INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Korean Financial Institution's AI System Leaks Sensitive Information to Hackers

| 2026-10-08 07:06 CRITICAL LOW AI-ENABLED ATTACK · AUTONOMOUS DATA BREACH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
A recent incident of cyberattack targeting Korea's financial sector has been reported, with AI-based attacks and data breaches involving personal information. Citi AI Lab warned that such incidents can lead to personal data leaks and more severe crimes. The attack process was analyzed by Citi AI Labs, which divided it into five stages: service entry, customer number collection, linked service queries, bulk data extraction, and incident awareness and response. In the first four stages, an AI-based abnormal behavior detection technology can be applied, detecting repetitive customer information queries or abnormal service access. The attack was detected through analysis of unusual DNS traffic attempting to embed an internal server into a proxy botnet by communicating with an external malicious IP address. Citi AI Lab's in-house detection model compared favorably with publicly disclosed features of its solution, DTI.ai, which analyzes normal communication activities and detects abnormal changes without predefined rules or signatures. The company applies over 20 types of threat detection models to various areas, including web, network, VPN, and DNS.
Technical Mitigations AI-generated
• Pre-compromise (ATT&CK mitigation for Botnet): This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls. • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Cyclops BlinkCyclops Blink
Target & Sectors
LATAM LATAM NORTH_AMERICA NORTH_AMERICA automotiveautomotive mediamedia governmentgovernment financefinance
Incident Timeline
‎July 7
CrowdStrike Intelligence released a report on July 7 identifying the infrastructure related to attacks on Korean financial institutions from September 2026 to early October 2026.
attribution CrowdStrike Intelligence
‎August 27th
Threat actors exploited a vulnerability in an external API to retrieve order information, resulting in the exposure of 159,852 customer personal data records.
tactic Data Breach
organisation API
data_breach 159,852 data records
‎September 4th
Threat actors exploited a consultation record API to reveal unauthorized access, resulting in the exposure of approximately 220,000 personal data records.
data_breach 220,000 personal data records
‎September 2026
CrowdStrike Intelligence identified infrastructure related to attacks on Korean financial institutions from September 2026 to early October 2026.
attribution CrowdStrike Intelligence
‎Sept. 14
An unidentified hacker used a well-known language model to breach corporate personal data stores, prompting Spain's Data Protection Agency to issue a report on September 14.
target_region Spain
industry Government
attribution Data Protection Agency
‎2026/09/18
Threat actors used AI-driven exploits to target South Korean media and automotive sectors on September 18, 2026.
industry Media
industry Automotive
target_region Korea, Republic of
organisation Media & Automotive
‎September 28
An unidentified attacker attempted to exploit vulnerabilities and steal information on September 28.
‎2026/10/02
An unidentified attacker attempted to exploit vulnerabilities and steal information on September 28.
‎October 2
The Financial Security Institute stated on October 2 that a widespread attack using AI autonomous intrusion tools is underway against domestic financial institutions.
organisation the Financial Security Institute
‎early October 2026
CrowdStrike Intelligence identified infrastructure related to attacks on Korean financial institutions from September 2026 to early October 2026.
attribution CrowdStrike Intelligence
‎2026/10/08
Threat actors used an AI-based intrusion testing tool and a large language model to carry out the attacks on Korean financial institutions, including Shinhan Bank.
organisation LLM
organisation CrowdStrike
organisation IP
organisation FamousSparrow APT Spies
organisation US Politics
organisation ARTEX
organisation Widespread Attack
organisation Shinhan Bank
organisation Vulnerability Exploited
organisation Telegram
organisation CloudStrike
organisation CTI Lab's
organisation DNS
organisation CTI
organisation Agentic Data Breach
organisation National Cryptologic Center
organisation CCN
organisation the Korea Internet & Security Agency
organisation KISA
organisation Bank
organisation Red Team
data_breach 138,841 records
data_breach 21,011 records
victims 20,0005 customer information
organisation CTO
organisation Spanish Organization
organisation Modifies Personal Data
organisation Above Security
Tactical Metrics
Metrics
data_breach
159,852
Data Records
Metrics
data_breach
220,000
Personal Data Records
Metrics
data_breach
138,841
Records
Metrics
data_breach
21,011
Records
Metrics
victims
200,005,000
Customer Information