tens of thousands
South Korea's financial sector is responding to a series of coordinated cyberattacks that have compromised personal and financial data at numerous banks and financial companies. The list of affected institutions includes major players such as Shinhan Bank, KB Kookmin Bank, Hana Bank, and Woori Bank. The attacks, which appear to have targeted less secure, externally-facing systems rather than core banking infrastructure, have prompted South Korean President Lee Jae Myung to order a comprehensive investigation and the development of stronger countermeasures. The Financial Services Commission (FSC) has raised concerns that the attackers may have leveraged Artificial Intelligence (AI), signaling a potential escalation in the sophistication of threats facing the industry.
The campaign appears to be a widespread, opportunistic attack targeting multiple financial institutions simultaneously. Attack traffic was traced to IPs in the US, Japan, Singapore, Vietnam, and Britain, indicating the attackers were scanning broadly for vulnerable systems. The primary vector was the exploitation of vulnerabilities in ancillary, internet-connected systems, such as websites for loan agents and mobile work-support platforms. This allowed the attackers to bypass the more heavily fortified core banking systems, which are typically isolated from the internet.
Data breaches have been confirmed at several institutions:
The attackers demonstrated a clear understanding of financial IT environments by avoiding direct assaults on hardened core networks. Their strategy focused on the softer perimeter.
T1190 - Exploit Public-Facing Application. The attackers likely used automated scanners to identify vulnerabilities in web applications associated with the banks but not part of the core transaction systems. This is supported by the distributed nature of the attack traffic.T1213 - Data from Information Repositories.T1530 - Data from Cloud Storage Object or similar) and exfiltrated it. The use of AI, as suspected by authorities, could have been for automating vulnerability discovery, optimizing attack paths, or crafting more effective exploits.This coordinated attack has resulted in the confirmed breach of sensitive data for tens of thousands of customers, exposing them to risks of fraud and identity theft. For the affected banks, the incidents cause significant reputational damage, erode customer trust, and will likely lead to increased regulatory scrutiny and potential fines. The incident has triggered a national-level response, highlighting the systemic risk such campaigns pose to a country's financial stability. The call for an "AI attacks defended by AI" strategy indicates a paradigm shift in how the nation's financial regulators view cybersecurity threats.
No specific Indicators of Compromise (IOCs) were mentioned in the source articles.
Security teams at financial institutions may want to hunt for the following patterns:
/loan_agent/, /mobile_support/w3wp.exe, httpd).D3-ITF: Inbound Traffic Filtering.D3-NTA: Network Traffic Analysis.M1030 - Network Segmentation.Properly segmenting ancillary, internet-facing systems from core banking networks is crucial to prevent lateral movement and contain breaches to the perimeter.
Maintaining an aggressive patch management program for all internet-facing applications and servers is essential to close the vulnerabilities exploited by attackers.
Using a Web Application Firewall (WAF) to filter malicious requests can block common web exploitation techniques.
Implement and enforce strict network isolation between externally-facing systems (like loan-agent portals) and the internal core banking network. This is the most critical defense against the attack pattern described. No direct communication should be allowed from the external DMZ to the internal trusted zone. All communication must be brokered through hardened, inspected proxies or middleware. This containment strategy ensures that even if an external web server is fully compromised, the attacker cannot pivot directly to high-value internal assets, effectively containing the breach to the perimeter.
Establish a rapid, risk-based patching program for all internet-facing applications and their underlying infrastructure. Since the attackers targeted weaker external systems, it is highly likely they exploited known vulnerabilities. Financial institutions must have a complete asset inventory of all web properties and use continuous vulnerability scanning to identify and prioritize flaws. Patches for critical and high-severity vulnerabilities on these systems should be deployed within days, not weeks, to close the window of opportunity for attackers.
Deploy network traffic analysis tools to monitor for reconnaissance and attack patterns against the financial institution's public IP space. Since attack traffic was noted from multiple countries, detecting the initial scanning phase is key. Security teams should baseline normal traffic and alert on indicators like broad port scans, vulnerability scanning signatures (e.g., from tools like Nuclei or Nessus), and repeated requests to non-existent pages, which often indicate enumeration attempts. This proactive detection can provide an early warning before a successful breach occurs.
Shinhan Bank reports a data breach, one of the first in a series of attacks.
South Korean President Lee Jae Myung orders a full investigation into the financial sector cyberattacks.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.