Skip to content
Seoul financial district street at night after rain

TL;DR: Shinhan disclosed a leak of names, phones, incomes and loan limits for about 25,000 people, plus 66 resident-registration numbers and 97 ID codes. Investigators say attackers used ARTEX, an AI pentest platform, on partner and staff systems rather than public mobile banking. KB, Hana and Busan banks reported much smaller exposures. It is an industry security failure under investigation, not a finding that an autonomous agent emptied accounts.

Status note: Checked 4 October 2026 against Yonhap's 1 October disclosure, Seoul Economic Daily and Kyunghyang accounts of the Shinhan numbers, Herald Business reporting on 3 October that the Korea Financial Security Institute traced ARTEX, and Shinhan Financial Group's 6-K saying impact is not yet quantified. Victim counts and tool attribution can still move as the Financial Supervisory Service inspection continues.

What Shinhan says left the building

On 1 October 2026 Shinhan said an unauthorized outsider used abnormal means to bypass authentication between 29 September and the early hours of 30 September. The breach sat in a simplified inquiry service on "M Shinhan," a mobile site loan brokers use to check application status. Attackers altered code, entered inquiry values, pulled customer numbers, then stole contact and credit fields.

Exposed items, the bank and Korean press said, included names, phone numbers, annual incomes and calculated loan limits for about 25,000 customers. Herald Business later put Shinhan's figure at 25,729. Also leaked: 66 resident-registration numbers and 97 "CI" connecting identifiers. Yonhap said the Financial Supervisory Service sent examiners the same day and that the investigation could take months.

Shinhan blocked external IP addresses, suspended the affected services, stood up an emergency team, and pledged full compensation if customer losses are confirmed. In a 6-K, Shinhan Financial Group said it cannot yet reasonably quantify any effect on finances or operations.

ARTEX, and what that word does not mean

Yonhap cited sources saying suspected overseas hackers used advanced AI tools, and industry voices called the whole sector vulnerable to "AI agent-assisted" attacks. On 3 October, Herald Business reported that the Korea Financial Security Institute traced Shinhan attack IPs and server logs to ARTEX AI, a Chinese-developed, large-language-model pentest platform. An institute official said Saturday that industry suspicions about ARTEX were accurate.

That is a tool in a human operation. It is not evidence that a consumer chatbot at Shinhan independently decided to export a customer file. Every attack described in that report hit internal employee or partner systems, not retail internet or mobile banking apps.

The smaller copies at other lenders

Herald Business, citing the same probe, said KB Kookmin reported 119 records leaked from an employee mobile work-support system, Hana Bank 89 records from an ODS sales-support system, and BNK Busan Bank information on 11 contract workers. Two savings banks were under investigation for similar patterns. Combined identified victims sat just under 26,000, almost all at Shinhan, with room to rise.

Because the attacks appear to have originated overseas, the institute has been sharing attacker IPs with police since the first report. There is no public timeline for closing the file.

Where things stand

South Korean banks had a bad week on partner-facing web tools. Shinhan's 25,000-person leak is the large confirmed case. ARTEX, if the institute's trace holds, is how the door was tested, not a verdict that "AI robbed the bank." Watch the FSS inspection, any rise in victim counts, and whether prosecutors name operators. Do not treat a 6-K that cannot quantify losses as a completed damage bill.

Sources: Yonhap on the Shinhan leak, 1 October 2026; Seoul Economic Daily on the 25,000-customer figure and compensation pledge; Herald Business on the Financial Security Institute ARTEX finding, 3 October 2026.