Sunday, October 11, 2026

160 Were Gathered and Warned—but the Financial Sector Was Breached Just Two Weeks Later

Input
2026-10-11 09:20:43
Updated
2026-10-11 09:20:43
Yonhap News Agency
[Financial News] The financial sector, already hit by a large-scale personal data breach, was found to have failed to prepare despite receiving an explicit advance warning from the Financial Security Institute about AI-powered hacking attacks just two weeks before the breach. With it confirmed that security officials from affected financial firms attended the seminar in large numbers, the firms are expected to face scrutiny over allegations of inadequate preparation.
According to materials obtained from the Financial Security Institute by Han Chang-min, a Social Democratic Party lawmaker on the National Assembly’s National Policy Committee, the institute held a “Financial AI Security Threat Response Seminar” for financial firms’ security officials on the 17th of last month.
At the seminar, the institute reportedly shared a real-world case of an AI agent attacking Company A in South Korea’s financial sector, along with specific countermeasures. About 160 people attended, including officials from five of the seven financial institutions affected by the incident, among them Shinhan Financial Group, KB Kookmin Bank, Hana Bank, Hyundai Capital and Welcome Savings Bank.
According to the presentation materials, the attacker instructed a DeepSeek-based AI agent to scan specific server software assets in the financial sector, then exploited a server vulnerability to install malware (a web shell) in just one day.
This method was virtually identical to that used by the group behind the current wave of attacks, which combined the Chinese-made intrusion tool ARTEX with AI models such as DeepSeek to target externally exposed assets. The institute also said at the time that the attack surface of externally exposed assets should be continuously measured and verified, and cited the need for ongoing management rather than one-off assessments as a recommended response.
Criticism is mounting that the damage could have been minimized if the financial sector had thoroughly checked for vulnerabilities in external systems immediately after the seminar.
However, some analysts say there may have been limits to proactive defense: the earlier attack on Company A targeted a third-party solution, whereas the current incident targeted externally connected business systems directly operated by financial firms, such as loan agent lookup pages. In response, the Financial Security Institute said that targeted attacks using AI would have been difficult to detect through existing firewall monitoring systems and the like, making them hard to catch proactively.
Political circles plan to hold those responsible for the incident strictly accountable at the upcoming parliamentary audit. The heads of the five major commercial banks are scheduled to appear as witnesses at the Financial Supervisory Service’s parliamentary audit on the 19th to explain the causes and circumstances of the hacking. Han’s office made clear that it would thoroughly question the appropriateness of the response before and after the incident, criticizing the financial firms’ poor management for leaving vulnerabilities unaddressed despite repeated warnings.

[email protected] Kim Dong-gyu Reporter