INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Shinhan and KB form 'Basic Control' with Hana separation

| 2026-10-06 02:30 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
A massive data breach exposed sensitive information of hundreds of millions of customers in South Korea, with Shinhan Bank, KB Kookmin Bank, and Hana Bank being under scrutiny for their handling of customer data. The breach involved the use of artificial intelligence to launch a series of hacking attacks on the banks' external work support and inquiry systems, rather than their core financial transaction systems. Approximately 25,000 people's data was compromised at Shinhan Bank, while Citizens Bank customers saw 119 of their information exposed, and Hana Bank customers saw 89 of their information exposed. The attackers targeted individual users who were able to bypass authentication and access customer information, which was then used to extract additional information. Seven banks in total were affected by the same attack, with the same IP address being used, but some banks were able to avoid damage due to basic security controls such as restricted access to loan application systems and multi-authentication measures.
Technical Mitigations AI-generated
• Use multi-authentication to prevent unauthorized access, as seen in NH NongHyup Bank's implementation of separate certificate and biometric authentication. • Implement repeated login blockage to prevent attackers from accessing systems from the same IP address, a feature used by banks that were able to prevent the attack. • Restrict access to sensitive systems to only be accessed from designated terminals or devices, as seen in Woori Bank's restriction of loan application system access to a tablet terminal.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
KR
financefinance governmentgovernment
Incident Timeline
‎2025/10/06
Citizens Bank invested the most in information security among four major banks, with a total of 43.3 billion won, according to the Financial Services Commission's Personal Credit Information Utilization and Management Continuous Evaluation.
organisation Citizens Bank
general_metric 43.3 banks
organisation Financial Security
organisation the Financial Services Commission's
‎2026/09/06
Threat actors used artificial intelligence to launch a series of hacking attacks that resulted in the recent data breach.
tactic Data Breach
‎2026/10/06
Seven major South Korean banks, including Shinhan Bank and Hana Bank, were hit by a cyberattack lasting approximately forty-two hours.
organisation KB
organisation Hana
organisation Shinhan Bank
organisation KB Kookmin Bank
organisation Hana Bank
organisation KISA
organisation Woori Bank
organisation Hana Bank's
organisation ODS
organisation IP
organisation NH NongHyup Bank
organisation the Ministry of Science
organisation ICT
organisation Korea Information Protection Target
organisation Continuous Evaluation of Information Protection
organisation the Information Protection Commendation
organisation the Financial Commission
organisation The Financial Supervisory Commission
victims 119 customers
victims 89 customers
Tactical Metrics
Metrics
victims
119
Customers
Metrics
victims
89
Customers