AI-linked hacks hit Korean banks through loan-agent sites

South Korean President Lee Jae Myung News Conference
Lee Jae Myung, South Korea's president, said this week that there were signs that AI had played a role in recent cyberattacks against Korean banks.
SeongJoon Cho/Bloomberg
  • Key insight: South Korea's Financial Services Commission blamed systems used by employees and outside personnel such as loan recruiters and contractors for the intrusions.
  • Supporting data: Shinhan said about 25,000 customers were affected, KB Kookmin said 99 customers and 20 current and former employees were, and Hana said 89 customers were.
  • Forward look: Korean regulators asked financial firms to finish checking their internet-facing systems and fix any gaps by Thursday, and police have opened a formal investigation.

Overview bullets generated by AI with editorial review.

Processing Content

Attackers have broken into at least seven South Korean banks and lenders since late September and stolen personal data, including loan-application details on about 25,000 Shinhan Bank customers.

South Korean President Lee Jae Myung said Tuesday that there were signs AI had played a role in some of the attacks.

The attackers came in through side doors, according to the banks and South Korean press reports, including a lookup service Shinhan built for loan recruiters (outside agents who refer borrowers to the bank), a mobile work-support system for a second bank's employees and a sales-support system at a third bank.

The second bank, KB Kookmin, is South Korea's largest lender. The third, Hana, merged in 2015 with Korea Exchange Bank, which had long led the country's foreign exchange business. Shinhan's corporate history traces back to one of Korea's first banks.

Spokespeople for Shinhan, KB Kookmin and Hana did not immediately respond to requests for comment.

At Shinhan, the attackers got around a verification step, according to what the bank told Yonhap, a South Korean news agency.

The bank had given the recruiters, who are not bank employees, access to sensitive customer credit data, which critics called excessive, according to Newsis, another Korean news agency.

The set of breaches is an early case in which authorities suspect a campaign against a country's banks involved AI tools. The attackers took advantage of what appear to be ordinary cyber hygiene failures rather than complex vulnerabilities.

The controls aimed at those hygiene failures are ones U.S. regulators have been naming for months. Federal Reserve Vice Chair for Supervision Michelle Bowman listed several of them in a speech to community bankers last week.

Shinhan said about 25,000 customers were affected, and that the exposed data included names, phone numbers, annual incomes and calculated borrowing limits, according to an Oct. 1 notice on the bank's website.

KB Kookmin said the breach affected 99 customers and 20 current and former employees, and Hana said it affected 89 customers, according to notices each bank posted. The other four Korean firms that got hit include two savings banks, a regional bank and a consumer lender.

The attackers did not get passwords or one-time authentication codes, and regulators have confirmed no cases of customers losing money, according to a Tuesday consumer alert from South Korea's Financial Services Commission.

The alert warned that fraudsters could use the detailed income and loan information the attackers stole to make fake loan offers seem legitimate.

The commission held emergency meetings on Friday and Sunday. It ordered financial firms to inspect every internet-facing system "regardless of whether they are customer-facing," according to its release on the Friday meeting.

Regulators asked firms to finish those checks and fix any gaps by Oct. 8 (Thursday), according to Yonhap. Police have opened a formal investigation, according to the agency.

How the attackers got in

Over about 30 hours starting Sept. 28, attackers fed random customer numbers into Shinhan's loan lookup services and got past a mobile-phone verification step, according to the newspaper Dong-A Ilbo. The newspaper described an incident report Shinhan gave to a South Korean lawmaker.

The target was the site Shinhan built for loan recruiters, Yonhap and Newsis reported. However, reports conflict over the exact technique that the attackers used.

Yonhap said the attackers used a technique called credential stuffing, which usually means trying usernames and passwords stolen from somewhere else. Dong-A Ilbo described a technique called enumeration, which means cycling through guessed account numbers until some of them return data.

It is not clear how the attackers got past the phone check. The step might have been one a user could simply skip, the site might have mishandled login sessions, or it might have been something else.

Shinhan's own notice says only that an "unauthorized outsider" reached some of its services "through abnormal means."

BNK Busan Bank, the regional bank caught up in the attack, said some of its web pages had "insufficient session validation," meaning they did not properly check that a request came from a logged-in user.

That gap exposed data on 11 outsourced developers, according to a statement the bank gave Yonhap.

The Shinhan site gave loan recruiters access to applicants' incomes and borrowing limits, according to Newsis. The commission issued an order on Sunday responding to that kind of setup.

The order told firms to make sure personal credit data is not "unnecessarily stored or viewable" in systems used by employees and by "outside personnel such as loan recruiters and outsourcing contractors," which it called "the cause of the recent intrusions," according to the release.

Where AI fits

"In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety," Lee said at a Tuesday cabinet meeting, according to Reuters. He did not say what kind or model of AI.

BNK Busan said the attempt on its web servers used an AI agent, according to a statement the bank gave Yonhap.

A South Korean security researcher cited by Yonhap found that a web server believed to have been used against Shinhan carried a page title matching ARTEX, according to the news agency.

ARTEX is an open-source penetration-testing tool, meaning it automates the kind of probing for weaknesses that security testers do with a client's permission. Many banks use penetration testing to understand the weaknesses they need to address.

The ARTEX tool describes itself as an autonomous system driven by multiple AI agents, running on models from Anthropic or OpenAI, according to its GitHub page.

Investigators traced Shinhan's attack logs and found evidence pointing to ARTEX, an official at the Financial Security Institute, the sector's cyber agency, told the Korean outlet Herald Business. The AI "did not act independently without human involvement," the official told the outlet.

"There are a great many open-source AI tools like ARTEX," the official said, according to Herald Business.

No regulator has publicly named ARTEX as being involved in the attack.

The controls U.S. regulators keep naming

Before the attacks on Korean banks became public, Bowman, the Fed's vice chair for supervision, told community bankers in the U.S. that they should stick to the fundamentals when defending against AI-powered threats.

This work "begins with strong cyber hygiene," including "phishing-resistant multifactor authentication" and "strong identity and access controls," Bowman said in her Sept. 29 remarks at a Fed cyber workshop.

Those controls protect against the kinds of gaps that showed up in Korea: a verification step that got bypassed and session checks that did not hold. She also suggested banks keep "up-to-date asset inventories," meaning a current catalog of every system the bank runs.

Interagency guidance on third-party risk that the Fed, the Federal Deposit Insurance Corp. and the OCC issued in 2023 explicitly covers "referral arrangements," the closest U.S. counterpart to Korea's loan recruiters.

Mortgage brokers and auto dealers are common examples of third parties that send borrowers to U.S. banks. Relying on such a third party "does not diminish" a bank's responsibility, according to the guidance.

The guidance calls for scrutiny of a third party's "access to a banking organization's systems and information."

South Korea's regulator has now ordered financial firms to take an inventory of every system exposed to the internet, according to its release on the Friday meeting.


For reprint and licensing requests for this article, click here.
Cyber Security Cyber attacks Artificial Intelligence Data breaches International banking Vendor management Federal Reserve OCC Technology
MORE FROM AMERICAN BANKER
Load More