JupiteX Get the app
Science & Technology11 Oct 2026 · about 6 min

Banks mull higher cybersecurity spending after AI-linked hacking incidents: sources

The brief

South Korea’s major banks faced a series of hacking incidents in October. Shinhan Bank, Hana Bank and KB Kookmin Bank reported leaks or exposure of customer information. The incidents matter because banks hold sensitive personal data, and the breaches raised concerns about how widespread the damage could become. Shinhan Bank disclosed on October 1 that information belonging to about 25,000 customers had been leaked. The exposed details included names, phone numbers and annual incomes. The article reports that hackers reportedly used advanced artificial intelligence tools in that attack. Other banks also reported similar leaks or exposure, but the article gives no detailed list of their affected data. The Financial Supervisory Service identified IP addresses in 12 countries suspected of links to AI-assisted attacks. Investigators could not determine locations connected to some addresses. In response, banks are considering larger cybersecurity budgets and more personnel, while President Lee Jae Myung called for a thorough investigation.

01

What hacking incidents affected South Korea's major banks, and what customer information was exposed?

South Korea’s major banks faced a series of hacking incidents in October. Shinhan Bank, Hana Bank and KB Kookmin Bank reported leaks or exposure of customer information. The incidents matter because banks hold sensitive personal data, and the breaches raised concerns about how widespread the damage could become.

Shinhan Bank disclosed on October 1 that information belonging to about 25,000 customers had been leaked. The exposed details included names, phone numbers and annual incomes. The article reports that hackers reportedly used advanced artificial intelligence tools in that attack. Other banks also reported similar leaks or exposure, but the article gives no detailed list of their affected data.

The Financial Supervisory Service identified IP addresses in 12 countries suspected of links to AI-assisted attacks. Investigators could not determine locations connected to some addresses. In response, banks are considering larger cybersecurity budgets and more personnel, while President Lee Jae Myung called for a thorough investigation.

02

What does “AI-linked hacking” mean, and how can hackers use artificial intelligence in an attack?

“AI-linked hacking” refers to a cyberattack in which attackers use artificial intelligence tools as part of their methods. The phrase matters because AI can potentially make some attacks faster, more adaptable or easier to scale. The article specifically reports that advanced AI tools were reportedly used against Shinhan Bank, but it does not explain exactly how.

In general, attackers might use AI to automate reconnaissance, create convincing phishing messages, analyze stolen information or adjust malicious code. These uses could help them target victims or systems more efficiently. However, those examples are established cybersecurity possibilities, not details confirmed about the attacks in this article.

The reported incidents prompted South Korean banks to reconsider their defenses. KB Kookmin plans to raise its cybersecurity budget, while Shinhan and Hana also plan larger investments. Banks expect to add cybersecurity personnel next year as investigators examine suspected AI-assisted activity.

03

How large are the reported breaches and planned security investments—for example, how many Shinhan customers were affected and how much will KB Kookmin spend?

The article reports one quantified breach and several major planned investments. Shinhan Bank said personal information belonging to about 25,000 customers was leaked. The information included names, phone numbers and annual incomes. Other banks reported similar incidents, but the article does not provide their affected customer totals.

KB Kookmin Bank plans to increase cybersecurity spending to more than 100 billion won, or US$74 million, in 2027. Its budget this year is 86.07 billion won. The planned increase shows that the bank views the recent AI-linked attacks as serious enough to require substantially greater protection.

Shinhan plans a record cybersecurity budget. Hana plans to invest tens of billions of won in stronger security systems next year. All three banks also plan to increase cybersecurity personnel. The article does not provide exact future totals for Shinhan or Hana, or a total breach size across the banking sector.

04

What could happen to bank customers and the financial system if stolen personal information is misused?

Stolen personal information can create risks for customers even when the article does not report actual misuse. Names, phone numbers and annual incomes could help criminals target people with convincing scams or attempt identity-related fraud. Customers may also face privacy loss, financial harm and the burden of securing affected accounts.

The reported Shinhan breach involved information from about 25,000 customers. If criminals combine those details with other information, they may build more persuasive profiles of victims. The article does not say that this happened, so these are possible consequences rather than confirmed results of the attacks.

At the financial-system level, repeated breaches could reduce confidence in banks and raise costs for monitoring, investigation and security upgrades. Disruption or widespread fraud could affect many institutions. The article confirms that the incidents raised concerns about the potential scale of breaches, but it does not describe any systemwide disruption or losses.

05

Why are Shinhan, Hana and KB Kookmin increasing cybersecurity budgets and personnel after these attacks?

Shinhan, Hana and KB Kookmin are increasing cybersecurity efforts because recent hacking incidents exposed or may have exposed customer information. The attacks created concern about their possible scale, and one Shinhan incident reportedly involved advanced AI tools. That combination has pushed banks to reassess whether existing defenses and staffing are sufficient.

KB Kookmin plans to spend more than 100 billion won on cybersecurity in 2027, compared with 86.07 billion won this year. Shinhan plans a record cybersecurity budget. Hana plans to invest tens of billions of won in stronger security systems next year. The banks also plan to add cybersecurity personnel.

The response follows President Lee Jae Myung’s call for a thorough investigation. The Financial Supervisory Service identified suspected attack-linked IP addresses in 12 countries, although some locations remained unclear. The banks’ planned investments aim to strengthen defenses as investigations continue and AI-linked threats receive greater attention.

06

What can investigators learn from an attack’s IP addresses, and why might those addresses fail to reveal where the hackers actually are?

An Internet Protocol address is a network identifier that can provide clues about where online activity appears to originate. Investigators can compare such addresses with geographic records, connect related activity and identify possible infrastructure used during an attack. The Financial Supervisory Service found IP addresses in 12 countries suspected of links to the AI-assisted attacks.

An address may point to a server, network or other intermediary rather than the attacker’s own device. Attackers can route activity through systems in other places, making the apparent country different from their real location. The article does not identify the exact techniques used in these incidents, but it confirms that some addresses could not be tied to locations.

Therefore, IP evidence can guide an investigation without proving who carried out an attack or where they were physically present. The FSS’s findings provide leads, not a complete attribution. Investigators still need to determine the locations linked to the unresolved addresses and connect the evidence.

07

What is cybersecurity, and how does it protect a bank’s computer systems, customer data and financial transactions?

Cybersecurity is the set of technologies, rules and trained personnel used to protect computer systems, networks and data. In a bank, it helps prevent unauthorized access, detect suspicious activity and keep digital services operating. It matters because banks manage sensitive customer information and financial transactions.

Protection can include secure access controls, monitoring, software updates, data safeguards and systems that detect or block attacks. Banks also investigate incidents and improve defenses when weaknesses appear. The article does not list the exact tools used by the South Korean banks, but it reports leaks involving customer information and suspected AI-assisted attacks.

The banks are responding by increasing planned spending and staffing. KB Kookmin expects to spend more than 100 billion won in 2027. Shinhan plans a record budget, and Hana plans tens of billions of won for stronger systems. These measures are intended to improve resilience as investigations continue.

This brief was written by AI from the original reporting and checked by other models. Names, figures and quotes come from the source; read it for full context.

Read more in the JupiteX app

Pulse is free. New stories every 4 hours, each one broken into the questions that explain it.

Or read more news on the web