INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Korean Financial Institution's AI System Leaks Sensitive Information to Hackers
| 2026-10-08 07:06 CRITICAL LOW AI-ENABLED ATTACK · AUTONOMOUS DATA BREACH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
A recent incident of cyberattack targeting Korea's financial sector has been reported, with AI-based attacks and data breaches involving personal information. Citi AI Lab warned that such incidents can lead to personal data leaks and more severe crimes. The attack process was analyzed by Citi AI Labs, which divided it into five stages: service entry, customer number collection, linked service queries, bulk data extraction, and incident awareness and response. In the first four stages, an AI-based abnormal behavior detection technology can be applied, detecting repetitive customer information queries or abnormal service access. The attack was detected through analysis of unusual DNS traffic attempting to embed an internal server into a proxy botnet by communicating with an external malicious IP address. Citi AI Lab's in-house detection model compared favorably with publicly disclosed features of its solution, DTI.ai, which analyzes normal communication activities and detects abnormal changes without predefined rules or signatures. The company applies over 20 types of threat detection models to various areas, including web, network, VPN, and DNS.
Technical Mitigations AI-generated
• Pre-compromise (ATT&CK mitigation for Botnet): This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Cyclops BlinkCyclops Blink
Target & Sectors
LATAM
LATAM
NORTH_AMERICA
NORTH_AMERICA
automotiveautomotive
mediamedia
governmentgovernment
financefinance
Incident Timeline
July 7
CrowdStrike Intelligence released a report on July 7 identifying the infrastructure related to attacks on Korean financial institutions from September 2026 to early October 2026.
Click on any entity below to view its context and source!
attribution
CrowdStrike Intelligence
According to the report released by CrowdStrike Intelligence on July 7, the company identified the infrastructure related to the attacks on Korean financial institutions from September 2026 to early October 2026.
August 27th
Threat actors exploited a vulnerability in an external API to retrieve order information, resulting in the exposure of 159,852 customer personal data records.
Click on any entity below to view its context and source!
tactic
Data Breach
The 29CM sister company, 29CM, recently experienced a data breach incident where an external API request to retrieve order information on August 27th resulted in the exposure of 159,852 customer personal data records.
organisation
API
The 29CM sister company, 29CM, recently experienced a data breach incident where an external API request to retrieve order information on August 27th resulted in the exposure of 159,852 customer personal data records.
data_breach
159,852 data records
The 29CM sister company, 29CM, recently experienced a data breach incident where an external API request to retrieve order information on August 27th resulted in the exposure of 159,852 customer personal data records.
September 4th
Threat actors exploited a consultation record API to reveal unauthorized access, resulting in the exposure of approximately 220,000 personal data records.
Click on any entity below to view its context and source!
data_breach
220,000 personal data records
On September 4th, a consultation record API revealed unauthorized access, resulting in the exposure of approximately 220,000 personal data records.
September 2026
CrowdStrike Intelligence identified infrastructure related to attacks on Korean financial institutions from September 2026 to early October 2026.
Click on any entity below to view its context and source!
attribution
CrowdStrike Intelligence
According to the report released by CrowdStrike Intelligence on July 7, the company identified the infrastructure related to the attacks on Korean financial institutions from September 2026 to early October 2026.
Sept. 14
An unidentified hacker used a well-known language model to breach corporate personal data stores, prompting Spain's Data Protection Agency to issue a report on September 14.
Click on any entity below to view its context and source!
target_region
Spain
On Sept. 14, Spain's Data Protection Agency (AEPD) — the Spanish government's data protection watchdog — described a
breach report
submitted by an unnamed organization, in which an unidentified hacker used a "well-known language model" to breach corporate personal data stores.
industry
Government
On Sept. 14, Spain's Data Protection Agency (AEPD) — the Spanish government's data protection watchdog — described a
breach report
submitted by an unnamed organization, in which an unidentified hacker used a "well-known language model" to breach corporate personal data stores.
attribution
Data Protection Agency
On Sept. 14, Spain's Data Protection Agency (AEPD) — the Spanish government's data protection watchdog — described a
breach report
submitted by an unnamed organization, in which an unidentified hacker used a "well-known language model" to breach corporate personal data stores.
2026/09/18
Threat actors used AI-driven exploits to target South Korean media and automotive sectors on September 18, 2026.
Click on any entity below to view its context and source!
industry
Media
"
Related:
Cyber Op Targets South Korean Media & Automotive Sectors
Are Agentic Attacks Already Old News?
Stories of
AI-driven cyberattacks
might leave one feeling less shocked today than they did earlier in 2026.
industry
Automotive
"
Related:
Cyber Op Targets South Korean Media & Automotive Sectors
Are Agentic Attacks Already Old News?
