South Korea’s financial sector is facing a broader personal data breach that has now spread to seven financial companies. Since the case was disclosed on Oct. 1, the number of confirmed affected firms had reached seven by Oct. 6: Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital.
Among the major banks, Shinhan Bank reported the largest breach, with about 25,000 people affected. KB Kookmin Bank reported 119 affected individuals, while Hana Bank reported 89.
Breaches hit externally exposed inquiry and support systems
The attacks were concentrated on externally accessible inquiry and business support systems. At Shinhan Bank, the compromised system was a simplified inquiry website used by loan brokers. At KB Kookmin Bank, the affected system was a mobile business support platform used by employees. Hana Bank said its sales support system, or ODS, was targeted.
Reports said core transaction systems, including internet banking and mobile banking, were not breached.
Authorities say three banks saw nearly identical attack IPs
According to South Korean media reports relaying a Herald Business editorial, the Korea Financial Security Institute said the IP addresses used in attacks on Shinhan Bank, KB Kookmin Bank and Hana Bank were nearly identical. The institute also found traces showing the use of an AI hacking tool developed in China and based on the Chinese language.
South Korea’s Financial Supervisory Service said on Oct. 6 that the attack attempts involved 33 IP addresses, or 28 after duplicates were removed. The regulator added that the attackers may have routed traffic through IPs in multiple countries to avoid tracking, making it difficult to determine the attackers’ actual location based only on IP geography.
Two developments on Oct. 6
There were two new developments on Oct. 6. First, the Financial Supervisory Service upgraded its investigation into Shinhan Bank to a formal on-site inspection. Second, Prime Minister Han Seong-sook ordered government agencies and public institutions to immediately clean up websites that are no longer operating or have been left unmanaged.
Shinhan breach crossed South Korea’s 10,000-person legal threshold
Shinhan Bank reported the loan-related personal data leak to the Financial Supervisory Service on Sept. 30 and disclosed it publicly on Oct. 1. The bank said it would fully compensate customers for losses resulting from the incident. Financial authorities held an emergency meeting on Oct. 2 and instructed banks and card companies to inspect their cybersecurity posture and report back.
According to Newsis, external actors entered some of Shinhan’s loan-related services by using an abnormal method that bypassed authentication. The leaked data included customer names, phone numbers, annual income and estimated loan limits. For some customers, resident registration numbers, which are comparable to national ID numbers, and CI, or connection information, were also exposed.
There are concerns that the data could be used to impersonate loan consultations and become a basis for secondary crimes such as voice phishing.
Under South Korea’s Personal Information Protection Act, a leak affecting 10,000 people is a key threshold. Once that level is exceeded, the response burden on regulators and the obligations imposed on financial companies increase sharply. Shinhan crossed that threshold, while the other major banks were around the 100-person level.
Emergency inspections spread across the financial sector
The Herald Business editorial said insurers, securities firms and internet-only banks also found traces of external access attempts, pushing the broader financial sector into emergency inspections. The editorial also said Shinhan Bank, KB Kookmin Bank and Hana Bank had spent more than KRW 123.9 billion on cybersecurity over the past year, yet the latest incident still exposed gaps in protection.
Woori and NH NongHyup have not confirmed leaks
Woori Bank and NH NongHyup Bank have not confirmed any data leaks so far. According to Bizwatch, Woori requires loan broker operations to be handled only on designated tablet devices and only after certificate-based and biometric authentication. The bank also uses two-step authentication and AI-based vulnerability checks, with tools including Xint Web from security firm Theori and in-house tools.
NH NongHyup operates external attack surface management, or ASM, to continuously identify externally exposed websites and apps and manage vulnerabilities. Abnormal external behavior is blocked in real time, and access to important systems requires secondary authentication such as one-time passwords, or OTPs. NongHyup also said allowing loan brokers to separately query customer data carries cybersecurity risk, so related work is handled mainly by internal staff.
Park Sang-won, head of the Korea Financial Security Institute, said one key difference between organizations that were breached and those that were not was whether multi-factor authentication, or MFA, had been deployed. Financial authorities also said whether vulnerabilities in external-facing systems had been patched in advance affected whether intrusions succeeded.
Internet-only banks also saw probing from the same IP group
According to Sisa Journal, the same batch of IPs also probed three internet-only banks. KakaoBank detected repeated access attempts from some of the attack IPs starting in January this year. K Bank also confirmed attempts from the same IPs. Toss Bank said it saw more than 10 access attempts between January and August this year. All three detected and blocked the activity, and none reported personal data leaks.
The publication quoted a financial industry source as saying attackers usually begin by probing a large number of unspecified institutions for weaknesses. If they find a vulnerability or are not blocked, they continue the attack.
On-site inspection to focus on scale, intrusion path and compliance
After receiving Shinhan’s report on Sept. 30, the Financial Supervisory Service first carried out an on-site check to establish the facts and trace the intrusion path. Newsis reported that the regulator upgraded the process to a formal on-site inspection starting Oct. 6, six days after the initial report. The inspection will focus on the exact scale of the leak, the intrusion route and whether Shinhan violated any laws.
Newsis said loan brokers are external personnel, yet they were able to access sensitive credit information such as annual income and estimated loan limits through Shinhan’s system. That has led to questions over whether Shinhan granted overly broad access permissions and failed to manage them properly.
Prime Minister orders cleanup of dormant websites
At a ministerial meeting on personal data leaks involving financial and public institutions on Oct. 6, Prime Minister Han Seong-sook gave an emergency instruction: 「Please immediately organize and clean up websites of government and public institutions that are not operating or have been left unattended.」 Han previously served as chief executive of Naver.
Newsis said the order was seen as a first step in responding to AI-driven automated hacking.
Experts said unused websites can become targets for automated AI hacking programs, part of what is often called shadow IT. Shadow IT refers to IT assets that are outside an organization’s formal security framework or assets that are no longer being managed. Common examples include websites with unclear ownership, APIs left behind by past projects and servers connected to partner companies.
South Korea currently has about 10,000 public websites and about 1,200 mobile apps operated by central government agencies, local governments and public institutions.

