Seoul puts 28 investigators on bank breaches affecting 66,000 people
South Korean police on Tuesday assigned 28 investigators in four teams to suspected intrusions at seven financial firms. Shinhan disclosed 25,729 affected customers. Regulators circulated 28 IP addresses and told firms to finish security checks by Thursday.

Seoul3 min read
Last updated
The Korean National Police Agency on Tuesday put 28 investigators, in four teams from its cyberterrorism unit, onto a run of intrusions at South Korean financial firms. By Sunday, seven institutions had reported breaches: Shinhan, KB Kookmin, Hana and BNK Busan banks, Yegaram and Welcome savings banks, and Hyundai Capital. Reports put the combined exposure at about 66,000 people and 2,200 corporate records. Shinhan, which disclosed on 1 October, counted 25,729 customers. Yegaram Savings Bank accounted for about 40,000 of the individual records.
President Lee Jae Myung raised the case in Tuesday's Cabinet meeting. He said the country should speed the development and deployment of artificial intelligence tools built for cybersecurity, and that it was time to overhaul the security model for the AI era. He said speed was of the essence, because technical change was outrunning the measures meant to counter it, and he asked for an immediate review of critical systems. The Serious Crimes Investigation Agency had already opened a file on Friday. The Financial Supervisory Service issued a statement on Tuesday. The Financial Services Commission is in the circle of agencies now on the case.
What regulators have actually handed the banks
The concrete instruction is narrower than the president's line about a new model. Regulators circulated 28 IP addresses linked to the attempts and told financial firms to finish security checks by Thursday. Woori and NH NongHyup were named among firms drawn into the check even where a public breach count has not been posted. An IP list is a lead, not an attribution. Twenty-eight addresses can be rented, shared, or abandoned within hours. The Thursday deadline forces each firm to say whether those addresses touched its network and which logs still exist.
Kim Seung-joo, a professor at Korea University's School of Cybersecurity, told CBS radio that the attacks may have involved ARTEX, a tool that uses AI to look for weak points. He said tools of that kind will keep appearing and will make it easier for people who are not specialists to run an intrusion. Police have not confirmed ARTEX, or any other named tool, in a charging document. The professor's point is about the labour market for this kind of attack: a scanner that writes its own next probe lowers the skill needed to walk through a bank's customer-file server.
Why the numbers do not yet explain the method
Sixty-six thousand personal records and 2,200 corporate records is a large notification. It is not, by itself, evidence of stolen money. South Korean banks have spent a decade under rules that split customer data from transaction systems and that require notice when names, numbers and account identifiers leave a controlled store. A breach count can therefore rise fast once a firm decides the legal test is met, even if the intruder did not move funds. Shinhan's 25,729 and Yegaram's roughly 40,000 are notice figures. They are not a loss figure.
The investigative shape is what changed on Tuesday. A cyberterrorism unit with 28 people, a presidential instruction, a 28-address list and a Thursday check are the operational facts. Whether the same cluster hit all seven firms, whether ARTEX was on the wire, and whether any won moved, are still open. The customer letters will go out on the notice counts. The charges, if they come, will have to name a person or a tool the IP list only points toward.