Monday, October 5, 2026

Banks' 'Security Gaps' Rise 20%, but Information Security Investment Falls Instead [Financial Sector Helpless Against AI Attacks (Part 1)]

Input
2026-10-04 18:21:17
Updated
2026-10-04 18:21:17
Security vulnerabilities discovered through penetration testing in the banking sector rose by more than 20% last year. Although 952 vulnerabilities had been identified by August this year, information security investment at three major banks with comparable data fell instead. As hacking incidents have been confirmed at commercial banks, savings banks and capital firms following the breach at Shinhan Bank, calls are growing for a comprehensive review of whether sufficient investment is being made to address vulnerabilities and respond to attacks.
■ Bank investment 'falls' despite rising vulnerabilities
According to data that the office of Park Sang-hyuk of the Democratic Party of Korea obtained from the Financial Supervisory Service on the 4th, 20 banks found 1,286 valid vulnerabilities through penetration testing last year. That was an increase of 215, or 20.1%, from 1,071 the previous year. The number of vulnerabilities discovered has risen every year, from 683 in 2022 and 785 in 2023 to more than 1,000 in 2024. This year, 952 vulnerabilities had been found by August, of which 846 had been remediated. Follow-up measures were still underway for the remaining 106. The number of penetration tests rose 13.1%, from 107 in 2024 to 121 last year. In other words, the 20.1% increase in vulnerabilities outpaced the growth in the number of penetration tests.
Meanwhile, information security investment at major banks appears to be declining.
According to information security disclosures filed with the Korea Internet & Security Agency (KISA), KB Kookmin Bank, Shinhan Bank, Bank of Hope and Woori Bank invested a combined 153.77 billion won in information security last year. KB Kookmin Bank spent 43.32 billion won, followed by Bank of Hope with 37.17 billion won, Shinhan Bank with 36.9 billion won and Woori Bank with 36.38 billion won. Bank of Hope participated in the disclosure for the first time this year and released its results for the previous year, while Nonghyup Bank has not yet participated in the disclosure.
Information security investment at the three banks with comparable year-over-year data—KB Kookmin Bank, Shinhan Bank and Woori Bank—fell 5.9%, from 123.95 billion won in 2024 to 116.6 billion won last year. Although KB Kookmin Bank increased its investment, spending declined at Shinhan Bank and Woori Bank. As a result, the three banks' combined information security investment as a share of total information technology (IT) investment fell from 9.14% to 8.35%.
A banking industry official explained, "Banks do not carry out major system upgrades every year, so investment can rise and then fall," adding, "It may look small as a proportion, but the absolute amount is large."
■ Concerns over blind spots in detection extend to the secondary financial sector
Against this backdrop, security concerns across the financial sector are intensifying. After a data breach affecting more than 25,000 people at Shinhan Bank became known on the 1st, information leaks were also confirmed at other commercial banks, savings banks and capital firms. Similar intrusion attempts were detected at mutual finance institutions, but no data breach was found to have occurred. In particular, the attacks identified this time had a common feature: they targeted separate systems with external points of contact, such as services related to loan recruiters and employee business support systems. Some of the attacks are believed to have used AI agents.
As AI tools become more sophisticated, the barrier to automating information security attacks has fallen. This has raised concerns that attackers could target a wider range of areas, including business support systems that had previously been given relatively low management priority.
Another challenge is the difficulty of immediately determining the purpose and type of an attack. Officials said many attempts are difficult to distinguish between efforts to penetrate a system directly and preliminary reconnaissance intended to install malware. Even if detected attacks have been blocked, the possibility that some intrusion attempts escaped security systems cannot be ruled out.
Financial industry observers say institutions need to quickly address vulnerabilities found through internal inspections while expanding the scope of security checks and investment to systems with external points of contact, including loan recruiter lookup services and business support systems. A financial sector official said, "Amid the unrelenting stream of random attacks every day, the frequency of attacks has surged and remains high," adding, "In many cases, it is difficult to determine the attackers' intentions or the type of attack, and there may have been attacks we failed to detect, so it is difficult to guarantee that we have blocked them all."
[email protected] Ye Byeong-jeong Reporter