Hacking attacks that targeted South Korea’s five biggest banks are spreading beyond regional banks to secondary financial firms such as savings banks and capital companies. After customer data leaks were confirmed at Shinhan, KB Kookmin and Hana, about 40,000 customers’ data were leaked at Yegaram Savings Bank and personal data of 146 housing loan agents were leaked at Hyundai Capital.
Woori Bank and NH Nonghyup Bank were also attacked, but no data leak has been confirmed so far. Financial regulators decided to bring forward their planned inspection schedule and urgently convene heads of associations across the financial sector and chief executives of financial companies where security incidents occurred.
As of Oct. 3, the financial sector said recent hacking targets are rapidly expanding from banks to savings banks and specialised credit finance companies.
All five major banks faced external hacking attempts, and actual personal data leaks occurred at Shinhan, KB Kookmin and Hana. At BNK Busan Bank, personal data of 11 outsourced development workers were exposed.
All five major banks attacked... Shinhan leaks data on 25,000 people
Among the five major banks, Shinhan Bank suffered the biggest damage. At Shinhan Bank, abnormal access to a loan broker query service led to the leak of information on about 25,000 customers. The data included information related to loan applications such as customer names and phone numbers, annual income and calculated loan limits, and 66 cases of resident registration numbers and 97 cases of connected information (CI) were also believed to have been leaked.
At KB Kookmin Bank, an employee mobile business support system was breached from outside, leaking personal and credit information of 119 people. The leaked data included customer names and phone numbers, addresses and encrypted resident registration numbers. The system is an employee-only system operated separately from customer financial transaction systems such as internet banking or mobile banking.
Hana Bank also saw the leak of information on 89 customers due to abnormal external access to its sales support system (ODS). The data included resident registration numbers, names, addresses, email addresses, phone numbers, mobile phone numbers and workplace names. Hana Bank blocked the related IP addresses and began inspecting similar systems.
At BNK Busan Bank, the names, phone numbers, dates of birth and email addresses of 11 outsourced development workers were exposed through a webpage. At Woori Bank and NH Nonghyup Bank, external hacking attempts were blocked through intrusion prevention systems and no data leak damage has been confirmed so far.
A common feature of these incidents is that they were concentrated on auxiliary systems with external touchpoints, such as loan query services, employee mobile business support systems and sales support systems, rather than core financial transaction systems such as internet and mobile banking.
Financial regulators also instructed financial companies to inspect authentication and access control vulnerabilities and any unnecessary exposure of information across externally exposed computer systems and services.
Spreads to savings banks and capital firms... Yegaram estimated at 40,000 people
Damage that had been concentrated in the banking sector has spread to secondary financial firms.
Yegaram Savings Bank said on Oct. 3 it confirmed signs that personal data were leaked after an unidentified hacker accessed a server containing customers’ personal information on Sept. 30. The leaked information includes customers’ names, dates of birth and contact details.
The scale of damage is estimated at about 40,000 people, and the exact scope is being further checked. The bank halted related services immediately after recognising the incident and blocked external IP addresses.
Hyundai Capital also confirmed on the day that some personal data of 146 housing loan agents were leaked.
The company believes the housing loan agent query page was attacked through overseas IP addresses, and leaked data included names, mobile phone numbers, emails and Korea Credit Finance Association registration numbers, as well as internal agent numbers and resident registration numbers. Hyundai Capital explained that it had not confirmed any leak of general customer personal data or access to internal systems.
As the scope of attacks expands from banks to savings banks and capital firms, concerns are growing that additional damage could spread across the financial sector. It has not been confirmed so far whether the incidents were carried out by the same attacker or group, or whether the same attack method was used.
Some attacks have raised the possibility that artificial intelligence (AI) agents were used. The specific intrusion routes require further investigation by financial authorities and investigative agencies.
Regulators bring forward schedule, urgently convene entire financial sector
Financial authorities are also stepping up their response.
The Financial Services Commission will hold an emergency inspection meeting at the Government Complex Seoul on Oct. 4 afternoon, calling in heads of associations across all financial sectors including banks, financial investment, insurance, specialised credit finance, savings banks, mutual finance, virtual assets and fintech, as well as CEOs of financial companies where security incidents occurred. FSC Chairman Lee Eok-won (이억원) will chair the meeting, and Financial Supervisory Service Governor Lee Chan-jin (이찬진) will also attend.
The FSC had planned to conduct self-inspections by each financial company during the holiday period that runs through Oct. 5 and then receive reports on the results on Oct. 7. It brought the schedule forward after additional data leaks were confirmed at Yegaram Savings Bank and Hyundai Capital. Sectors where no damage has been confirmed yet, including insurance, financial investment, mutual finance, virtual assets and fintech, were also included in the inspection targets.
Earlier, on Oct. 2, the FSC also held an emergency response meeting with the Financial Supervisory Service, the Financial Security Institute, six banks and three card companies. It told financial companies to immediately inspect externally exposed computer systems and services overall, and called for checks on authentication and access control vulnerabilities, blocking unauthorised access, and sharing threat information such as attacking IP addresses.
Investigative authorities are also moving. The National Police Agency’s cyberterror response investigation unit began a preliminary investigation into data leak cases at Shinhan, KB Kookmin, Hana and BNK Busan Bank. Police are expected to examine intrusion routes, attack methods and links between the cases.
As repeated incidents occurred in individual systems with external touchpoints rather than core financial transaction networks, the scope of security inspections across the financial sector is expected to expand from an internet and mobile banking focus to overall query, business support and external linkage services.
In particular, investigation results on whether the attacks were by the same force and whether AI was actually used in the attack process are expected to become key variables in future overhauls of the financial sector’s security systems.