VibeTimes
#기술

Data Breach Hits 7 Financial Firms, Spreading to Savings Banks

모민철모민철 기자· 10/5/2026, 9:27:02 AM· Updated 10/5/2026, 9:27:02 AM

The customer data breach incident at financial companies has spread to savings banks and capital companies. According to financial authorities and the financial industry on the 5th, the affected financial companies number seven: Shinhan, KB Kookmin, Hana, and BNK Busan Bank, along with Hyundai Capital, Yeagaram Savings Bank, and Welcome Savings Bank. The scale of the damage varies by company. Shinhan Bank saw the personal information of 25,727 individuals leaked, while KB Kookmin Bank had the information of 119 customers exposed. Hana Bank lost customers' resident registration numbers, addresses, and contact details affecting 89 customers. BNK Busan Bank had only the information of 11 outsourced development staff exposed, with no customer data leaks confirmed. Yeagaram Savings Bank estimates that the names, birth dates, and contact details of roughly 40,000 people were leaked. Hyundai Capital had the information of 146 mortgage loan brokers leaked, while Welcome Savings Bank is investigating the scale of its corporate customer data breach.

The common thread in this incident is the attack vector. The breached points were not internet banking. Shinhan Bank's loan progress inquiry service used by loan brokers was targeted. KB Kookmin Bank's employee-facing mobile work support system, RM·PB Agent, was attacked, as was Hana Bank's operational data store (ODS), which is separate from its internet and mobile banking systems. BNK Busan Bank's employee-facing mobile sales support system was breached, and Hyundai Capital's mortgage broker inquiry page was compromised. In other words, the incidents were concentrated in systems connected externally for work convenience, rather than in customer-facing internet or mobile banking or core banking infrastructure.

This comes against the backdrop of expanding digital operations: as employees, loan brokers, and outsourced vendors use work sites, inquiry systems, application programming interfaces (APIs), and partner services, the number of touchpoints handling financial information outside core networks has grown.

An investigation into the attack methods is also under way. The attack on Shinhan Bank used IP addresses from multiple countries, including the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, and the United Kingdom, in addition to South Korea. Financial authorities believe that IP addresses belonging to the same attacker were identified at multiple financial companies and are investigating connections between the attackers and their methods. However, it has not yet been confirmed whether the attacks involved the same actor or the same techniques.

There had been advance warnings. Before the incident escalated, on the 17th of last month, the Financial Security Authority warned at a seminar attended by some 160 financial company security officers of the possibility of cyberattacks on the financial sector using AI agents, and urged stronger API management connecting systems and data. The Financial Services Commission also reported on the 3rd of last month that the possibility of AI being used for broad vulnerability scanning is growing, and moved to ease network separation regulations so that financial companies can use external high-performance AI and security services to check for vulnerabilities.

The financial security framework is shifting from the traditional network separation model, which divides external and internal networks, toward a zero trust approach that continuously verifies users, devices, and access paths, along with the adoption of AI-based security systems to detect AI-driven attacks. At an emergency meeting of the entire financial sector held at the Government Complex Seoul on the 4th, Financial Services Commission Chairman Lee Eok-won said that security blind spots had been identified in external web pages and servers used by loan brokers and employees, and called on financial companies to block unnecessary external access and minimize access rights and the scope of information available for viewing.

As identical or similar attacks occurred at multiple financial companies, sharing of attack IP addresses and vulnerability information among firms is also taking place. Financial authorities have instructed banks and card companies to complete their own security checks by the 6th, and securities firms, insurers, savings banks, and others by the 8th. Key inspection targets include publicly accessible web pages, work support systems, access rights, authentication procedures, and the scope of personal information storage.

Related Articles