Korea Bank Breaches: Shinhan’s 25,729 and the Oct 3 ARTEX Log Confirmation
Dated both-sides timeline: Shinhan’s ~25,000–25,729 records (1 Oct), KB, Hana and Busan counts, and the 3 Oct FSI confirmation that ARTEX appeared in Shinhan logs — staff systems, not the customer app.
TL;DR — Between 27 Sep and 1 Oct 2026, South Korean banks reported a cluster of personal-data leaks from staff and partner systems, not from the customer banking app. Shinhan put the exposure at about 25,000 people on 1 Oct (later cited as 25,729), including names, phones, income and loan limits, plus 66 resident-registration numbers and 97 linking IDs (CI). KB Kookmin (119), Hana (89) and BNK Busan (11 contract staff) followed. On 3 Oct, the Korea Financial Security Institute (FSI) told The Herald Business it had found traces of a Chinese open-source tool, ARTEX, in Shinhan logs, and that a person used it — the AI did not act alone. Regulators say direct account transfers look unlikely and voice-phishing is the real consumer risk. The opposition wants the Financial Services Commission grilled at a Thursday 8 Oct audit. Counts are not final.
Last checked: 3 Oct 2026 (KST). Synortex controversy timeline for readers outside Korea. This is not a security advisory and it does not describe how any intrusion worked. Figures move; attribute them to the outlet and the date below.
Why this matters if you do not bank in Seoul
Korea’s big commercial banks sit under a strict network-separation rule: business systems are supposed to stay physically cut off from the open internet. Since June 2026, regulators have been easing that rule on an emergency basis so firms can test AI security tools. The Herald Business reported that the second phase, starting this month, covers 75 firms, 26 more than the 49 in phase one.
The October leaks landed on the other side of that bet. Authorities say the customer internet and mobile apps were not the door. The records that did leave — phone numbers next to annual income and loan limits, and in a thin slice a national ID number — are exactly the raw material for voice phishing, the scam Korean regulators already name as the likely harm. Whether that should slow the network-separation rollback, and who answers for it at the National Assembly next week, is the fight. It is not settled.
Dated timeline
| When (2026, KST) | What was reported | Why it matters | Source |
|---|---|---|---|
| 27 Sep–1 Oct | FSI told Herald the activity was concentrated from Sunday 27 Sep through Thursday 1 Oct. Further banks surfaced after FSI shared addresses seen in the Shinhan review and each bank checked its own logs. | This is being treated as one wave, not four unrelated accidents. FSI said simply blocking addresses was “little more than emergency first aid,” and that related activity was still going on as of the Saturday call. | Herald, 3 Oct exclusive |
| 1 Oct | Shinhan CEO Jung Sang-hyuk posted an apology: an unauthorized outsider had taken customer data from “some service” by an abnormal method. The bank’s count that day was about 25,000. Fields: name, phone, annual income, calculated loan limit, plus 66 resident-registration numbers and 97 CI values. Shinhan said the Super SOL customer app was not involved; the path was a loan-agent lookup on the mobile website. The bank promised to compensate in full if a customer suffers a loss from the leak, and said it had cut off outside addresses, stopped the related service, and applied new security rules. | First public scale. The ID-number counts are small beside 25,000, but those fields are the sensitive ones. Compensation is if harm occurs, not a blanket cash payout. | Yonhap, 1 Oct; Asia Economy, 1 Oct |
| 1 Oct, morning | The Financial Services Commission (FSC) and the Financial Supervisory Service (FSS) held an emergency meeting. Yonhap reported FSI had already been on site since the day before, and that a final written finding could take months. | The regulator clock started before the cross-bank picture was public. | Yonhap, 1 Oct |
| 1 Oct | The National Assembly Political Affairs Committee adopted 18 general witnesses and 2 reference witnesses for audits of the FSC, the Fair Trade Commission and the privacy regulator. No financial-group chair and no commercial-bank CEO was on that list. | The witness slate was locked before the cluster became the week’s story. Adding bank chiefs later is a separate negotiation. | Dailian, 2 Oct |
| 2 Oct | KB Kookmin confirmed an outside intrusion leaked personal and credit data on 119 customers: name, phone, address, and encrypted resident-registration numbers. The target was an employee mobile work system, not internet or mobile banking. The same day, Democratic Party lawmaker Park Sang-hyeok (the ruling side’s lead on the committee) wrote that he would summon the five major bank presidents and “hold them strictly accountable.” | Second named bank, much smaller count, same shape: staff system, not the customer app. Political demand for CEOs in the hearing room starts here. | Dailian, 2 Oct |
| 2 Oct (Friday) | Herald reported the FSC held another emergency meeting with the FSS, FSI, major banks and card companies, and ordered a review of externally reachable IT systems — what is exposed, how logins are checked, and whether checks were skipped on data lookups — plus sharing of attack-linked addresses across firms. | Authorities’ own framing: a sector problem of outside-facing internal tools, not a single broken app. | Herald audit story, 3 Oct |
