[Editorial] Financial Sector Easily Breached by AI-Powered Hacking, Leaving Customers Anxious
- Input
- 2026-10-04 19:18:26
- Updated
- 2026-10-04 19:18:26

Both the scale and nature of the damage are serious. Information on more than 25,000 people was taken from Shinhan Bank alone, while data on about 40,000 people was leaked from YeGaram Savings Bank. In particular, the information exposed by Shinhan Bank included not only names and contact details but also annual income, calculated loan limits, resident registration numbers and linked information. There are concerns that such financial data, when combined with other personal information, could lead to direct financial losses through voice phishing or loans taken out through identity theft.
Financial authorities and the cybersecurity industry believe that artificial intelligence (AI) may have been used in the attacks. The attackers may have used AI agents and other tools to target multiple financial companies at random. In fact, after authorities shared the attackers' IP addresses, additional victims were identified one after another as financial institutions compared their access logs. Inspections must be expedited, as more financial companies may not yet have identified the damage.
The hackers did not penetrate core systems such as internet and mobile banking. Instead, they targeted auxiliary systems, including simple inquiry services for loan agents and work-support systems for employees. While focusing on securing core networks, financial institutions appear to have left vulnerabilities in the management of peripheral systems connected to the outside. Shinhan Bank, in particular, took 15 hours to detect the attack and nearly 30 hours to block it. The fact that Shinhan Bank received perfect scores for six consecutive years in the FSC's inspections of personal credit information protection highlights the limitations of the current assessment system.
Meanwhile, financial companies have recently reduced their security investments. This raises questions about the financial sector's complacent attitude toward security. According to disclosures by the Korea Internet & Security Agency (KISA), the four major banks—KB Kookmin, Shinhan, Hana and Woori—invested 153.7 billion won in information security last year, down 9.8% from the previous year. Information security accounted for only around 8% of their information technology (IT) investments. The execution rate for information-security budgets allocated by eight banks last year was just 69%. Financial companies should reflect on whether they have treated security merely as a 'cost' while earning substantial profits year after year.
Financial companies must first inspect every system accessible from outside, whether intended for customers or employees, to eliminate security blind spots. Since sharing attackers' IP addresses proved effective in uncovering hidden damage, authorities should also strengthen joint response mechanisms, including real-time threat-information sharing among financial authorities, the Financial Security Institute, KISA, the police and financial companies. Authorities must move beyond document-based assessments, expand hands-on inspections such as surprise penetration testing, and verify that vulnerabilities are actually being fixed.
Discussions on easing 'network separation,' which physically isolates internal computer networks from the external internet, should also be accelerated. The systems breached this time were services that were accessible from outside in the first place. This shows that existing regulations requiring network separation are not sufficient on their own. Financial companies should be allowed to use the latest AI security technologies, but they must also bear substantially greater responsibility for ensuring real security. AI-driven attacks must be met with AI-based defenses. The current security framework, which focuses only on protecting core networks, cannot stop the next attack.