Seven Financial Firms Breached... Information on 66,000 Individuals and 2,200 Corporations Leaked [Widespread Cyberattacks Across the Financial Sector]
- Input
- 2026-10-04 18:22:48
- Updated
- 2026-10-04 18:22:48

■ Data breaches confirmed at seven financial institutions
According to the financial sector on the 4th, seven institutions have been confirmed to have suffered information leaks caused by external hacking since the beginning of this month: Shinhan Bank, KB Kookmin Bank, Bank of Hope, BNK Busan Bank, Hyundai Capital Services, Yegaram Savings Bank, and Welcome Savings Bank.
By institution, customer information leaked from Shinhan Bank involved 25,729 people, while the figure was approximately 40,000 at Yegaram Savings Bank, 119 at KB Kookmin Bank, and 89 at Bank of Hope. Including 146 Hyundai Capital Services mortgage-loan agents and 11 outsourced developers at BNK Busan Bank, information on approximately 66,000 people was compromised. Welcome Savings Bank identified signs of a hack-related leak of corporate customer information during an internal inspection on the 3rd. The leaked information is estimated to cover up to 2,200 records, including corporate names, contact persons' names, email addresses, and telephone numbers.
Loan inquiry and business-support services became attack vectors at banks. At Shinhan Bank, customer names, telephone numbers, annual income, and calculated loan limits were leaked through services for loan agents, including a loan inquiry service. The leak also included 66 resident registration numbers and 97 connection information (CI) records belonging to some customers. KB Kookmin Bank suffered a leak through its employee mobile business-support system, while Bank of Hope experienced one through its operations support system (ODS). At BNK Busan Bank, the names and telephone numbers of outsourced developers were exposed.
Hyundai Capital Services also had a service related to loan agents targeted. On an inquiry page where customers could check information about mortgage-loan agents, not only names, mobile phone numbers, and email addresses but also confidential information—including internal agent numbers and resident registration numbers—was extracted. At Yegaram Savings Bank, individual customers' names, dates of birth, and contact details were leaked.
Woori Bank and Nonghyup Bank said they had been targeted by external attacks but blocked them quickly, and that no information leak had been confirmed so far. The Korea Federation of Community Credit Cooperatives also found signs of an attempted access from the same internet protocol (IP) address used by the attacker in the Shinhan Bank customer information leak. The federation said, "We blocked the abnormal access and prevented an information leak." Nonghyup Mutual Finance, which shares a network with Nonghyup Bank, is also known to have blocked similar intrusion attempts.
■ Possibility of AI-enabled hacking raises concerns about further damage
Security problems in the financial sector have also occurred repeatedly in the past. According to data that the office of Park Jun-tae of the People Power Party obtained from the Financial Supervisory Service, a total of 36 cyberattacks were reported from January 2024 through the end of August this year: 14 in the financial sector and 22 in the electronic financial services sector. Of the 14 incidents in the financial sector, banks accounted for the largest share with six, followed by insurance companies with four, specialized credit finance companies with two, and securities firms and savings banks with one each. The attack methods also varied, ranging from intrusions exploiting security vulnerabilities to malware infections and denial-of-service attacks.
There were also leaks of employee information and disruptions to internal business systems. At Standard Chartered Bank Korea, some employee information was exposed in 2024, and use of its employee mobile-device management system was halted last year. Some employee information was also exposed at KB Life Insurance last year, while employee information at Baro Savings Bank was leaked by malware in April this year.
Cyberattacks also led to disruptions in financial services. Seoul Guarantee Insurance (SGI) suspended its services for 64 hours last July after being infected with ransomware. At KB Kookmin Bank, a denial-of-service attack in 2024 delayed banking login services by 34 minutes, while access to Hana Card's Hana Money service was suspended for 2 hours and 47 minutes following the same type of attack last year.
Against this backdrop, the recent series of hacking incidents has raised the possibility of automated attacks using AI. A financial industry official said, "As AI moves into a phase in which it can identify vulnerabilities in financial systems and attack them automatically, it is becoming increasingly difficult to respond using existing security methods alone," adding, "The defense side must also use AI to improve its ability to detect vulnerabilities and respond to attacks."
[email protected] Ye Byeong-jeong Reporter