| 3 Oct, ~12:31 | FSI, in a phone call with Herald: investigators traced Shinhan logs and addresses and found ARTEX had been used. The official said industry suspicion was correct, then drew a line: “It is true that AI was used in the attacks, but the AI did not act independently without human involvement. A hacker used the AI as a tool.” Herald describes ARTEX as an open-source, LLM-based penetration-testing platform distributed mainly on GitHub and aimed at Chinese-speaking users. | This is the first official confirmation Synortex can cite, and it is narrow: traces in the Shinhan investigation, via FSI speaking to one paper. It is not a finished report on every bank. | Herald exclusive, 3 Oct |
| 3 Oct, same call | Banks’ own figures, as Herald reported them: Shinhan 25,729 via the loan-agent inquiry service; KB 119; Hana 89 from an employee sales-support system (ODS); BNK Busan 11 contract workers. Woori and NH NongHyup were targeted; FSI said the specific weaknesses sought were not present, so there was no breach and no duty to report. FSI’s running total of affected people: just under 26,000, and it can rise. Two savings banks are still being checked. Yegaram Savings Bank had already posted that an unidentified intruder accessed it and personal data leaked. FSI also said many more institutions were hit than those with a confirmed incident, including some outside banking. | Almost all of the headcount is Shinhan. The rest of the wave is small counts plus a savings-bank unknown. Yegaram’s notice is not an FSI confirmation that ARTEX was used there. | Herald exclusive, 3 Oct |
| 3 Oct | FSI’s harm view: the intruder did not take over the systems; officials do not expect money to be transferred straight out of accounts; leaked data could still be used for voice phishing. FSI is drafting a recommendation that firms audit employee-facing outside access points; the FSC plans to send it out. An FSC official called several banks having similar problems at once “a very extraordinary set of circumstances.” On an older Government24 portal incident, FSI said it cannot check that data and suspects a different actor because the timing is far apart. | Regulators are selling low direct-theft risk and high scam risk. A link to the government portal is an explicit non-finding. | Herald exclusive, 3 Oct |
| 3 Oct, afternoon | People Power Party spokesperson Park Sung-hoon said bank security is “the last line of defense” for the public’s assets and credit, and that the incidents are “a warning signal to the defense network of South Korea’s financial security, going beyond a simple personal data leak.” PPP said it will press the FSC on whether routine supervision worked before the leaks. Herald also reported police have opened a preliminary investigation into Shinhan, KB, Hana and Busan. The same story said the FSS was still investigating how far AI was used in each incident. | Opposition case: oversight failure, not only a bank IT miss. Same-day caveat: a Shinhan log hit is not yet a published finding on every bank’s AI use. | Herald, 3 Oct |
| Thu 8 Oct (scheduled) | Political Affairs Committee questions the FSC. Herald’s morning preview said the deadline to name witnesses for that session has already passed, so the five bank CEOs are unlikely to be in the room on Thursday. | The audit will still be about the regulator. CEO testimony, if it happens, is a later argument. | Herald preview, 3 Oct; Herald, 3 Oct |
| 19 Oct (scheduled) | FSS national audit. Herald and Dailian both treat this — and a later comprehensive finance audit — as the live negotiation for extra witnesses, including possibly bank presidents. Nothing is adopted yet. | The political half of this story does not end on 8 Oct. | Herald preview, 3 Oct; Dailian, 2 Oct |
Counts, as attributed — not a final toll
| Institution | People reported | What reporters said was exposed | System named | Status |
|---|---|---|---|---|
| Shinhan | ~25,000 (bank apology, 1 Oct); 25,729 (Herald, 3 Oct) | Name, phone, annual income, loan limit; 66 resident-registration numbers; 97 CI | Loan-agent inquiry service. Bank: not the customer app | Public apology and compensation-if-harm pledge |
| KB Kookmin | 119 (bank, reported 2 Oct) | Name, phone, address, encrypted resident-registration numbers | Employee mobile work system, not customer banking | Confirmed by the bank |
| Hana | 89 (Herald, 3 Oct) | Herald did not itemize fields | Employee sales-support system (ODS) | Bank figure via Herald |
| BNK Busan | 11 | Personal data on outsourced / contract staff, not a mass customer file | Not itemized beyond that | Bank figure via Herald |
| Woori, NH NongHyup | No confirmed leak | — | Targeted; FSI said the weaknesses sought were absent | No damage, no report required |
| Two savings banks, incl. Yegaram’s own notice | Not in the “under 26,000” as a finished number | Yegaram: personal data leaked after unidentified access | Logs still with FSI | Open |
| FSI running total | Just under 26,000 | Can rise | Across the confirmed bank cases | As of the 3 Oct call |
Shinhan’s 1 Oct “about 25,000” and the later 25,729 are the same incident tightening, not two leaks. Do not add KB, Hana and Busan on top of 25,729 and call it a new total — FSI’s “under 26,000” already sits just above Shinhan’s figure.
