JupiteX Get the app
Defence & Security10 Oct 2026 · about 6 min

(LEAD) Police expand team investigating recent hacking of financial institutions

The brief

South Korean police are investigating a series of hacking attacks against financial institutions. The attacks affected multiple companies, including Hana Bank, KB Kookmin Bank and Shinhan Bank. The case matters because hackers reportedly breached institutions and stole data, creating risks for financial companies and their customers. The National Office of Investigation added 15 people to the existing 28-member team. This brings the team’s total to 43 investigators. The new personnel include digital forensic experts, who can examine electronic evidence and help reconstruct how the attacks happened. Police are also seeking international cooperation while tracing the attacks’ path. The expansion followed President Lee Jae Myung’s instruction to devote more personnel and resources to preventing and minimizing damage. CrowdStrike linked the attacks to an unidentified Chinese-speaking hacker using AI-powered tools. Logpresso later detected signs that the suspect may belong to Chinese-affiliated DDoS-for-hire organizations, although that connection remains a suggestion.

01

What happened to the South Korean financial institutions, and why did police expand the investigation team?

South Korean police are investigating a series of hacking attacks against financial institutions. The attacks affected multiple companies, including Hana Bank, KB Kookmin Bank and Shinhan Bank. The case matters because hackers reportedly breached institutions and stole data, creating risks for financial companies and their customers.

The National Office of Investigation added 15 people to the existing 28-member team. This brings the team’s total to 43 investigators. The new personnel include digital forensic experts, who can examine electronic evidence and help reconstruct how the attacks happened. Police are also seeking international cooperation while tracing the attacks’ path.

The expansion followed President Lee Jae Myung’s instruction to devote more personnel and resources to preventing and minimizing damage. CrowdStrike linked the attacks to an unidentified Chinese-speaking hacker using AI-powered tools. Logpresso later detected signs that the suspect may belong to Chinese-affiliated DDoS-for-hire organizations, although that connection remains a suggestion.

02

What is a cyberattack, and how can hackers breach a bank's computer systems?

A cyberattack is an unauthorized effort to access, damage or misuse computers, networks or data. For a bank, a successful attack could expose customer information, disrupt services or let criminals take control of systems. The article reports that several South Korean financial institutions were breached and that data was stolen.

Hackers can breach a bank in several ways. They might exploit an unpatched software weakness, trick an employee into revealing credentials, infect a device with malicious software or abuse a stolen password. Once inside, they may move through connected systems and copy information. These are common methods, but the article does not state which method was used here.

CrowdStrike said an unidentified hacker believed to be a Chinese speaker used AI-powered hacking tools. Police added digital forensic experts to trace the attacks. Their work can help identify entry points, follow activity across systems and preserve evidence for the investigation.

03

How many investigators are now working on the case, and how many financial institutions were targeted?

The police investigation grew from 28 members by adding 15 more personnel. That means 43 people are now working on the case. The enlarged team is intended to improve local law enforcement’s ability to respond to the attacks and trace their source.

The article describes the targets as multiple financial companies. It specifically names Hana Bank, KB Kookmin Bank and Shinhan Bank. However, it does not state the total number of financial institutions attacked. Therefore, three is the number of named examples, not necessarily the full count.

The added personnel include digital forensic experts. Police are also working with international partners because the attacks may have crossed national borders or involved overseas infrastructure. CrowdStrike connected the attacks to an unidentified Chinese-speaking hacker using AI-powered tools, while Logpresso reported signs of a possible link to Chinese-affiliated DDoS-for-hire groups.

04

What do digital forensic experts do when investigating a cyberattack?

Digital forensic experts investigate evidence stored or created by computers, networks and other electronic devices. They help determine what happened, when it happened and which systems or accounts were involved. Their findings can support both technical responses and criminal investigations.

In a bank hacking case, experts may examine system logs, files, access records, malware traces and network activity. They can reconstruct how an attacker entered, where the attacker moved and what information was copied or changed. These techniques are general examples; the article does not list the specific evidence being examined in this investigation.

The National Office of Investigation added digital forensic experts to the enlarged team. Police said they have sought to trace the path of the cyberattacks with international cooperation. That work could help connect activity across different systems or countries and clarify who was responsible, although the article does not report a final attribution.

05

What could happen to banks and their customers if hackers steal financial data?

When hackers steal financial data, banks and customers can face serious risks. Exposed information may help criminals attempt fraud, misuse accounts or target victims with further scams. Banks may also need to investigate, secure systems, notify affected people and repair damaged services. These are possible consequences, not losses specifically reported in this article.

The reported attacks involved multiple South Korean financial companies, including Hana Bank, KB Kookmin Bank and Shinhan Bank. CrowdStrike said an unidentified hacker used AI-powered hacking tools to breach institutions and steal data. The article does not say what types of data were taken or whether customers lost money.

The investigation’s expansion reflects the need to limit further damage. Police added 15 personnel, including digital forensic experts, to the 28-member team. President Lee Jae Myung also instructed the government to dedicate more resources to preventing and minimizing harm from the recent series of hacking attacks.

06

Why do police need international cooperation to trace the path of a cyberattack?

International cooperation helps investigators follow a cyberattack when its evidence is spread across countries. An attacker may operate from one location, use infrastructure in another and target systems somewhere else. Access logs, service records and other evidence may therefore be held by foreign companies or authorities.

In this case, South Korean police are trying to trace the path of attacks against multiple financial institutions. The article says they have sought international cooperation for that work. Such cooperation can help investigators compare technical evidence, identify linked activity and pursue information that is outside South Korea’s direct reach. The article does not name the partner countries or agencies.

The need for cooperation also reflects uncertainty about the attacker’s identity. CrowdStrike described an unidentified hacker believed to be a Chinese speaker. Logpresso detected signs suggesting the suspect may belong to Chinese-affiliated DDoS-for-hire organizations. Those suggestions have not been presented as a final police conclusion.

07

How do AI-powered hacking tools and DDoS-for-hire organizations fit into the wider world of modern cybercrime?

Modern cybercrime increasingly combines automated technology with criminal services. AI-powered hacking tools can help attackers search for weaknesses, generate malicious content or adapt attacks more quickly. DDoS-for-hire organizations offer paid disruption services, allowing customers to rent attacks against online targets. These are broad explanations; the article does not detail the tools or services used here.

CrowdStrike said an unidentified hacker believed to be a Chinese speaker used AI-powered hacking tools to breach several South Korean financial institutions and steal data. Logpresso later found signs suggesting the suspect may belong to Chinese-affiliated DDoS-for-hire organizations, including GodNet and VITAS. The report does not establish that membership as fact.

The case shows why investigators need both technical expertise and cooperation across borders. Police added 15 personnel, including digital forensic experts, to the 28-member team. Their task is to trace the attacks and clarify who was involved. Further findings could confirm, refine or challenge the reported connections.

This brief was written by AI from the original reporting and checked by other models. Names, figures and quotes come from the source; read it for full context.

Read more in the JupiteX app

Pulse is free. New stories every 4 hours, each one broken into the questions that explain it.

Or read more news on the web