South Korea’s national police have opened a preliminary inquiry into a series of cyberattacks targeting major banks, as investigators assess the extent of customer information exposure and whether an artificial intelligence-based tool was involved. The National Police Agency’s Cyber Terror Response Investigation Unit is examining incidents involving Shinhan Bank, KB Kookmin Bank, Hana Bank and BNK Busan Bank.

Police began examining the Shinhan incident on Oct. 1 and added the other three banks on Oct. 2, according to the Dong-A Ilbo. The inquiry remains at the pre-booking stage, meaning authorities are gathering facts before deciding whether to open a formal criminal investigation. Investigators are expected to trace the attack routes, compare the incidents and determine whether they came from a coordinated campaign.

Inquiry target
Shinhan, KB Kookmin, Hana and BNK Busan banks
Police unit
National Police Agency Cyber Terror Response Investigation Unit
Current status
Pre-booking inquiry before a decision on formal investigation

Shinhan Bank said approximately 25,000 customers’ personal information had been exposed in a new type of attack involving an AI agent, the Dong-A Ilbo reported. The information included 66 resident registration number records and 97 customer identification linkage records, along with data such as names, telephone numbers, annual income and calculated information. The available evidence does not provide comparable exposure totals for the other banks.

Reports from MBC and the Kyunghyang Shinmun said investigators found signs of a Chinese-language autonomous penetration tool. The tool was suspected of identifying weaknesses in bank security networks and designing attack paths. That finding has prompted concern that AI may have helped automate parts of the intrusion, but police have not yet publicly established that AI directed the attacks or identified who operated the tool.

Reported exposure varies across the affected banks

The incidents extended beyond the four banks where information exposure was reported. Woori Bank and NH NongHyup Bank also faced attempted intrusions, according to the Kyunghyang Shinmun, but no customer information was reported leaked from those two institutions. The distinction matters for customers because an attempted breach does not by itself establish that personal data was obtained.

For affected customers, the immediate risk depends on precisely which records were accessed and whether they can be combined for impersonation, phishing or other fraud. Customers of the banks involved should rely on official notices from their institutions, scrutinize unexpected messages requesting credentials or financial information, and avoid treating unverified contact as a legitimate bank communication.

The police inquiry will need to establish whether the attacks shared infrastructure, code or operators, and whether the apparent autonomous tool independently selected vulnerabilities or merely assisted a human attacker. Investigators must also determine the full number of affected customers and clarify the security controls breached at each institution.

Investigators must separate automation from human control

A decision to convert the inquiry into a formal investigation would bring additional procedural consequences under South Korea’s reorganized criminal justice system. MBC reported that police would first have to notify the newly established Serious Crimes Investigation Agency that they had identified a case potentially falling within the seven major crime categories. Until that decision is made, the central findings remain provisional: several banks were targeted, customer information was exposed at four institutions, and AI involvement is suspected rather than conclusively proven.