Published: October 6, 2026 · Last updated: October 6, 2026
TL;DR: South Korea is investigating whether AI tools helped an attacker breach Shinhan Bank, after someone bypassed identity verification and cycled through query values to pull data on roughly 25,000 customers, prompting a direct warning from President Lee Jae-myung.

An attacker got past Shinhan Bank’s identity verification system, then did something that sounds almost tedious when you describe it plainly: cycled through query values one after another, pulling customer records each time the system let a request through. That mechanical, repetitive pattern is exactly why investigators are looking at whether AI tooling was behind it. Humans get bored running the same query thousands of times with slightly different inputs. Scripts and AI agents don’t.
Korean outlets reported the breach exposed data on approximately 25,000 Shinhan Bank customers. It’s one entry in a wave of attacks hitting Korean financial institutions this month, serious enough that President Lee Jae-myung addressed it directly, saying signs have emerged of AI being used in the breaches of commercial banks. That’s an unusually blunt statement for a head of state to make about an active investigation, and it signals how seriously Seoul is treating the pattern rather than waiting for a forensic report to land before saying anything.
What makes identity-verification bypasses like this one dangerous isn’t cleverness. It’s scale. A single attacker manually guessing their way past a verification system might get a few dozen records before giving up or getting caught. An AI-assisted script doing the same job can run through thousands of attempts in the time it takes a security team to notice the traffic pattern looks wrong, and by the time anyone does notice, the query cycling has already pulled everything it’s going to pull.
Banks have spent two decades building fraud detection around how humans behave: typing speed, mouse movement, the small inconsistencies that give away a scammer on the phone. None of that defense works against a tool that doesn’t get tired, doesn’t get nervous, and doesn’t need to sound convincing on a call. If AI involvement here is confirmed, Shinhan won’t be the last Korean bank to find that out, and it almost certainly won’t be the last bank anywhere.
Shinhan isn’t the only Korean financial institution dealing with this. Local reporting has tied the broader wave of incidents this month to at least one other major bank, and regulators have reportedly opened a joint review of identity verification systems across the sector rather than treating each breach as an isolated incident. That kind of coordinated response is unusual outside of a confirmed, large-scale compromise, which is itself a signal of how seriously Seoul’s financial regulators are taking the pattern even before a full forensic picture exists.
Identity verification bypasses like this one typically exploit a narrow gap between how a system checks a single request and how it behaves under a flood of slightly varied ones. A system built to catch one person guessing a password wrong a few times often has no equivalent defense against thousands of automated attempts spread out just enough, and slow enough, to avoid tripping whatever rate limit the bank originally built. That gap is exactly where AI-assisted automation thrives, and it’s why investigators are focusing less on how the attacker got in and more on how many times the same trick could be repeated before anyone noticed.
Related: Google just paused its bug bounty program over AI-generated reports and a Japanese car-sharing app confirmed 6.6 million accounts were exposed.
Bottom Line: Fraud defenses built around how humans behave don’t hold up against tools that never get tired or careless. South Korea’s banks just found that out, and every other bank still running identity checks tuned for human attackers should be paying close attention.
Follow Teck Hustlers: Facebook · X · Instagram · LinkedIn · TikTok · Pinterest


