Detect Deepfakesby Resemble AI
Agentic AI attack

Shinhan Bank agentic AI attack — Oct 2026

South Korean banks including Shinhan and KB Kookmin suffered data breaches linked to autonomous AI agents executing credential stuffing attacks on business.

Reported date
Oct 2, 2026
Target
Shinhan Bank, KB Kookmin Bank, Hana Bank, and BNK Busan Bank
Agent type
Other AI agent
Agent role
Used by the attacker

The exact incident date was not established. This entry is dated by its source report.

Updated Oct 4, 2026 · 2 min read

Major South Korean financial institutions have experienced a series of data breaches attributed to the use of autonomous AI agents. The incidents, which impacted Shinhan Bank, KB Kookmin Bank, Hana Bank, and BNK Busan Bank, have prompted investigations by the National Police Agency and the Financial Supervisory Service.

What happened

The attacks are believed to involve the use of ARTEX AI, an autonomous penetration testing tool based on large language models. Security experts identified traces of this tool on servers associated with the attacks, noting that such agents can autonomously plan and execute vulnerability discovery and exploitation without human intervention. The primary method utilized was credential stuffing, where attackers tested stolen credentials against business-use systems.

The impact varied across the targeted institutions:

  • Shinhan Bank: The largest breach, affecting 25,000 records on a mobile page used by loan solicitors. Compromised data included names, phone numbers, annual income, and credit limits.
  • KB Kookmin Bank: 119 customer records were compromised via an employee mobile work-support system.
  • Hana Bank: 89 customer records were leaked, including resident registration numbers and contact information.
  • BNK Busan Bank: Contact information for 11 outsourced employees was accessed.

Banks detected abnormal access attempts between the 29th and 30th of the previous month, leading to emergency measures such as IP blocking. While the banks emphasized that the breaches occurred on business-use systems rather than core internet banking infrastructure, authorities have ordered comprehensive security reviews of all externally exposed IT assets. The National Police Agency is currently conducting an internal investigation, as officials suspect the same perpetrator may be responsible for the simultaneous attacks due to matching IP addresses and consistent methodologies. Experts warn that the speed at which AI agents can exploit software vulnerabilities creates a significant challenge for institutions, as they may be unable to patch systems before an automated attack occurs. Investigations remain ongoing, and officials have cautioned that the total scope of the damage could expand.

Evidence in the reporting

Incident evidence
Major South Korean commercial banks have been breached in succession
Agent involvement
traces of ARTEX AI, an autonomous penetration testing tool

Sources