Stories of
AI-driven cyberattacks
might leave one feeling less shocked today than they did earlier in 2026.
target_region
Korea, Republic of
"
Related:
Cyber Op Targets South Korean Media & Automotive Sectors
Are Agentic Attacks Already Old News?
Stories of
AI-driven cyberattacks
might leave one feeling less shocked today than they did earlier in 2026.
organisation
Media & Automotive
"
Related:
Cyber Op Targets South Korean Media & Automotive Sectors
Are Agentic Attacks Already Old News?
Stories of
AI-driven cyberattacks
might leave one feeling less shocked today than they did earlier in 2026.
September 28
An unidentified attacker attempted to exploit vulnerabilities and steal information on September 28.
2026/10/02
An unidentified attacker attempted to exploit vulnerabilities and steal information on September 28.
October 2
The Financial Security Institute stated on October 2 that a widespread attack using AI autonomous intrusion tools is underway against domestic financial institutions.
Click on any entity below to view its context and source!
organisation
the Financial Security Institute
Shinhan Bank, following 29CM and Gangnam Sister, has also experienced a customer information leak incident, with the Financial Security Institute stating on October 2 that a widespread attack using AI autonomous intrusion tools is actually underway against domestic financial institutions.
early October 2026
CrowdStrike Intelligence identified infrastructure related to attacks on Korean financial institutions from September 2026 to early October 2026.
Click on any entity below to view its context and source!
attribution
CrowdStrike Intelligence
According to the report released by CrowdStrike Intelligence on July 7, the company identified the infrastructure related to the attacks on Korean financial institutions from September 2026 to early October 2026.
2026/10/08
Threat actors used an AI-based intrusion testing tool and a large language model to carry out the attacks on Korean financial institutions, including Shinhan Bank.
Click on any entity below to view its context and source!
organisation
LLM
The document included a Chinese prompt specifying the method for LLM to perform intrusion testing and a Hong Kong-based IP address controlled by the attackers.
organisation
CrowdStrike
CrowdStrike has conducted additional analysis of the Hong Kong-based server and secured the Cloud Code session records, ARTEX configuration files, and Cloud Memory files.
organisation
IP
The investigation into the primary attacking IP revealed that the ARTEX, a Chinese-based open-source AI autonomous intrusion tool, was running on the infrastructure, and further analysis of the same IP's access history confirmed that the attacker had attempted to conduct infiltration attacks against multiple domestic financial institutions.
The analysis began with the IP address associated with the attack, '38.244.50[.]120'.
A representative example cited was the detection of abnormal DNS traffic that attempted to embed an internal server into a proxy botnet by communicating with an external malicious IP address.
organisation
FamousSparrow APT Spies
Related:
China's FamousSparrow APT Spies on US Politics in Latin America
It was never going to take long for this prediction to become reality in Spain itself.
organisation
US Politics
Related:
China's FamousSparrow APT Spies on US Politics in Latin America
It was never going to take long for this prediction to become reality in Spain itself.
organisation
ARTEX
The server was running ARTEX, and a publicly available directory revealed a Claude Code instruction document.
[Issue Analysis] ARTEX's Widespread Attack on Financial Sector, Shinhan Bank, and Gangnam Sister, Misa, Also Affected... 'API Permission Verification' Vulnerability Exploited by AI.
organisation
Widespread Attack
[Issue Analysis] ARTEX's Widespread Attack on Financial Sector, Shinhan Bank, and Gangnam Sister, Misa, Also Affected... 'API Permission Verification' Vulnerability Exploited by AI.
organisation
Shinhan Bank
[Issue Analysis] ARTEX's Widespread Attack on Financial Sector, Shinhan Bank, and Gangnam Sister, Misa, Also Affected... 'API Permission Verification' Vulnerability Exploited by AI.
organisation
Vulnerability Exploited
[Issue Analysis] ARTEX's Widespread Attack on Financial Sector, Shinhan Bank, and Gangnam Sister, Misa, Also Affected... 'API Permission Verification' Vulnerability Exploited by AI.
organisation
Telegram
The attacker asked the victim about where Korean leaked data is primarily sold, and requested help in finding a Korean-related data-selling Telegram group.
organisation
CloudStrike
CloudStrike evaluated this case as showing that an attacker using AI tools can carry out multiple breaches within a short period of time for financial motives.
organisation
CTI Lab's
CTI Lab's latest analysis compared the attack stages and features of its in-house detection model with those publicly disclosed by Citi AI Lab.
