SBS NEWS

News > Society

Banks and Platforms Compromised... AI Pieces Together Personal Data

Yoo Younggyu

Published : Oct 6, 2026 7:08 AM


▲ Financial Sector Hacking Attacks

"Hello, customer. I'm calling to follow up on the credit loan you received last month."

When a caller knows your name, workplace, bank, and even the details of your loan, it is honestly not easy to suspect phishing.

Recently, personal data breaches have continued to occur across commercial banks, online platforms, general corporations, and public institutions.

Security experts express concern that such leaked personal information can be woven together using generative artificial intelligence (AI) for precise targeted attacks.

Spear phishing, which throws customized bait targeting specific individuals, is not a new method.

However, while attackers previously had to manually comb through portal sites or social media (SNS) to select targets and refine phrases, AI now takes over that role.

Microsoft (MS) warned in a threat analysis published this year that attackers are utilizing generative AI for crafting phishing phrases, targeting, and analyzing stolen data.

Just looking at the recent string of data breaches in South Korea gives a sense of how widely personal information is floating around.

Shinhan Bank announced on October 1 that an external unauthorized person bypassed authentication procedures to access some loan-related services.

The affected customers were estimated at approximately 25,000.

The initial penetration point for the attacker was a mobile homepage service where loan brokers check customer loan application statuses.

Customer names, phone numbers, annual incomes, and calculated loan limits were leaked.

This also included 66 resident registration numbers and 97 connection information (CI) records.

Security industry analyses also emerged indicating that traces of AI penetration tools were found on servers presumed to have been utilized in the attack.

Moon Jong-hyun, head of the Genians Security Center, stated via LinkedIn that he identified a Chinese phrase reading "ARTEX-AI Autonomous Penetration Testing Console" in the HTML title of a web server believed to have been used in the attack.

ARTEX is a Chinese-centric open-source penetration testing tool based on large language models (LLMs).

It has not been officially confirmed by financial authorities or Shinhan Bank whether this tool was actually used in the attack.

At KB Kookmin Bank, personal and credit information of 119 customers was leaked due to an external intrusion.

The bank explained that the breached point was a mobile work support system for employees and is unrelated to customer financial transactions.

Names, phone numbers, addresses, and encrypted resident registration numbers were leaked, with items varying by customer.

Hana Bank stated that an external hacking group accessed its Sales Support System (ODS) abnormally, leading to the leakage of information belonging to 89 customers.

The leaked data included resident registration numbers, names, addresses, emails, phone numbers, and even workplace names.

Personal information of 11 outsourced development employees was also exposed at BNK Busan Bank, but no customer data leakage was confirmed.

Woori Bank and NH Nonghyup Bank stated that while there were hacking attempts, no customer information was leaked.

Data leaks are not limited to banks.

Korea Electric Power Corporation (KEPCO) stated in a press release distributed on October 4 that the names, affiliations, and phone numbers of approximately 24,000 KEPCO employees were exposed on an external web page.

At the online streaming service (OTT) TVING, a massive amount of member information was leaked last June.

Member IDs, names, dates of birth, genders, phone numbers, and emails were included, with the scale of damage tallied at 19.53 million users.

This is the fourth-largest leak accident in South Korea, following Coupang (approx. 37.56 million), Cyworld and Nate (approx. 35 million), and SK Telecom (approx. 23.24 million).

As such, banks hold customer incomes and loan details, while telecommunications companies and platforms store contact info and dates of birth.

While these pieces of information are fragmented on their own, matching them together allows for a precise profile of an individual to be constructed.

Targeted phishing using AI has already been reported multiple times overseas.

In a report this year, MS noted that attackers customize phishing messages based on targets' job titles, affiliations, and recent activities, pointing out that phishing is becoming increasingly sophisticated as AI rapidly adapts phrasing to match victims' native languages and tones.

Attackers used generative AI to create emails tailored to targets' jobs, utilizing requests for proposals, invoices, and manufacturing processes as subject material.

They subsequently employed methods to automatically analyze public profiles and internal address books to weed out finance personnel and executives first.

MS stated that click-through rates in AI-integrated phishing attacks reached up to 54%, observing cases that were 4.5 times higher than traditional methods.

However, MS analyzed that most attacks are still driven by humans and have not yet reached the stage where AI executes attacks entirely on its own from start to finish.

The time taken for attacks is also shrinking.

According to a report last month by Google's Threat Intelligence Group (GTIG), after seizing cloud resources in the second quarter, an attacker deployed an AI agent to plan, build, and execute a large-scale credential-theft operation in less than six hours.

AI is also being used to find subsequent targets from breached accounts.

A representative example is the phishing-as-a-service platform "EvilTokens," which MS blocked last month; it was reportedly sold on Telegram for 500 dollars a month to use phishing features.

The method used by this platform directs victims who click a link to an official MS login page, prompting them to enter a code.

At that moment, victims unknowingly hand over account access permissions to the attackers.

From then on, attackers use AI to analyze mailboxes, search for financial conversations, select employees worth targeting, and decide whom to impersonate.

MS estimated that through this platform, 12,000 mailboxes across 10,000 organizations in construction, finance, universities, and healthcare were compromised.

Security firm Check Point viewed "EvilTokens" as a commercial service built with AI, directly linking LLMs to the attack execution process.

Experts point out that once such sophisticated features are built, any buyer can use them, significantly lowering the barrier to committing fraud with AI.

In the past, awkward grammar or bizarre requests were key clues in identifying phishing.

However, the story changes when someone approaches you in a tone that accurately knows your name, workplace, and recent loans.

It has not yet been confirmed whether information leaked from South Korea's financial sector was combined with data leaked from elsewhere via AI and used in actual crimes.

However, overseas cases have already exposed instances where stolen information and public data were analyzed using AI to select targets and create bait.

KB Kookmin Bank urged customers not to click links in text messages or emails from unclear sources and to refrain from responding if personal or financial information is requested.

TVING also advised users immediately after the incident to change passwords for other services utilizing the same IDs and passwords.

If you receive contact ostensibly from financial institutions or claiming to confirm a data leak, it is best not to use the links or numbers listed in the message.

Checking directly through official apps or customer service numbers is the fundamental rule.

Enabling multi-factor authentication (MFA) and using different passwords for each site can also prevent accounts from being compromised in a chain reaction.

We have now entered an era where if someone knows excessively much about you, you need to start by suspecting them.