[비즈한국] The fallout from Lotte Card's personal data breach continues to grow. Although Lotte Card emphasizes that there have been no confirmed cases of actual damages, concerns regarding financial loss persist as it has been revealed that a significant amount of data was leaked externally. With this incident turning eyes toward the information security management and investment scales across the entire financial sector, we have examined the status of information security through the voluntary disclosures made by financial firms.

Interest in information security investment is rising due to the leakage of customers' personal information at Lotte Card. This follows criticism that the private equity firm MBK Partners may have reduced its share of information security investment to focus on profitability after acquiring the credit card company.
According to the office of Representative Kang Min-kuk of the People Power Party, Lotte Card's information security budget relative to its 2025 IT budget was 9%, a 5.2 percentage point drop over five years from 14.2% in 2020. However, MBK Partners countered by stating, "That figure is based solely on IT infrastructure; Lotte Card is investing in both IT infrastructure and personnel simultaneously."
The status of information security investment by domestic companies can be verified through 'Information Security Disclosures.' Companies disclose their information security investment amounts and the status of dedicated personnel. Since 2022, companies meeting certain criteria in terms of business sector, revenue, and number of service users have been obligated to disclose this information. This year, 666 companies were designated as mandatory disclosers. However, public institutions, small businesses, financial firms, and electronic financial business operators are exempt from this requirement.
Some financial firms voluntarily disclose their status despite having no such obligation. Looking at the financial firms that voluntarily disclosed data over the past three years (2023–2025), only Kookmin Bank, Woori Bank, and Shinhan Bank (participating since 2024) among the five major commercial banks (KB Kookmin, NH Nonghyup, Shinhan, Woori, and Hana) have disclosed their information security status. Woori Bank has been voluntarily disclosing since 2020, while Hana Bank and Nonghyup Bank have never disclosed this information.
This year, among the banking sector, △Kookmin Bank, △Shinhan Bank, △Woori Bank, △Jeju Bank006220, and △Toss Bank disclosed their information security investment and personnel status. Among second-tier financial sector banks, only Welcome Savings Bank voluntarily disclosed. Bithumb and Dunamu (Upbit), which operate virtual asset exchanges, were included in the mandatory disclosure list as they belong to the information and communications sector. Additionally, some securities firms (SK, NH Investment & Securities, Daishin, Shinhan, Toss, and Korea Investment & Securities), electronic payment agencies (Toss Payments, Kakao Pay377300), and capital firms (Lotte Capital) also revealed their information security status.
Reviewing the information security status by sector, only two institutions in the first-tier financial sector had an information security investment ratio exceeding 10% of their 2024 (2025 disclosure) IT investment: Woori Bank (12.3%) and Jeju Bank (10.8%). They were followed by Toss Bank at 9.8%, Shinhan Bank at 8.6%, and Kookmin Bank at 7.5%. In particular, Woori Bank recorded 10.5% in both 2022 and 2023, maintaining a ratio above 10% for three consecutive years.
Woori Bank invested 44.4 billion KRW out of its 359.6 billion KRW IT investment into information security last year, ranking first in terms of the actual amount. It was followed by Kookmin Bank (42.5 billion KRW out of 567.3 billion KRW) and Shinhan Bank (37 billion KRW out of 428.8 billion KRW). Toss Bank invested 9.5 billion KRW out of 96.7 billion KRW, and Jeju Bank invested 3.8 billion KRW out of 35.1 billion KRW into information security.

Nonghyup Bank, which did not disclose, reported that its information security investment slightly decreased from 65.7 billion KRW in 2022 to 65.1 billion KRW in 2023, before expanding to 80.2 billion KRW in 2024. Hana Bank did not disclose figures related to its information security status. However, according to its 2024 Sustainable Management Report, the ratio of information security investment to IT budget for Hana Financial Group was 26%.
Welcome Savings Bank, a second-tier financial institution, was the only savings bank to voluntarily disclose its information security status starting in 2024, recording high figures with an information security investment ratio of 13.5% (2.2 billion out of 16.2 billion KRW) in 2023 and 15.0% (2.6 billion out of 17.5 billion KRW) in 2024.
Virtual asset exchanges are classified as information and communications services, and they are subject to mandatory disclosure if their average daily number of users (visitors) is 1 million or more. Dunamu, the operator of Upbit, saw its information security investment and ratio increase: 8.7 billion KRW (6.4%) in 2022, 9.2 billion KRW (9.4%) in 2023, and 14.8 billion KRW (9.6%) in 2024.
Notably, while its 2023 IT investment was 97.6 billion KRW, a 28.1% decrease from the previous year (135.7 billion KRW), its information security investment ratio increased. The number of personnel also grew. The number of dedicated information security staff (internal/outsourced) among IT personnel increased from 13.3 (5.2%) to 26.7 (7.9%) and then to 33.6 (9.0%).
Bithumb, designated as a mandatory discloser this year, showed a difference from its voluntary disclosure four years ago (2020 data). Bithumb set its 2024 information security investment at 9.2 billion KRW, accounting for 9.9% of its IT investment (92.5 billion KRW). Compared to its 2020 information security investment (4.7 billion KRW), the amount increased by about two times, but the ratio was halved (18.3% → 9.9%). However, during the same period, the number of dedicated information security personnel more than tripled from 10.1 (9.0%) to 31.9 (10.2%).
Meanwhile, the repercussions of the Lotte Card personal data breach have spread across the entire financial sector. On September 23, Kwon Dae-young, Vice Chairman of the Financial Services Commission, summoned about 180 Chief Information Security Officers (CISOs) from all financial sectors to hold an emergency meeting, ordering them to inspect and reinforce their security systems. Kwon emphasized that day, "Under the responsibility of the CEO, you must 'bet the company's fate' on thoroughly checking whether there are any security loopholes in your computer systems and information security frameworks," adding, "Please hurry to conduct a comprehensive inspection and establish an internal management system."