Shinhan Bank data breach exposes 25,000 customers in suspected AI-assisted cyberattack
Personal information of around 25,000 customers has been leaked from Shinhan Bank, the lender said Thursday, prompting the financial watchdog to conduct an on-site inspection. According to the bank, loan borrowing by…
Source: Korea Herald · October 1, 2026 at 8:02 PM · AI-assisted report
Single-source
SOUTH KOREA, 2 OCTOBER 2026 —
South Korea’s Shinhan Bank confirms 25,000 customer data leak in AI-assisted cyberattack, regulator launches probe
South Korea’s Shinhan Bank disclosed Thursday that personal data—including loan records, annual income, names, and phone numbers—of approximately 25,000 customers was exposed in a cyberattack on Wednesday, with authorities confirming the breach involved AI-powered tools deployed by suspected overseas hackers.
The incident has triggered an on-site inspection by the Financial Supervisory Service (FSS), which began earlier in the day and is expected to last months. Shinhan Bank has activated an emergency response team, implemented IP address blocking, and suspended affected services to contain potential fallout.
Industry experts warned that the bank was likely a random target in a broader wave of AI-driven attacks on vulnerable financial systems, urging other institutions to enhance cybersecurity measures and monitor abnormal access attempts.
According to Shinhan Bank, the leaked data encompassed loan borrowing details, annual income figures, customer names, and phone numbers, though the bank did not specify whether other sensitive information—such as account numbers or financial transaction histories—was compromised. The FSS’s investigation will focus on the scope of the breach, the methods used by attackers, and the bank’s response protocols.
An industry official, speaking to Yonhap, emphasized the systemic risk posed by AI-assisted cyber threats, stating: "The entire financial industry is vulnerable. Institutions must conduct immediate security audits to identify and patch vulnerabilities."
Shinhan Bank’s statement did not attribute the attack to a specific group but noted that forensic analysis suggests the hackers operated from overseas, leveraging automated AI tools to exploit weaknesses in digital infrastructure. The bank has assured customers that no financial losses have been reported to date, though it has not ruled out potential misuse of the exposed data for phishing, identity fraud, or targeted scams.
The FSS has not yet commented on whether criminal charges may be pursued against the perpetrators.
For Malaysia and regional markets, the breach underscores the growing threat of AI-driven cybercrime to financial institutions, particularly as digital banking adoption accelerates across Asia. Local banks, including Maybank, CIMB, and Public Bank, have previously faced similar risks, with regulators such as Bank Negara Malaysia (BNM) tightening cybersecurity guidelines in response. The Shinhan incident may prompt Malaysian authorities to review their own financial sector vulnerabilities, especially as cross-border cyber threats increasingly blur national borders.
The next critical steps will be the FSS’s investigative findings, which could lead to stricter regulatory oversight for South Korean banks and potentially trigger global cybersecurity collaborations to counter AI-assisted attacks.
Related: Shinhan Bank · Financial Supervisory Service (FSS) · South Korea
Malaysia Impact
3/10May prompt Malaysian regulators (e.g., BNM) to review and tighten cybersecurity guidelines for local banks, given cross-border AI-driven cyber threats.
bankingpolicyregulation