Project MindForge to develop an AI risk management toolkit.

The Asia-Pacific cyber insurance market is growing at a compound annual growth rate of 16.12% from 2026 to 2031, the fastest of any region globally, according to Mordor Intelligence. For brokers advising financial institution clients on how cyber risk investments are shaping the insurance market, the South Korean attacks have made the coverage question concrete.

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB ASIA.