Between late September and October 2, 2026, hackers breached employee-facing loan-officer portals at several of South Korea’s largest banks, exposing personal data on tens of thousands of customers. Shinhan Bank alone confirmed roughly 25,000 affected customers, with smaller numbers disclosed at KB Kookmin Bank, Hana Bank, and BNK Busan Bank; exposed data included resident registration numbers, names, phone numbers, income, and loan details. A cybersecurity firm found Chinese-language strings referencing “AI autonomous penetration” on a compromised web server, leading financial authorities to suspect an autonomous AI hacking agent rather than manual intrusion was used to probe the weaker-security loan-agent systems. South Korea’s Financial Supervisory Service convened an emergency meeting and ordered sector-wide security audits after describing existing defenses as rendered ineffective.