Sunday, October 4, 2026

From Banks and Savings Banks to Mutual Finance... Widespread Hacking Puts Financial Sector on High Alert [Comprehensive]

Input
2026-10-04 13:10:33
Updated
2026-10-04 13:10:33
(Source: Yonhap News)
[Financial News] The financial sector is on high alert as data breaches caused by hacking spread from commercial and regional banks to savings banks and capital companies. Some of the attacks are suspected to have involved AI agents, while loan-broker inquiry services and employee work-support systems have been breached one after another. Financial authorities are urgently summoning the heads of associations across all financial sectors and the CEOs of affected financial companies to inspect security vulnerabilities in externally accessible computer systems and determine whether there has been further damage.
Data Breaches at Savings Banks and Capital Companies
According to financial-sector sources on the 4th, hacking incidents successively identified in the banking sector are spreading to non-bank financial institutions, including savings banks and capital companies.
Hyundai Capital Services said on the 3rd that some personal information belonging to 146 home-loan brokers had been leaked in a hacking incident. The company discovered on the afternoon of the 2nd that its home-loan broker inquiry page had been attacked through an overseas Internet Protocol (IP) address. The webpage allows customers to check brokers' publicly available information, but the breach exposed not only names, mobile phone numbers and email addresses, but also nonpublic information such as internal broker identification numbers and resident registration numbers.
Yegaram Savings Bank also announced on the 2nd that customer information had been leaked. The bank confirmed signs that a hacker had accessed a server containing customer information on the 30th of last month, resulting in a data breach. The leaked information reportedly included names, dates of birth and contact details, with the scale estimated at approximately 40,000 cases.
A data breach involving corporate customers was also confirmed at Welcome Savings Bank following a hacking incident. The exact scale of the damage and the circumstances of the leak are reportedly still under investigation.
After the leak of information belonging to approximately 25,000 Shinhan Bank customers became known, similar damage has continued to emerge at other financial companies. At Shinhan Bank, customer names, phone numbers, annual income and calculated loan limits were extracted through an inquiry service used by loan brokers. The breach also included 66 resident registration numbers and 97 connected information (CI) records belonging to some customers.
At KB Kookmin Bank, the personal and credit information of 119 customers was leaked through an employee mobile work-support system. Bank of Hope also determined that personal information belonging to 89 customers had been leaked following abnormal access to its operations support system (ODS).
Among regional banks, an incident occurred at Busan Bank in which the names, phone numbers and other information of 11 outsourced development employees were exposed.
There were also cases in which hacking attempts were blocked before they resulted in data breaches. Woori Bank and Nonghyup Bank blocked external attacks with their security systems, and no data breaches have been identified so far. The Korea Federation of Community Credit Cooperatives also reportedly used its own security equipment to block access from the same attacker IP address used in the Shinhan Bank customer information breach. Nonghyup Mutual Finance, which shares a network with Nonghyup Bank, is also known to have blocked a similar intrusion attempt.
Financial Authorities to Launch Emergency Inspection
The Financial Services Commission (FSC) plans to convene the heads of associations across all financial sectors and the CEOs of financial companies affected by security incidents for an emergency inspection meeting at 2 p.m. that day at Government Complex Seoul. FSC Chairman Lee Eok-won will preside over the meeting, which will also be attended by Lee Chan-jin, Governor of the Financial Supervisory Service, to discuss the status of security incidents and response measures.
The authorities had initially planned to receive the results of financial companies' internal inspections on the 7th after the holiday period. However, the schedule was brought forward after damage was also confirmed in the non-bank financial sector. The inspection will cover not only banking, financial investment, insurance, specialized credit finance, savings banks and mutual finance, but also virtual assets and fintech.
In these incidents, loan-broker inquiry services and employee work-support systems became the main targets rather than internet and mobile banking services used directly by customers. Security weaknesses in the authentication and access controls of externally accessible systems led to the leakage of customer information.
There remains a possibility that additional damage will be uncovered at financial companies that have not yet detected the breaches.
The authorities will also strengthen joint efforts to quickly share the IP addresses and methods used in the attacks, as well as records of intrusion attempts, among financial companies and relevant agencies. Based on a security vulnerability checklist, the authorities plan to collect the results of financial companies' internal inspections. They will also oversee and supervise whether customer protection and compensation for victims at affected financial companies are carried out without disruption.
A financial-sector official said, "As attacks have entered a phase in which AI finds vulnerabilities in financial systems and launches attacks automatically, it is becoming difficult to respond using existing security measures alone. The defense side must also use AI to improve its ability to detect vulnerabilities and respond to attacks."
[email protected] Ye Byeong-jeong and Park Moon-su Reporter