South Korea's Five Major Commercial Banks Targeted in Simultaneous Cyberattacks
South Korea's top five commercial banks were simultaneously targeted in suspected AI-driven cyberattacks, leading to customer data breaches at Shinhan Bank, KB Kookmin Bank, and Hana Bank. The breaches compromised personal data from tens of thousands of customers through internal business support systems rather than core transaction platforms. This incident marks the first time South Korea's top financial institutions faced a synchronized, multi-target cyberattack, highlighting how AI capabilities may escalate threat scalability against enterprise infrastructure. It underscores that non-transactional internal portals, such as mobile business support tools, represent critical vulnerabilities in enterprise banking security. Shinhan Bank suffered the largest leak affecting approximately 25,000 customers, including sensitive details like annual income and loan limits, while KB Kookmin Bank and Hana Bank reported smaller breaches affecting 119 and 89 customers respectively. Woori Bank and NH Nonghyup Bank successfully blocked the intrusions, and core online banking transaction systems remained uncompromised across all institutions.
## BACKGROUND
In banking software architecture, Operational Data Stores (ODS) and internal business support systems aggregate customer data to help mobile sales staff and relationship managers perform daily operations remotely. While these systems are isolated from core banking engines that process actual financial transactions, they often maintain synchronized personal records to provide real-time operational context to employees.