AI tools suspected in Shinhan Bank cyberattack that exposed 25,000 customers

4 days ago 8



Hackers may have had some help from artificial intelligence when they broke into a Shinhan Bank platform and exposed information tied to about 25,000 customers, Yonhap News reported. What happened at Shinhan Unauthorized access to Shinhan’s systems ran from the early hours of September 29 into September 30, 2026. The bank’s systems flagged suspicious activity at around 9:30 a.m. on September 29. The target was not the bank’s core banking infrastructure. Attackers went after a loan-broker inquiry platform, a separate system that sits apart from the machinery handling deposits and transfers. Personal and financial details of about 25,000 customers were exposed. Among the compromised records were 66 resident registration numbers, along with 97 encrypted identifiers. For context, a resident registration number is South Korea’s national ID number. It is roughly the equivalent of a Social Security number in the US, the kind of identifier that is very hard to change once it is out in the wild. Initial investigations suggest the attackers used advanced AI tools to run what is known as a credential-stuffing attack. Technically, credential stuffing takes usernames and passwords leaked in ear...

Read Entire Article