A separate July case at Woori — 17,551 nickname and ID records held by an outside developer, which Yonhap attributed to staff error at that vendor — is not this cluster. It is only context: Yonhap called the Shinhan event the second commercial-bank personal-data incident of 2026.
Both sides
Regulators and the banks (as stated)
- Not the customer app. Shinhan said Super SOL was unrelated. FSI said every attack in this wave hit employee or partner systems, and that customer electronic finance had been “enormously strengthened” while internal systems were managed less rigorously. The official added that the management surface is so wide that firms themselves struggled to see where the weak points were.
- AI was a tool, not the actor. FSI: a person used ARTEX; the model did not run the attack alone. The institute also said there is no practical way to restrict every open-source AI tool “being developed and distributed around the world.”
- Money-movement risk is low; scam risk is not. No expected direct transfers. Voice phishing is the harm they name. FSC will be asked to recommend a full look at employee-facing outside doors. The commission calls the simultaneous pattern extraordinary.
- Some targets held. Woori and NongHyup were hit in the attempt and, on FSI’s account, did not leak.
Opposition, and the industry argument about the rules
- Supervision, not only a bad server. PPP spokesperson Park Sung-hoon framed the leaks as a warning to the financial-security defense network. The party says Thursday’s FSC hearing should ask whether day-to-day oversight saw this class of exposed internal service before customers did.
- Put the CEOs on the record. Park Sang-hyeok wants the five bank presidents as witnesses. As of 3 Oct, that demand had missed the witness deadline for the 8 Oct FSC session. It is a pledge, not a subpoena.
- Network separation. Herald reported that some observers think a wave aimed at internal systems could stall the emergency easing that has been widening since June (49 firms, then 75). That is a political forecast. No authority has said the easing is cancelled.
- Design of the Shinhan door. A financial-industry official told Yonhap that letting loan agents check application status on a website “is not the usual setup,” and that a hard block on abnormal access did not appear to be in place. That is an industry criticism of exposure, not a published FSI cause report.
Synortex reading: the consumer stake is phishing fuel from loan files, concentrated at one bank. The political stake is whether a regulator that is loosening network separation can explain staff-side systems that were already reachable. Neither side has a final report.
Still unresolved
- Savings banks. Two are under log review. Yegaram has disclosed a leak on its own site. FSI has not put ARTEX on that notice, and Synortex will not.
- Per-bank AI use. The noon exclusive is Shinhan logs. Herald’s afternoon audit story still said the FSS was investigating how far AI was used in each incident.
- Headcount. “Under 26,000” is a Saturday snapshot. Yonhap already warned the Shinhan cause report could take months. FSI told Herald it has no clear end date, because several firms surfaced at once and the institute’s staff is stretched. Police have a preliminary case. Addresses were shared with police because the traffic came from overseas; that is not an identified suspect. No charged person is named in these reports.
- Government24. FSI suspects a different actor and says it cannot verify a link. Treat any “same campaign” claim as unsupported.
- Other sectors. FSI said organizations outside banking were also attacked, and that far more institutions were targeted than those with a confirmed leak. It did not publish that list on 3 Oct.
- Thursday’s hearing can grill the FSC without the bank CEOs in the chair. Whether those CEOs appear on 19 Oct is unfinished bargaining.
FAQ
Did someone drain accounts?
FSI told Herald it does not expect funds to be transferred directly. The stated risk is voice phishing and similar scams using leaked identity and loan data. Shinhan’s promise is full compensation if a customer is harmed by this leak, per the 1 Oct apology as reported by Asia Economy.
Was the mobile banking app broken?
Shinhan says no. FSI says this wave targeted employee and partner systems. KB’s 119 records were on an employee mobile work system, not customer internet or mobile banking.
Did an AI hack the banks by itself?
FSI’s line on 3 Oct: AI was used, and a person used it. Confirmation cited so far is traces in the Shinhan investigation, not a blanket finding for every later report.
Is 25,729 the whole story?
It is Shinhan’s figure as Herald reported it on 3 Oct, inside an FSI total of just under 26,000 that officials say can still rise. KB, Hana and Busan are the other confirmed slices in that reporting. Savings banks are the open variable.
Sources
- The Herald Business, 3 Oct 2026 — FSI confirms ARTEX traces in the Shinhan investigation (Korean: 10892496)
- The Herald Business, 3 Oct 2026 — breaches head into the FSC audit (Korean: 10892529)
- The Herald Business, 3 Oct 2026 — national-audit preview, witness deadline, 19 Oct FSS session
- Yonhap, 1 Oct 2026 — Shinhan loan-agent service, field list, emergency meeting
- Asia Economy, 1 Oct 2026 — CEO apology and compensation pledge
- Dailian, 2 Oct 2026 — witness list, KB’s 119, Park Sang-hyeok
Image: "Skyline of Yeouido, a prominent finance district in Seoul" by S h y numis, CC BY 4.0, via Wikimedia Commons.
← Back to all posts