Bank Security Breaches Highlight Vulnerabilities Amid AI Hacking Threats

by Lee Seongjin Posted : October 5, 2026, 15:24Updated : October 5, 2026, 15:24

As hacking attacks suspected to involve artificial intelligence target the financial sector, the authentication and access control methods employed by banks have come under scrutiny for their role in data breaches.


Woori Bank, which has not confirmed any data leaks to date, restricts access through work devices and additional authentication. NH Nonghyup Bank has also strengthened its detection of unusual access and checks for external exposure routes. In contrast, even banks that received top ratings in information security assessments have experienced data leaks through their work systems, raising questions about the effectiveness of security measures in the banking sector.


According to the financial sector on October 5, recent data breaches linked to external hacking have been confirmed at Shinhan, KB Kookmin, and Hana Banks. While Woori and NH Nonghyup Banks have faced attempted attacks, no data leaks have been reported so far.


Woori Bank requires loan solicitors to input relevant information through ODS tablet devices and undergo 'WON Certificate' authentication via smartphones during login. The bank states that the structure of using work devices and a separate authentication process makes typical external logins impossible.


In response to the recent attacks, Woori Bank has blocked identified suspicious IP addresses and is reviewing past access attempts and potential data leaks. The bank is also using both external high-performance AI-based vulnerability assessment solutions and its own developed tools to identify security weaknesses in its systems.


NH Nonghyup Bank has reported that it is enhancing its detection of unusual activities, such as authentication bypass and abnormal mass access, while continuously checking for vulnerabilities by blocking unnecessary external exposure points.


In the banks where data was leaked, the work systems used by loan solicitors and employees became the attack vectors. At Shinhan Bank, information was leaked through the mobile homepage 'M Shinhan' during a simple inquiry service where loan solicitors check the status of their submitted loans. KB Kookmin Bank experienced data loss due to abnormal access to its employee mobile support system, while Hana Bank faced leaks from its sales support system (ODS).


The leaks from work systems, which are separate from customer financial transaction systems, have raised concerns about the security management of external access points. Experts argue that if there are pathways to access customer information, not only should authentication at the access stage be enforced, but there should also be restrictions on inquiry permissions and detection and blocking of repeated or mass inquiries.


Despite the emphasis on security systems in disclosures by major banks, the recent attacks have revealed vulnerabilities. Shinhan Bank reported in its semi-annual report that it received an S grade (100 points) for six consecutive years in its 'Personal Credit Information Management and Protection Status Check.' KB Kookmin Bank highlighted additional authentication and permission restrictions when accessing customer information, along with continuous monitoring of the entire process of personal information handling. Hana Bank stated that its group integrated security monitoring center operates 24/7. However, all three banks failed to prevent data leaks through their work systems, prompting calls for a review of whether the protective measures touted by the banking sector are effectively applied to external access points.


Financial authorities and experts emphasize the importance of how organically multi-authentication systems, external exposure system management, access permission restrictions, and information encryption are operated. They stress that it is crucial to ensure that security measures function seamlessly during actual access and information inquiry processes.


A financial authority official stated, “Differences among companies depend on how organically they operate multi-authentication systems, physical barriers, access permission management, and information encryption.”





* This article has been translated by AI.