organisation
DNS
The company stated that it currently applies over 20 types of threat detection models to various areas, including web, network, VPN, and DNS.
organisation
CTI
CTI Lab Representative Cho Hong-yeon stated that "this financial sector attack can be analyzed as a normal operation learned by the AI model, allowing detection of personal information leaks before they occur, in the repeated review stage."
organisation
Agentic Data Breach
Profile of an Agentic Data Breach
In June, Spain's National Cryptologic Center (CCN) published a
report
warning about the "paradigm shift" malicious AI represents for cybersecurity.
organisation
National Cryptologic Center
Profile of an Agentic Data Breach
In June, Spain's National Cryptologic Center (CCN) published a
report
warning about the "paradigm shift" malicious AI represents for cybersecurity.
organisation
CCN
Profile of an Agentic Data Breach
In June, Spain's National Cryptologic Center (CCN) published a
report
warning about the "paradigm shift" malicious AI represents for cybersecurity.
organisation
the Korea Internet & Security Agency
29CM promptly identified the incident and blocked the affected access route, reporting it to the Korea Internet & Security Agency (KISA).
organisation
KISA
29CM promptly identified the incident and blocked the affected access route, reporting it to the Korea Internet & Security Agency (KISA).
organisation
Bank
Shinhan Bank's loan recruitment inns can access their own loan processing status through the mobile website 'M Shinhan'.
organisation
Red Team
According to a Red Team insider who is familiar with the financial sector, "Unlike installing malicious code on the server or executing abnormal commands, an attacker can enter a service that appears to be open normally and change only the request value, which can be detected as a normal connection by network monitoring systems.
data_breach
138,841 records
Out of these, 138,841 records contained names, while 21,011 records contained names and email addresses, phone numbers, delivery information, and more.
data_breach
21,011 records
Out of these, 138,841 records contained names, while 21,011 records contained names and email addresses, phone numbers, delivery information, and more.
victims
20,0005 customer information
Shinhan Bank has estimated that approximately 20,0005 thousand customer information was leaked, and the financial authorities and the Financial Security Institute are investigating the cause of the incident.
organisation
CTO
Gene Moody, field chief technology officer (CTO) at Action1, notes how obvious it is that AI already has the capability, and that hackers en masse are inevitably starting to take advantage.
organisation
Spanish Organization
AI Agent Breaches Spanish Organization, Modifies Personal Data.
organisation
Modifies Personal Data
AI Agent Breaches Spanish Organization, Modifies Personal Data.
organisation
Above Security
In this new reality, where autonomous systems can chain familiar cyberattack steps together without a human manually driving every stage, "That changes the defender’s time horizon," says Aviv Nahum, co-founder and CEO at Above Security.
Tactical Metrics
Metrics
data_breach
159,852
Data Records
Click for context!
The 29CM sister company, 29CM, recently experienced a data breach incident where an external API request to retrieve order information on August 27th resulted in the exposure of 159,852 customer personal data records.
Metrics
data_breach
220,000
Personal Data Records
On September 4th, a consultation record API revealed unauthorized access, resulting in the exposure of approximately 220,000 personal data records.
Metrics
data_breach
138,841
Records
Out of these, 138,841 records contained names, while 21,011 records contained names and email addresses, phone numbers, delivery information, and more.
Metrics
data_breach
21,011
Records
Out of these, 138,841 records contained names, while 21,011 records contained names and email addresses, phone numbers, delivery information, and more.
Metrics
victims
200,005,000
Customer Information
Shinhan Bank has estimated that approximately 20,0005 thousand customer information was leaked, and the financial authorities and the Financial Security Institute are investigating the cause of the incident.
Intelligence Sources
Dark Reading
2026-09-18
Dailysecu
2026-10-02
Dailysecu
2026-10-08
Dailysecu
2026-10-08
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-08T10:32
Comprehensive Tactical Telemetry
Highly Correlated Entities
29x
organisation
Identified Entity
LLM
entity
13x
timeline
Temporal Reference
July 7
date
5x
target region
Target Country
Hong Kong
country
5x
industry
Targeted Sector
Finance
sector
3x
tactic
Cyber Operation Type
Botnet
tactic
2x
attribution
Attributing Entity
CrowdStrike Intelligence
authority
2x
data breach
Records
138,841
records
Contextual Telemetry
Context Block
7 METRICS
general metric
Types
20
types
data breach
Data Records
159,852
data records
data breach
Personal Data Records
220,000
personal data records
victims
Customer Information
200,005,000
customer information
target region
Target Region
LATAM
region
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
malware
Malware Payload
Cyclops Blink
tool
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.