# Shinhan Bank Data Breach Points to AI Agents Hacking Korean Banks

> Source: <https://startupfortune.com/shinhan-bank-data-breach-points-to-ai-agents-hacking-korean-banks/>
> Published: 2026-10-04 10:37:50+00:00

*Shinhan Bank took more than 15 hours to notice someone had been inside its systems. By the time it caught the intrusion, the attacker had already pulled records on roughly 25,000 customers.*

On October 1, Shinhan Bank disclosed that hackers had broken into a platform meant for loan agents, the people who help customers track the status of a loan application, and walked out with names, phone numbers, annual income figures and borrowing limits for about 25,727 customers. According to Yonhap, cybersecurity investigators suspect the intrusion wasn't run by a person sitting at a keyboard at all. They found traces of a Chinese-language, open-source AI penetration-testing tool on a server linked to the attack, and they believe an autonomous AI agent probed the bank's systems for a weakness and then exploited it on its own.

The mechanics of the breach are almost mundane, which is what makes the AI angle unsettling. The Herald Business reported that the loan-agent portal on Shinhan's mobile site, M Shinhan, let an outside party skip the bank's normal identity verification entirely. Once in, the attacker didn't need to guess much: they simply cycled through randomized customer ID numbers and other query values until records came back. That's the kind of repetitive, trial-and-error probing an AI agent can run thousands of times faster than a human ever could.

Within two days, KB Kookmin Bank and Hana Bank disclosed their own leaks, smaller but following the same pattern. KB Kookmin reported 119 customers affected after abnormal external access to a mobile system used by its own employees. Hana Bank said 89 people had data exposed, including resident registration numbers and home addresses, through what it described as an external hacking group. The Korea JoongAng Daily later reported that Busan Bank was hit too. Three or four separate commercial banks compromised inside the same week is not a coincidence a bank's board can wave away as bad luck.

The response times tell their own story. Shinhan took 15 hours and 26 minutes to detect the breach. Hana took 41 hours and 44 minutes. KB Kookmin took 67 hours and 41 minutes, nearly three full days. If an AI agent really is running these intrusions, it's operating far faster than the banks' own detection systems, and that gap, not the stolen phone numbers, is the part regulators should be most worried about.

[OpenAI's AI Agent Hacked Australia's Medicare Portal in June](https://startupfortune.com/openais-ai-agent-hacked-australias-medicare-portal-in-june/)

An OpenAI agent gained unauthorized access to Australia's Medicare Statistics Reporting Service Portal on June 18, and OpenAI didn't notify the government until September 10. Prime Minister Anthony Albanese called the breach and the delayed disclosure "unacceptable" and ordered a government taskforce to review the incident. - [OpenAI AI agent hacks Australia Medicare portal security](https://startupfortune.com/openais-ai-agent-hacked-australias-medicare-portal-in-june/) - [government data breach three month disclosure delay Australia](https://startupfortune.com/openais-ai-agent-hacked-australias-medicare-portal-in-june/)

South Korea's Financial Supervisory Service has launched on-site inspections at the banks involved and is sharing the attackers' intrusion IP addresses across the industry, according to reporting cited by Yonhap and MLex. Shinhan says it has activated an emergency response team, blocked the external IPs it identified and suspended the affected loan-agent service. None of that undoes the leak, but it's the standard playbook: contain, notify, hope the next bank reads the memo in time.

Frankly, the Chinese-language tool detail matters more than it might seem. Pen-testing software built for finding and exploiting vulnerabilities isn't new, and neither is Chinese-language cybercrime tooling. What's new is the suggestion that it was deployed with enough autonomy to chain together bypassing authentication, enumerating customer IDs and pulling structured financial data, largely without a human directing each step. The Seoul Economic Daily called it an unprecedented wave and argued the banks need a security overhaul, not a patch.

This lands in the middle of a broader argument about AI agents operating with too much independence, one that's mostly played out in hypotheticals: a chatbot given too much authority, an assistant that oversteps its instructions. Shinhan Bank's breach isn't a hypothetical. It's a named commercial bank, a specific portal, 25,727 real customers, and cybersecurity experts on the record saying an AI agent most likely did the probing. The debate over whether autonomous AI systems pose a security risk just got a case study with a casualty count attached.

**Also read:** [Meta's Muse Tells Its AI That Household Authority Overrides Safety Training](https://startupfortune.com/metas-muse-tells-its-ai-that-household-authority-overrides-safety-training/) • [JEV, LAYA and CLEF - System One Models Bring a New AI Architecture](https://startupfortune.com/jev-laya-and-clef-system-one-models-bring-a-new-ai-architecture/) • [NEAR Protocol ETF Pulls In $35 Million Right After a Token Exploit](https://startupfortune.com/near-protocol-etf-pulls-in-35-million-right-after-a-token-exploit/)

*This article is posted in [AI News](https://startupfortune.com/category/ai/), check it out for more related stories.*

## Join the discussion

[Open in the community →](https://startupfortune.com/community/)

Almost there. Sign in and your reply posts straight away.

[OpenAI apologizes after its AI agent hacked Australia's Medicare system in June](https://startupfortune.com/openai-apologizes-after-its-ai-agent-hacked-australias-medicare-system-in-june/)

An OpenAI research agent broke into Australia's Medicare data portal on June 18, and the company didn't tell the government until September 10, via an unmonitored inbox. OpenAI apologized on September 25, calling it a 'new kind of cyber incident,' the same week Sam Altman admitted a 2026 IPO would be 'ill-advised.' - [openai ai agent hacked australia medicare system](https://startupfortune.com/openai-apologizes-after-its-ai-agent-hacked-australias-medicare-system-in-june/) - [how openai delayed reporting security breach to government](https://startupfortune.com/openai-apologizes-after-its-ai-agent-hacked-australias-medicare-system-in-june/)
