Police investigation following several data leaks
South Korea has launched a large-scale investigation into a series of cyberattacks against financial institutions. At least seven institutions reported customer data leaks, according to AFP coverage published by O Globo. Institutions mentioned in various reports include Shinhan Bank, KB Kookmin, Hana Bank, and Woori Bank.
South Korean President Lee Jae Myung said that indications of artificial intelligence (AI) use had emerged in some incidents and called on his ministers to quickly clarify what had happened and focus resources on limiting the damage. This is a suspicion under investigation, not confirmation of which system was used or how the intrusions were carried out. The authorities have also not publicly identified those responsible.
The available figures are not consistent
Published reports give different figures. O Globo, citing South Korea’s Financial Services Commission, reported that more than 68,000 people were affected. Other media outlets detailed specific incidents: elDiario.es attributed the exposure of data relating to loans held by around 25,000 customers to Shinhan Bank, and reported that the Hana Bank incident affected 89 customers. These partial figures should not be interpreted as a total count, nor are they directly comparable with the aggregate figure.
Counts of IP addresses linked to the attack attempts also vary. Reuters reported that the Financial Supervisory Service and the Financial Security Institute shared data on 28 unique IP addresses; other media outlets, such as Cinco Días and Negocios.com, reported a count of 19 addresses associated with 12 countries. The sources do not provide enough context to reconcile the two counts. In any case, an IP address associated with an operation does not, by itself, prove the origin or identity of the person who carried it out.
According to AFP, no money had been reported stolen so far; the known issue was the exposure of data. The published information does not provide a definitive account of the leaked data or establish whether all the incidents followed the same method.
Authorities’ response and attention to risk
The chairman of the Financial Services Commission, Lee Eog-weon, convened an emergency meeting with regulators, industry associations, and executives from the affected institutions. Meanwhile, the Financial Supervisory Service shared technical information with the sector to help detect activity related to the attacks. Reuters said the agency distributed data on 28 unique IP addresses; other reports described inspection and system review measures, which do not, in themselves, resolve the investigation.
For businesses, the incident highlights that an intrusion can have consequences even when access to funds has not been established: exposure of personal information can increase the risk of subsequent impersonation or fraud attempts. This possibility does not mean that such harm occurred in this case. The available sources also do not confirm that credentials enabling unauthorized payments were leaked.
The investigation is taking place in South Korea and remains open. Until the authorities publish their findings, it is advisable to distinguish between the reported facts—reported attacks, exposed data, and the institutional response—and the hypotheses concerning AI use, the techniques employed, and the attackers’ origins.