
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

A series of data breaches at Shinhan Bank, KB Kookmin Bank and Hana Bank, three of Korea’s largest commercial banks, has heightened concerns in the financial sector over increasingly sophisticated cyberattacks using artificial intelligence (AI).
Summary
On Friday, KB Kookmin Bank said that personal information belonging to 119 customers was leaked after abnormal external access to a mobile system used by employees. The leaked information varied by customer and included names, phone numbers, addresses and resident registration numbers in encrypted format.
"We have activated an emergency response system across the company, including a thorough review of all our processes to prevent further damage and recurrence," a Kookmin Bank official said.
Later that day, Hana Bank said personal information belonging to 89 customers had been exposed following an external hacking agent’s attempt to gain unauthorized access to its sales support system. The leaked information included customers' resident registration numbers, names, addresses, email addresses, phone numbers and workplace information.
KazaSec's take
AI-related security incidents are a genuinely new category, prompt injection, model manipulation, and data leakage through an LLM integration don't map cleanly onto traditional application security testing, and are worth assessing deliberately rather than assuming existing controls already cover them.
Coverage details
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.