The Shinhan Bank cyberattack has exposed personal and financial information belonging to about 25,000 customers in South Korea, with investigators examining whether advanced artificial intelligence tools were used to carry out the intrusion.
The leaked information reportedly includes customers’ names, phone numbers, loan borrowing details and annual income. South Korea’s Financial Supervisory Service has launched an emergency on-site inspection as authorities investigate how the breach occurred and whether the suspected use of AI points to a wider risk for financial institutions.
Shinhan Bank said the information was leaked on Wednesday after hackers gained access to its systems. The bank immediately formed a response team and took measures aimed at limiting further damage.
These measures included blocking access from external IP addresses and suspending the affected services. The bank said it had completed safety measures related to the incident.
Sources cited in the reports said the attackers are suspected to be based overseas and may have used advanced AI tools during the attack. Experts said the bank may not have been specifically targeted, but could instead have been caught in attacks against vulnerable online platforms.
The Financial Supervisory Service sent a team to the bank to examine the incident. Its investigation is expected to take months as officials determine the nature and extent of the data exposure.
The suspected use of AI has added another concern to the Shinhan Bank breach. Cybersecurity experts said AI tools originally developed or shared for defensive purposes can also be adapted for malicious activity.
Mun Chong-hyun, director at cybersecurity firm Genians, said several recent attacks in South Korea have involved such AI tools. He described the technology as a double-edged sword because capabilities created for cybersecurity can also be used to facilitate cybercrime.
The concern is not limited to Shinhan Bank. An industry official said the wider financial sector could be exposed to AI agent-assisted attacks, and that financial institutions should conduct their own security checks to identify potential weaknesses and abnormal access attempts.
The incident also highlights the type of information that can be exposed in attacks against banks. Unlike a breach involving only basic contact information, the Shinhan incident reportedly exposed both personal details and financial information.
The Shinhan Bank cyberattack comes amid several recent incidents affecting South Korean lenders.
KB Kookmin Bank said last Friday that personal information belonging to 119 customers had been leaked following an external intrusion. Hana Bank also reported a separate hack affecting 89 customers.
South Korea’s Financial Services Commission has already held a meeting with local banks over the recent breaches and is expected to hold another meeting this week.
The latest incidents have raised concerns about how AI-powered hacking could affect the financial sector, particularly if attackers can use automated tools to identify vulnerable systems or support attacks at greater scale.
The Shinhan incident is relatively small compared with some of South Korea’s largest data breaches in terms of the number of affected people. However, the combination of personal and financial information makes the breach significant.
Sungho Hwang, Korea country manager at NordVPN, said the exposed information could be used to create personalized scams. He also noted that generative AI has made such scams more convincing.
The banking incidents come as South Korea cyberattacks have increased across other sectors.
Cyberattacks targeting South Korean military systems reached 18,951 cases in 2025, the highest annual figure in five years. The number was up 31 percent from 2024 and 108 percent from 2022.
South Korea has also expanded its use of AI for defensive cybersecurity. The Ministry of Education and the Korea Education and Research Information Service operate an AI-based system designed to detect suspicious activity and issue automated alerts across 435 monitored institutions.
In 2025, the system detected about 480 million potential cyber threat indicators, of which around 86,000 were confirmed as actual intrusions.
As the investigation into the Shinhan Bank breach continues, the suspected role of AI is adding to concerns that financial institutions may need to account for increasingly automated forms of cyberattacks.