AI Hacking Hits the Entire Financial Sector, with Damage Varying by Information Security Levels
- Input
- 2026-10-05 08:31:31
- Updated
- 2026-10-05 08:31:31

[Financial News] As the financial sector was broadly exposed to AI hacking attacks, the extent of damage varied by sector and company. Financial authorities and security experts believe that routine system management and the level of internal controls determined the success or failure of security measures.
Experts have pointed out that safeguards must be thoroughly reviewed to prevent secondary or additional damage, such as voice-phishing scams exploiting leaked personal information.
According to financial-sector sources on the 5th, breaches occurred at seven companies: Shinhan Bank, KB Kookmin Bank, Bank of Hope, Busan Bank, YEGARAM SAVINGS BANK, Not_found and Hyundai Capital Services.
PFC Technologies (PFCT) and Mouda, both online investment finance companies, also disclosed the breaches through notices. The same attacker's internet protocol (IP) address was found in hacking incidents involving commercial banks, but it was reportedly different from the IP addresses associated with savings banks and capital companies. The attack methods, however, were said to be similar. Online investment finance companies reported the incidents around the same time, and the circumstances of the breaches are being examined.
By contrast, the securities, insurance and credit-card sectors were exposed to hacking attempts, but no damage reports have been filed to date.
The presence and scale of damage varied widely not only across sectors but also within the same sector.
Shinhan Bank reported that 25,727 records had been leaked, while KB Kookmin Bank reported just 153. The figure for Bank of Hope was 89 individuals. Woori Bank and Nonghyup Bank also faced hacking attempts, but successfully defended against them and suffered no data leakage.
YEGARAM SAVINGS BANK had about 40,000 records leaked, while Not_found had 2,200, showing a wide disparity. Companies also differed in whether the leaked information had been de-identified.
Financial authorities and experts believe that routine system management and the level of internal controls determined the success or failure of security measures.
The results varied depending not only on the use of multi-factor authentication but also on whether companies had externally exposed systems, the level of their security programs, how they managed access rights and whether they encrypted information, as well as how these measures were operated.
At an emergency inspection meeting for the entire financial sector held the previous day, it was also reportedly pointed out that inadequate internal controls and security management were major causes of the breaches.
Financial Services Commission (FSC) Chairman Lee Eok-won also mentioned externally exposed IT assets and services, authentication and access controls, and breach-activity detection systems as areas requiring inspection. He stressed, "The entire security system must be inspected to ensure that there are no gaps."
Financial authorities urged all financial institutions to broadly strengthen controls over ancillary systems targeted in the attacks or minimize their use. Banks and credit-card companies must complete emergency inspections by the 6th, while securities firms, insurers, savings banks and electronic financial businesses must do so by the 8th.
The information made public so far reportedly includes customer names, dates of birth, contact details and resident registration numbers, but no sensitive information that could be directly used for fraudulent payments.
However, as the possibility of secondary damage resulting from the misuse of leaked information cannot be ruled out, the financial sector is remaining highly vigilant to prevent further damage.
[email protected] Park So-hyun Reporter