South Korea’s President Orders Probe Into Bank Data Breaches

President Lee Jae Myung ordered an investigation after breaches at Shinhan, KB Kookmin, Hana, Woori, and Yegaram Savings Bank exposed over 60,000 records.
Table of Contents
    Add a header to begin generating the table of contents

    South Korean President Lee Jae Myung ordered a full investigation and response measures on October 4 after a cluster of cyberattacks hit the country’s banks, finance companies, and public agencies, exposing more than 60,000 customer records.

    The order followed a string of breach disclosures at Shinhan Bank, KB Kookmin Bank, Hana Bank, Woori Bank, and Yegaram Savings Bank reported between September 30 and October 2.

    Yegaram Savings Bank Breach Exposed 40,000 Customers

    The largest single breach in the cluster hit Yegaram Savings Bank, which lost names, birth dates, and contact details belonging to roughly 40,000 customers in an incident reported October 2. Hana Bank and KB Kookmin Bank each disclosed smaller breaches affecting 89 and 119 customers, respectively — losses that, combined with Yegaram’s, pushed the confirmed sector-wide total past 60,000 affected individuals.

    Shinhan Bank and Woori Bank were also named among the institutions hit, though the research underlying this report does not specify individual record counts for those two banks beyond their inclusion in the broader wave.

    Attack Traffic Traced to Five Countries, Scanning Pattern Suspected

    Investigators traced the attack traffic behind the breaches to IP addresses located in the United States, Japan, Singapore, Vietnam, and Britain. Based on that pattern, investigators believe the activity represented a broad scan across multiple financial institutions rather than a campaign targeting any single bank.

    The Financial Services Commission chairman said authorities “could not rule out the possibility that artificial intelligence was used in the attacks” and called for financial institutions to adopt an “AI attacks defended by AI” approach to future defense.

    Financial Services Commission Convenes Emergency Industry Meeting

    The Financial Services Commission’s chairman convened an emergency meeting bringing together industry associations, regulators, and executives from the affected institutions following President Lee’s order. The FSC has directed financial institutions to carry out comprehensive security inspections, tighten access controls, minimize external system access, strengthen consumer protection measures, and begin sector-wide threat information sharing.

    Why a Presidential Order Signals Heightened Regulatory Pressure

    A direct order from the president, rather than action confined to the financial regulator alone, signals that the breach cluster is being treated as a national security and public-confidence issue rather than a routine compliance matter for individual banks. South Korea’s financial sector has faced scrutiny over cybersecurity practices in the past, and a presidential directive carries weight that can accelerate regulatory timelines and compel faster compliance than a standard FSC advisory.

    The scale of the response — a presidential order, an emergency industry-wide meeting, and new mandates covering access controls and information sharing — reflects how a relatively modest per-institution record count (89 customers here, 119 there) can still trigger a sector-wide response when the pattern suggests coordinated scanning across multiple major banks simultaneously. Financial regulators globally have increasingly treated cross-institutional attack patterns as a systemic risk signal distinct from isolated single-company breaches, since a scanning campaign hitting five or more major banks in the same window suggests shared vulnerabilities or a common attacker toolset rather than unrelated incidents.

    FSC Has Not Disclosed the Full Scope of the Bank Cluster

    The FSC and affected institutions have not yet disclosed the full scope of the breach cluster, and the 60,000-plus confirmed total may grow as the investigation continues across the named institutions. Authorities have not attributed the campaign to a specific threat actor or confirmed whether the five countries where attack traffic originated reflect the attackers’ true location or compromised infrastructure used to route traffic.

    The FSC chairman’s comments about possible AI involvement in the attacks, while not confirmed, point to a regulatory posture that is beginning to treat AI-enabled attack techniques as a planning assumption for financial-sector defense rather than a hypothetical future concern. That framing — defending against AI-assisted attacks with AI-assisted detection — marks one of the more concrete examples of a national financial regulator publicly tying its defensive strategy to the AI threat landscape rather than treating it as a background risk factor addressed only in long-term policy papers.

    For the banks named in the breach cluster, the immediate consequence is the FSC’s new mandate to complete comprehensive security inspections and tighten external system access, a process that will likely extend well beyond the presidential order as investigators work to confirm the full extent of compromised data and whether additional institutions beyond the five already named were affected by the same scanning activity.

    Related Posts