South Korean Cybersecurity Issues
This is a real, well-documented wave, but it isn't a new class of exploit. The attacker found badly protected, internet-facing business apps, and AI tooling made the work faster.
Confirmed facts
- Shinhan, KB Kookmin, Hana, BNK Busan, Yegaram Savings Bank and Hyundai Capital were hit between 27 and 30 September. Authorities have confirmed intrusions at seven institutions. scc cam 2026 0877 +2
- The best-supported total is about 68,000 people. Shinhan lost 25,727 records (names, contact details, income, credit limits). KB Kookmin lost 119 and Hana 89. Some outlets say 119,000 for KB. That looks like a unit error, so treat it with caution. khan
- Shinhan was breached through a loan-inquiry service used by brokers, and KB Kookmin through an employee mobile work-support system. Hana's was a sales-support system. khan koreaherald
- Detection took about 15 hours at Shinhan, nearly 42 at Hana and almost 68 at KB Kookmin. Shinhan's attackers reportedly returned after the bank blocked their first address. seoulz
- The FSC held an emergency meeting. The president ordered a thorough investigation. Regulators told all financial firms to cut non-essential outside access. www.bleepingcomputer.com +2
Attribution (single source, moderate confidence)
- CrowdStrike assessed with moderate confidence that one Chinese-speaking, financially motivated person was responsible. It has not tied the activity to a named threat group. theepochtimes
- CrowdStrike recovered Claude Code session histories, ARTEX config files and Claude memory files from open directories on attacker servers. The reporting says AI was embedded in a human-run workflow, not an autonomous operation. cybermagazine tech-insider
- ARTEX is a China-developed, open-source agentic pentest tool. The observed instance used DeepSeek as its main backend, with Claude Code, GLM and Grok used separately. The latest ARTEX release landed three days before the first attack. CrowdStrike: How a Cyber Attacker hit South Korean Banks +2
- Yes, Claude Code was one of the attacker's tools. Anthropic's own response wasn't in what I found.
Unresolved
- The initial access vector isn't confirmed. One account describes an access-control weakness rather than stolen credentials, while the entry point remains officially unsettled. cloudsecurityalliance
- Ignore the other incidents attached to this story. KEPCO's leak of 24,000 employee records is described as likely unrelated. The 850,000-member megachurch breach comes from a single lower-tier source, so I'd treat it as unverified. koreatimes
What this means for your setup
Your comparison with the FBI case holds. These victims were undone by exposed apps with weak authorisation and slow detection, and you control both. Worth checking:
- Exposed surface: list everything published through the reverse proxy.
- Per-endpoint auth: check that every route and API enforces authorisation, not just the login page.
- Detection: alert on request spikes and unusual data egress. The banks' main failure was 15 to 68 hours of silence.
- Response: blocking one IP isn't enough. Rate-limit and block by behaviour or ASN.
- Patch speed: AI tooling shortens the time between a vulnerability becoming known and being exploited.
Sources: Taipei Times/Reuters · Korea Herald · Kyunghyang · BleepingComputer · Cyber Magazine on CrowdStrike · Epoch Times · CSA research note · Korea JoongAng Daily on KEPCO · Seoulz · Signal Post
Looks like South Korea is getting pwned
#enoughsaid