CyberSecurityNews

South Korean President Orders Full Security Checks After Financial Sector Hacks


South Korean President Lee Jae Myung ordered a thorough investigation on October 4, 2026, after a series of financial sector data breaches exposed customer and worker information. The order comes as investigators examine whether AI tools helped attackers break into systems used by banks and other financial firms.

According to The Korea Times, Lee received a briefing on recent breaches at financial and public institutions and the steps taken in response. Presidential spokesperson Kang Yu-jung said the president ordered officials to investigate fully and develop measures with “a grave awareness of the seriousness of the matter.”

Bank Breaches Spread Across Institutions

Shinhan Bank reported a breach on October 1 affecting about 25,000 customers. Exposed information included names, phone numbers, annual income, and loan limits. Some resident registration numbers were also leaked, adding sensitive identity data to information collected during the loan application process.

KB Kookmin Bank and Hana Bank disclosed further breaches on October 2. KB reported that personal and credit information belonging to 119 customers had leaked through a mobile work-support system used by employees. Hana said attackers gained abnormal access to its operations support system, exposing information belonging to 89 customers.

Hana’s leaked records included names, resident registration numbers, addresses, email addresses, phone numbers and employer details. BNK Busan Bank separately reported the exposure of information belonging to 11 outsourced workers. These figures describe different affected groups, rather than one confirmed pool of bank customers.

The incidents also reached nonbank financial firms. Yegaram Savings Bank reported a personal information leak affecting about 40,000 customers, while Hyundai Capital said data belonging to 146 housing loan agents had been exposed. The widening scope has placed security checks across the financial sector under closer attention.

AI Involvement Remains Under Investigation

Reporting by Seoul Economic Daily said traces of an AI-based automation tool were found in the Shinhan incident. SBS also reported common IP addresses across attacks on several financial institutions.

However, investigators have not publicly established that one group carried out every breach or that AI independently completed each attack. The investigation will need to clarify both.

The distinction matters because evidence of an AI tool does not explain the full attack chain. Public reports have not identified a confirmed software flaw, malware family, or complete set of attack indicators. Describing these incidents as fully autonomous hacks would therefore go beyond the available evidence.

The reported entry points were loan-agent websites and employee support systems, not simply customer banking apps. The Korea Times reported that KB and Hana said their affected systems were separate from internet and mobile banking platforms, with no customer financial transaction information leaked in those incidents.

Police began examining the breaches on October 2. Financial authorities also ordered broad checks of computer systems at banks and card companies. The findings make supporting business systems an important focus: they can hold sensitive records even when the main customer banking platform is not affected.

Cybersecurity News previously covered the Korean Leaks campaign, which targeted South Korea’s financial sector through a compromised service provider. That separate case offers context, not evidence of a connection.

Its reporting on AI-driven phishing also shows why exposed personal details deserve attention: convincing messages can turn a data leak into another opportunity to target affected people with carefully tailored scams.



Source link