Tuesday, October 6, 2026

Hacked and unaware for five days... Welcome Savings Bank exposed to attack for 119 hours

Input
2026-10-06 20:31:09
Updated
2026-10-06 20:31:09
Welcome Savings Bank branch counter. Provided by Welcome Savings Bank

[Financial News] It emerged that Welcome Savings Bank and Hyundai Capital did not discover they had been breached until five days after the attacks.
According to documents obtained from the Financial Supervisory Service by the office of Han Chang-min, a lawmaker from the Social Democratic Party, on the 6th, Welcome Savings Bank reported in an incident report submitted to authorities that the breach occurred at around 5:09 p.m. on the 27th of last month.
Welcome Savings Bank became aware of the breach at around 4:04 p.m. on the 2nd of this month. After receiving an email from the Financial Security Institute sharing relevant IP address information following the Shinhan Bank hacking incident, the bank launched an internal review and discovered the breach about 116 hours and 55 minutes after it occurred.
At 4:12 p.m., it began its initial response by blocking the IP address and, a minute later, relayed the situation to the staff member in charge of operations.
The hacking attack was reported to have ended at around 4:25 p.m. that same day. The incident report recorded a total attack duration of 119 hours and 16 minutes.
The attack exposed corporate internet banking IDs, company names, representatives’ names, business contact numbers, mobile phone numbers, email addresses and other information.
Welcome Savings Bank estimated that 2,299 of the 2,370 leaked data records contained personal information. The figure has not been deduplicated, and the bank plans to provide a further report on the number of affected individuals.
Hyundai Capital, which also had some personal information belonging to 146 mortgage loan agents leaked, was likewise found to have become aware of the incident only belatedly.
Hyundai Capital was subjected to a hacking attack from 6:37 a.m. on the 27th of last month and was compromised for 24 minutes. The attack ended at around 7:01 a.m. that same day.
However, Hyundai Capital did not become aware of the incident until around 5:08 p.m. on the 2nd of this month, five days later.
Hyundai Capital also identified the breach while reviewing access records related to the hacking IP with assistance from the Financial Security Institute. It found signs that non-public resident registration numbers had been leaked from the mortgage loan agent information lookup website, the page that had been accessed.
Hyundai Capital reported that, after investigating indications and the possibility of customer information being leaked, it found no damage.
Lawmaker Han Chang-min said, "It is a serious problem that financial companies have still failed to respond properly despite repeated personal information leaks," adding, "At the parliamentary audit, I will thoroughly examine whether financial companies, as well as the supervisory authorities, bear responsibility."
[email protected] Seo Ji-yoon Reporter