Sunday, October 11, 2026

Financial-sector hacking fallout spreads across public agencies, universities and churches... Data on 1 million people leaked

Input
2026-10-11 09:12:18
Updated
2026-10-11 09:12:18
Yonhap News Agency
[Financial News] A massive personal data breach that began in the financial sector is spreading across the board to public corporations, universities and large churches. As hacking groups exploit artificial intelligence (AI) tools and focus their attacks on poorly secured external contractors and peripheral business systems, the cumulative number of people affected so far is believed to have exceeded 1 million.
According to sources in the financial and cybersecurity industries on the 11th, data leaks caused by hacking were confirmed at a total of seven financial firms—from late last month to early this month—including commercial banks such as Shinhan, KB Kookmin, Hana and BNK Busan Bank, as well as savings banks and capital firms. Information belonging to around 25,000 loan applicants at Shinhan Bank was leaked, and data on about 40,000 people was also stolen from Yegaram Savings Bank. There were also attempts to access three internet-only banks, including KakaoBank, from the same IP address, but they did not result in actual data leaks.
The damage is also spreading rapidly beyond the financial sector. The Korea Electric Power Corporation (KEPCO) urgently removed personal information belonging to about 24,000 employees after it was exposed on an external webpage. Seoul Cyber University is investigating a leak of students’ and staff members’ academic records and contact details, while Yoido Full Gospel Church is conducting its own analysis, allowing for the possibility that information on up to 850,000 congregants was leaked to servers operated by attackers overseas.
The most notable feature of this string of data breaches is that the attacks used 'external partners' as a gateway, rather than targeting the organizations’ own computer networks.
After a single online learning management system (LMS) provider, 'Malgeunsoft,' was hit by a hacking attack on the 19th of last month, around 20 organizations that had outsourced system management to the company—including the Ministry of National Defense, the National Academy of Integrity and Rights Education, and the Kia labor union—were breached simultaneously. More than 145,000 people’s information was leaked from just three organizations: the National Academy of Integrity and Rights Education (about 100,000 people), the Korea Educational Facilities Safety Institute (about 40,000) and the Kia labor union (about 5,000). It was also revealed that, at some organizations, historical data that should have been destroyed after system upgrades had instead been left on Malgeunsoft’s servers and stolen.
The breaches in the financial sector also resulted from attacks on peripheral systems that bypassed core networks, such as a service exclusively for loan agents at Shinhan Bank and a mobile work-support system for employees at KB Kookmin Bank. In effect, attackers focused on the 'weak links' whose security was relatively lax compared with that of the main networks.
With AI brought into the hacking process, the speed and destructive power of the attacks also doubled. According to the cybersecurity industry, signs were detected that a Chinese-language-based open-source penetration-testing tool called 'Artex (ARTEX)' had been used in conjunction with AI coding tools in the attacks. Even hackers with limited skills can now use AI to attack a wide range of targets in a short time.
Cybersecurity experts say it is essential to strengthen the basics of security—including multi-factor authentication, vulnerability patching and access controls—as attack techniques become more sophisticated. They also emphasized that regular security checks of external contractors and the immediate destruction of unnecessary data must come first.
As the situation spread, the government also stepped up its response. The Ministry of Science and ICT and the Korea Internet & Security Agency (KISA) entered a 24-hour emergency response system, while the Ministry of Education issued urgent security-check recommendations to about 400 affiliated organizations.

[email protected] Kim Dong-gyu Reporter