Skip to content
TrustList
News

South Korea's FSC orders a financial-sector security review after suspected AI-driven attacks on six banks

Editorial

By TrustList Editorial

After suspected AI-driven attacks exposed customer data at Shinhan, KB Kookmin, Hana and other banks, South Korea's Financial Services Commission ordered firms on 2 October to inventory external systems and close authentication gaps.

About South Korea's FSC orders a financial-sector security review after suspected AI-driven attacks on six banks

South Korea's FSC orders a financial-sector security review after suspected AI-driven attacks on six banks

2 October 2026 — South Korea's Financial Services Commission (FSC) held an emergency meeting on Friday 2 October 2026 and ordered financial firms to review their externally reachable systems, after attacks suspected to have been carried out with AI agents exposed customer data at several banks, according to reports by Korea JoongAng Daily and Seoul Economic Daily.

Not yet independently verified. Two Korean outlets report the meeting and the orders; we have not read the Financial Services Commission's own release. The AI-agent attribution is the authorities' suspicion as reported, and the affected-customer figures are not yet confirmed by the banks. We will update this when it can be confirmed, and remove this note.

What happened

The reports name KB Kookmin, Shinhan, Hana, Woori, NH Nonghyup and BNK as targets. At Shinhan, about 25,000 customers' data was exposed through a lookup page for loan brokers that required only a code sent by text message, with no certificate. KB Kookmin reported 119 customers affected through an employee mobile support system, Hana 89 through a sales-support system, and BNK 11 cases. The pattern described is automated probing of less-protected side doors: partner portals and staff tools rather than core banking systems.

What the regulator ordered

According to the reports, the FSC told financial firms to take an inventory of all externally reachable IT assets, including AI systems, and run security checks on them; to find any routes to internal data that bypass authentication; and to share attacking IP addresses and intrusion logs with KISA and other agencies and report findings promptly. The FSC said it would develop further regulatory measures, and the Financial Supervisory Service sent an inspection team to Shinhan.

Who is affected

Korean banks, card companies, insurers and fintechs, and the software vendors that build or host their broker portals, partner extranets and staff mobile tools. Foreign vendors serving Korean financial firms should expect questionnaires that follow the FSC's checklist.

What to do

  1. List every internet-facing application that can reach customer data, including portals for brokers, agents and partners.
  2. Remove single-factor access, such as text-message codes alone, from any page that returns customer records.
  3. Add rate limiting and anomaly detection for automated lookups; AI-driven probing tends to look like many small, valid-seeming queries.
  4. Vendors: prepare evidence of authentication strength and logging for the portals you run for Korean financial clients.
  5. Watch for the FSC's follow-up measures.

Why it matters for buyers

If the attribution holds, this is one of the first cases where a financial regulator has responded to attacks it believes were run by AI agents. The weakness exploited was ordinary, a lookup page with weak authentication, but automation makes such pages far cheaper to find and drain. Every regulated buyer should expect similar reviews.

Sources

Categories & features