A coordinated wave of cyberattacks has exposed personal data at seven South Korean financial institutions, with authorities investigating whether an artificial intelligence-based hacking tool was used to carry out the breaches.
South Korean President Lee Jae Myung raised the issue at a cabinet meeting on October 6, 2026. “In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety. Please establish the circumstances swiftly and clearly, and concentrate personnel and resources on minimizing the damage,” Lee said, according to Reuters.
Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Welcome Savings Bank, Yegaram Savings Bank and Hyundai Capital were among the institutions affected. Woori Bank and NH NongHyup Bank detected intrusion attempts but reported no breaches, according to The Korea Herald.
Yegaram Savings Bank disclosed the largest single breach, with about 40,000 customer records compromised. Shinhan Bank reported data from about 25,000 customers exposed, the Korea JoongAng Daily reported.
Read next: What the Gemini and Claude hacking incidents mean for cyber insurers
The stolen information included names, phone numbers, resident registration numbers, loan application details and calculated credit limits, the Korea JoongAng Daily reported. Authorities found the same attacker IP address across all seven firms, pointing to a single coordinated campaign, according to The Korea Herald.
The Korea Herald reported that traces of a Chinese-developed AI-based penetration-testing platform called Artex were found in the attacks. The tool reportedly selects its next intrusion method based on the results of previous attempts. South Korean authorities have not confirmed that attribution.
The attackers targeted external-facing systems used by employees and loan agents rather than core transaction networks, the Korea JoongAng Daily reported.
Detection was slow. Shinhan Bank took about 15 hours to identify its breach, Hana Bank about 42 hours and KB Kookmin Bank about 68 hours, the same outlet reported.
Financial Services Commission (FSC) chairman Lee Eog-weon convened an emergency meeting with financial industry leaders and ordered firms to block external access unless it was essential for business. “We cannot rule out the possibility of attacks using AI. We need to check the entire security framework to ensure there are no gaps,” Lee Eog-weon said, as reported by The Korea Herald.
The Financial Supervisory Service (FSS) alerted about 500 financial firms to malicious IP addresses tied to the attacks, the Korea JoongAng Daily reported. The FSS identified about 30 associated IP addresses across 12 countries and territories, The Korea Times reported.
South Korean financial authorities also issued a consumer alert and launched a month-long fraud prevention effort. No customer financial losses had been confirmed as of October 6, 2026, The Korea Times reported.
For the institutions affected, whether the attackers used an AI tool is unlikely to decide how their own cyber cover responds. These were deliberate criminal intrusions, and first-party cyber policies are generally triggered by unauthorised access to the insured’s systems, whatever tools the attacker used.
The more pressing coverage questions are about scale and cost. Breach response for tens of thousands of affected customers involves notification, investigation, credit monitoring and regulatory engagement, and those costs mount quickly. Resident registration numbers and loan details are among the most sensitive data a financial institution holds, which raises the potential for regulatory penalties and third-party claims. Detection times of up to 68 hours also lengthen the window in which data could be taken and widen the investigation required.
South Korean financial institutions also operate under specific requirements to hold insurance or reserves against electronic financial incidents and personal data breaches. Those statutory minimums set a floor, but a coordinated campaign of this scale is a reminder that minimum requirements and adequate limits are not the same thing.
Where AI does raise coverage questions is in how financial institutions use it themselves. A November 2025 survey by cybersecurity firm Delinea of more than 750 security leaders found that 42% said their cyber insurance policies specifically exclude AI misuse or liability. As banks deploy AI in lending, customer service and fraud detection, that exclusion trend is the AI wording question brokers placing financial institution cyber risk are most likely to face.
Pricing adds another layer. “Cyber insurance has rarely been more affordable, yet cyber risk has rarely been more consequential. That disconnect won’t exist forever,” Jack Bassett, cyber and technology regional leader for the Pacific at Howden, wrote in the firm’s H1 2026 cyber report, referring to the Australian and New Zealand market. Incidents on the scale of the Korean breaches are the kind of losses that test whether soft pricing elsewhere in the region can hold.
Read next: South Korea targets AI insurance fraud as detection systems come under strain
The Hong Kong Monetary Authority (HKMA) warned financial institutions in a June 2026 letter that “frontier A.I. models could mark a step change in the global cyber risk landscape.” The letter directed banks to review whether their existing controls remain adequate, and announced a new Cyber Resilience Testing Framework.
In Singapore, the Monetary Authority of Singapore (MAS) proposed new AI risk management guidelines for all regulated financial institutions in November 2025. In March 2026, it partnered with 24 industry participants through Project MindForge to develop an AI risk management toolkit.
For brokers advising financial institution clients across the region, the Korean attacks put the practical questions in sharp relief: whether limits reflect the volume and sensitivity of customer data held, how quickly a client could detect and contain a breach, and how its cover treats the costs of responding to regulators and customers at scale.