Monday, October 5, 2026

AI Hacking Emergency... 4,777 Vulnerabilities Exposed at Banks [Widespread Hacking Across the Financial Sector]

Input
2026-10-04 18:26:15
Updated
2026-10-04 18:26:15
Lee Eok-won, chairman of the Financial Services Commission, walks behind Lee Ho-sung, president and CEO of Bank of Hope (from left in the front row), Lee Hwan-joo, president of KB Kookmin Bank, and Jung Sang-hyuk, president of Shinhan Bank, after attending an emergency inspection meeting on financial-sector security incidents held at Government Complex Seoul on the afternoon of the 4th. Yonhap News Agency
AI-enabled cyberattacks are spreading throughout the financial sector, but some security vulnerabilities discovered at domestic banks have reportedly been left unresolved for extended periods. Although banks are increasing the number of simulated hacking exercises they conduct each year to identify vulnerabilities, some issues cannot be addressed immediately because they require a complete system replacement or other major measures. Critics warn that it is only a matter of time before hackers target them.
President Lee Jae Myung called on financial authorities to respond firmly to a series of personal-information breach incidents in the financial sector.
According to data the Financial Supervisory Service submitted on the 4th to the office of Park Sang-hyuk, a Democratic Party of Korea lawmaker and the ruling party's secretary on the National Assembly Political Affairs Committee, 20 domestic banks conducted a total of 481 simulated hacking exercises from 2022 through August this year and discovered 4,777 valid vulnerabilities.
Simulated hacking, or penetration testing, is a goal-oriented inspection method that uses the same techniques as actual hackers, or cyberattackers, to demonstrate the possibility of penetrating a financial company's information technology infrastructure. Banks conduct simulated hacking exercises every year using their own security personnel and in cooperation with white-hat hackers from the Financial Security Institute.
As the use of AI expands, the volume and speed of vulnerability discovery are rapidly increasing. The problem is that some vulnerabilities cannot be addressed immediately even after they are found. The 20 domestic banks conducted 107 simulated hacking exercises in 2024 and identified 1,071 vulnerabilities. One specialized bank among them has yet to address one of those vulnerabilities.
The Financial Supervisory Service said, "Immediate action is difficult because addressing the vulnerability requires shutting down the system or replacing it entirely." As a result, banks are responding by registering blocking rules on security devices or strengthening monitoring until remediation is complete.
Financial companies operating older systems often find that discovered vulnerabilities cannot be resolved through simple software patches alone. An official in the financial security industry said, "Addressing some vulnerabilities requires replacing every system built up over decades, and in some cases the employees responsible at the time have retired, leaving no relevant records." The official added, "We do not even know how much the necessary budget would be or whether the required technology exists."
The one vulnerability discovered at a specialized bank last year also remains unresolved.
Small and midsize financial companies with weaker information-security capabilities could become easy targets for hackers at any time. Since June, the Financial Services Commission has been easing network-separation regulations on an emergency basis for 49 financial companies that have total assets of at least 10 trillion won, at least 1,000 permanent employees, and are required under the Electronic Financial Transactions Act to appoint a chief information security officer (CISO). Financial holding groups regard strengthening the security capabilities of their smaller affiliates as a key task.
At the "Meeting on Responding to Hacking and Voice Phishing in the AI Transformation (AX) Era" held in June, Jin Ok-dong, chairman of Shinhan Financial Group, acknowledged, "Companies with smaller profits, sales, and workforces cannot independently defend themselves against cyberattacks."
Park Sang-hyuk said, "As hacking attacks targeting banks intensify, increased security investment and improvements to aging IT infrastructure must support efforts to ensure that vulnerabilities lead not merely to discovery but to prompt remediation."
After receiving a briefing on personal-information breach incidents in the financial sector and the status of the response, President Lee instructed officials to "ensure a thorough investigation and the preparation of countermeasures."
[email protected] Park Moon-soo and Seo Ji-yoon Reporter