South Korean President Orders Full Security Checks After Financial Sector Hacks
South Korea's president ordered security checks after banks leaked tens of thousands of customers' personal records.
South Korean President Lee Jae Myung ordered a full investigation and sector-wide security checks after a series of confirmed data breaches at banks and other financial firms. Shinhan Bank said about 25,000 customers were affected, including names, phone numbers, income, loan limits, and some resident registration numbers. KB Kookmin Bank and Hana Bank reported leaks of 119 and 89 customer records through employee or operations support systems, separate from internet and mobile banking. Yegaram Savings Bank reported about 40,000 customers affected, Hyundai Capital exposed data on 146 housing-loan agents, and BNK Busan Bank reported 11 outsourced workers. Police and financial authorities are investigating; reports of an AI automation tool and shared IP addresses remain unconfirmed as a single campaign.
- President Lee Jae Myung ordered a full investigation and security measures on October 4, 2026.
- Shinhan Bank reported about 25,000 customers affected, including some resident registration numbers.
- KB Kookmin and Hana reported leaks of 119 and 89 customer records via internal support systems.
- Yegaram Savings Bank reported about 40,000 customers affected; Hyundai Capital exposed 146 agents' data.
- Investigators have not confirmed a single actor, malware family, or that AI completed the attacks.
Full article588 words · extracted from cybersecuritynews.com · click to collapse
South Korean President Lee Jae Myung ordered a thorough investigation on October 4, 2026, after a series of financial sector data breaches exposed customer and worker information. The order comes as investigators examine whether AI tools helped attackers break into systems used by banks and other financial firms.
According to The Korea Times, Lee received a briefing on recent breaches at financial and public institutions and the steps taken in response. Presidential spokesperson Kang Yu-jung said the president ordered officials to investigate fully and develop measures with “a grave awareness of the seriousness of the matter.”
Bank Breaches Spread Across Institutions
Shinhan Bank reported a breach on October 1 affecting about 25,000 customers. Exposed information included names, phone numbers, annual income, and loan limits. Some resident registration numbers were also leaked, adding sensitive identity data to information collected during the loan application process.
KB Kookmin Bank and Hana Bank disclosed further breaches on October 2. KB reported that personal and credit information belonging to 119 customers had leaked through a mobile work-support system used by employees. Hana said attackers gained abnormal access to its operations support system, exposing information belonging to 89 customers.
Hana’s leaked records included names, resident registration numbers, addresses, email addresses, phone numbers and employer details. BNK Busan Bank separately reported the exposure of information belonging to 11 outsourced workers. These figures describe different affected groups, rather than one confirmed pool of bank customers.
The incidents also reached nonbank financial firms. Yegaram Savings Bank reported a personal information leak affecting about 40,000 customers, while Hyundai Capital said data belonging to 146 housing loan agents had been exposed. The widening scope has placed security checks across the financial sector under closer attention.
AI Involvement Remains Under Investigation
Reporting by Seoul Economic Daily said traces of an AI-based automation tool were found in the Shinhan incident. SBS also reported common IP addresses across attacks on several financial institutions.
However, investigators have not publicly established that one group carried out every breach or that AI independently completed each attack. The investigation will need to clarify both.
The distinction matters because evidence of an AI tool does not explain the full attack chain. Public reports have not identified a confirmed software flaw, malware family, or complete set of attack indicators. Describing these incidents as fully autonomous hacks would therefore go beyond the available evidence.
The reported entry points were loan-agent websites and employee support systems, not simply customer banking apps. The Korea Times reported that KB and Hana said their affected systems were separate from internet and mobile banking platforms, with no customer financial transaction information leaked in those incidents.
Police began examining the breaches on October 2. Financial authorities also ordered broad checks of computer systems at banks and card companies. The findings make supporting business systems an important focus: they can hold sensitive records even when the main customer banking platform is not affected.
Cybersecurity News previously covered the Korean Leaks campaign, which targeted South Korea’s financial sector through a compromised service provider. That separate case offers context, not evidence of a connection.
Its reporting on AI-driven phishing also shows why exposed personal details deserve attention: convincing messages can turn a data leak into another opportunity to target affected people with carefully tailored scams.
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.