‘A breach of sensitive information such as disease-related data could be disastrous’ ... Hacking fears reach the insurance industry, too
- Input
- 2026-10-06 15:43:33
- Updated
- 2026-10-06 15:43:33

[Financial News] A series of hacking incidents across the financial sector has put the insurance industry on edge as well. As hacking concerns that first emerged around the banking sector spread across the financial industry, insurers have begun checking for similar breaches and reviewing their security management practices. Insurers handle a wide range of customer information, including not only ordinary personal data but also health- and disease-related information and vehicle-related information, and believe that any incident could have far-reaching consequences.
According to the financial sector on the 6th, the Financial Supervisory Service is conducting urgent security checks across the entire financial industry. Banks and card companies must complete their checks by today, while insurers, securities firms, savings banks and electronic financial businesses, among others, must finish by the 8th. The checks cover each financial company’s security management, externally exposed assets, authentication and access controls, and its overall security system.
Insurers process a wide range of customer information, including health- and disease-related information and vehicle-related information, when entering into and managing contracts and paying insurance claims. The concern is that combining different kinds of information could make it possible to identify a specific individual or infer personal characteristics, such as their health, increasing the potential harm from a leak.
A security industry official said, “Compared with banks, insurers have to manage a wider variety of information because of the nature of their business.” The official added, “Security levels need to be reviewed with consideration not only for individual pieces of information, such as resident registration numbers, user IDs and passwords, but also for whether combining different kinds of information could identify an individual or reveal their characteristics.”
The nature of insurers’ business is also cited as a factor that increases the burden of security management. Insurance operations span a range of areas, including product development, contract management, claims payments and sales support, so the information systems supporting them also operate in various forms. For this reason, the view is that companies need to review their overall information access and management systems, rather than focusing only on the security of specific systems.
So far, no actual harm, such as personal information being leaked from insurers, has been confirmed in connection with this series of hacks, according to reports. However, insurers are checking for signs of similar access based on attack information shared by financial authorities, while reviewing their overall security management practices.
The card and finance-company sectors are also stepping up their vigilance. Since card companies handle sensitive financial information such as payment and credit data, and finance companies handle customer information related to loans, the possibility of similar breaches cannot be ruled out.
A security industry official said, “In the wake of this incident, financial companies need to go beyond checking only whether personal information has been leaked and review the management of their stored data and information systems as a whole.” The official added, “Insurers in particular should take the characteristics of the information they handle into account and review personal information protection and information security from a comprehensive perspective.”
[email protected] Hong Yeji Reporter