On October 4, 2026, South Korean President Lee Jae Myung called for a detailed investigation into a series of data breaches that have compromised sensitive information from both customers and employees in the financial sector. The directive follows concerns that attackers may have leveraged AI tools to infiltrate systems used by banks and financial institutions. President Lee was briefed on the breaches at both financial and public institutions, which led to his directive for a full investigation. Presidential spokesperson Kang Yu-jung emphasized the gravity of the situation and the need for robust measures in response.

The breaches began with Shinhan Bank on October 1, where data from approximately 25,000 customers was exposed. This included names, phone numbers, annual income, and loan limits, as well as some resident registration numbers. The following day, KB Kookmin Bank and Hana Bank reported additional breaches. KB revealed that personal and credit information of 119 customers had leaked through an employee work-support system, while Hana reported unauthorized access to its operations support system, affecting 89 customers.

Hana Bank's breach included sensitive details like names, resident registration numbers, and contact information. BNK Busan Bank also reported the exposure of data from 11 outsourced workers. The breaches have not been limited to banks; nonbank financial entities like Yegaram Savings Bank and Hyundai Capital were also affected, with data leaks impacting 40,000 customers and 146 housing loan agents, respectively.

Evidence suggests that an AI-based automation tool may have been used in these attacks. However, the investigation has yet to confirm if a single group orchestrated all breaches or if AI played a definitive role in each incident. Current findings indicate that the breaches exploited loan agent websites and employee support systems rather than customer-facing banking applications. Consequently, financial authorities have mandated widespread security checks across banking and card companies, focusing on supporting business systems that could store sensitive data.

The ongoing investigation aims to clarify the attack vectors and prevent future breaches. Previous incidents, such as the Korean Leaks campaign and AI-driven phishing attacks, highlight the importance of safeguarding personal data to prevent further exploitation.