“AI Hacking” Spreads from Banks to the Non-Bank Financial Sector; Authorities to Summon All Financial Institutions on the 4th
- Input
- 2026-10-03 21:54:23
- Updated
- 2026-10-03 21:54:23

[Financial News] As personal information leaks caused by novel AI-based hacking have spread from commercial banks to non-bank financial institutions such as savings banks and capital companies, financial authorities have urgently summoned CEOs from across the financial industry to launch a comprehensive response.
■ The breach has reached the non-bank financial sector; authorities to summon all sectors on the 4th
According to financial-sector sources on the 3rd, the Financial Services Commission (FSC) and the Financial Supervisory Service will hold an 'Emergency Response Meeting' at 2 p.m. on the 4th at Government Complex Seoul. The meeting will be attended by the heads of associations representing the entire financial industry—including banking, financial investment, insurance, specialized credit finance, savings banks, mutual finance, virtual assets and fintech—as well as CEOs of financial institutions affected by security breaches. FSC Chairman Lee Eok-won will chair the meeting, while Lee Chan-jin, governor of the Financial Supervisory Service, will also attend as authorities work to contain the incident.

Authorities had initially planned to hold the meeting on the 7th after compiling the results of each financial institution's self-inspection. However, they abruptly moved up the meeting after additional damage at non-bank financial institutions was reported one after another over the weekend, heightening concerns.
■ Damage spreads across the board, from commercial banks to capital companies; information on tens of thousands leaked
The information leaks identified so far have affected the financial sector broadly. At Yegaram Savings Bank, a hacker of unknown identity accessed the bank's server, exposing the names, dates of birth and contact information of approximately 40,000 customers. At Shinhan Bank, an unauthorized party bypassed authentication procedures to access a simple inquiry service exclusively for loan recruiters, compromising information belonging to approximately 25,000 customers.
At KB Kookmin Bank, the names, addresses and encrypted resident registration numbers of 119 people were leaked through an employee mobile work-support system. Damage was also confirmed at Bank of Hope, involving 89 people; Hyundai Capital Services, involving 146 housing-loan agents; and Busan Bank, involving 11 outsourced employees. Woori Bank and Nonghyup Bank were also targeted in hacking attacks, but no information leak has yet been confirmed.
■ Signs of Chinese-language-based 'AI hacking'; mounting evidence of indiscriminate attacks by a single group
Financial authorities believe the series of incidents was a novel cyberattack that used AI to automate the process of identifying security vulnerabilities and gaining access. In some attacks, they also detected signs that Chinese-language-based AI hacking tools had been used. As financial institutions cross-check the attacker IP addresses shared across the industry by the Financial Supervisory Service and the Financial Security Institute against their own access logs, additional leaks are being uncovered. This is strengthening the possibility that the attacks were carried out indiscriminately by a single hacking group.
Authorities are keeping open the possibility of further information leaks and plan to comprehensively review, at the emergency meeting, the status of IP-address cross-checks and self-inspections by all financial institutions. Smaller financial institutions face a greater risk of additional damage because they generally have fewer information-security personnel. Authorities will therefore move quickly to establish effective countermeasures and strictly oversee affected institutions' efforts to protect consumers and provide compensation.
[email protected] Park Ji-hyun Reporter