[비즈한국] Cyber hacking attacks have spread beyond major commercial banks to savings banks and capital firms, putting the entire financial sector on high alert. Personal data breaches have occurred in succession at KB Kookmin, Shinhan, and Hana Bank, as well as Yegaram Savings Bank and Hyundai Capital, with some financial firms identified as having been targeted by attacks utilizing artificial intelligence (AI) agents. As attacks targeting financial institutions occurred simultaneously over a short period, financial authorities held an emergency meeting with the entire financial industry to initiate emergency response measures.

The first news of a personal data breach surfaced at Shinhan Bank. A hacking incident between September 29 and 30 resulted in the leak of personal information belonging to approximately 25,000 customers. The target was Shinhan Bank's inquiry service exclusively for loan agents. The leaked information included credit data related to loan applications such as names, phone numbers, annual income, and calculated limits, as well as sensitive information including resident registration numbers (66 cases) and connected information (CI; 97 cases).
Following the report of the incident, Shinhan Bank launched an apology notice and a data breach inquiry menu on its website and its internal app "Super SOL" on the 1st. Immediately after the incident, the bank formed an emergency task force and took measures to prevent further damage, such as blocking external IPs, suspending related services, and applying new security policies. It is also working on improving business processes and security policies, and strengthening employee training. Shinhan Bank stated that it would provide full compensation if any financial damage occurs due to this data breach.
At KB Kookmin Bank, an external attack on the night of September 30 resulted in the leak of personal credit information of 119 customers. The target of the hacking attack was the mobile work support system for employees, and the leaked information included customer names, phone numbers, addresses, and encrypted resident registration numbers.
KB Kookmin Bank also plans to provide full compensation in the event of damages resulting from the data breach. The bank explained that it had individually notified affected customers of the breach and provided guidance on how to prevent secondary damage. KB Kookmin Bank stated, "We have blocked the compromised server and access routes to prevent follow-up damage," adding, "We have activated an enterprise-wide emergency response system to prevent further damage and recurrences."
Hana Bank also experienced a data breach due to hacking. An external attacker infiltrated the bank's operational support system (ODS), leaking personal information of 89 customers, including names, resident registration numbers, addresses, workplace names, emails, and phone numbers. On the 2nd, Hana Bank notified the affected customers individually and stated that it would provide full compensation if additional damage occurs.
Among regional banks, BNK Busan Bank also reported a hacking incident. Busan Bank stated that it faced an attempted external web server attack using an AI agent around 9 p.m. on the 1st. While the main attack was blocked, a follow-up inspection revealed that the personal information of 11 outsourced development staff was leaked through some web pages. The leaked information included names, phone numbers, dates of birth, and emails, and did not include bank customer information.
Busan Bank explained that it blocked the web pages where the information was exposed to restrict external access and strengthened monitoring of AI-based attacks to prevent similar cases. In addition, it is conducting additional inspections using Attack Surface Management (ASM—a method of discovering and analyzing vulnerabilities from a hacker's perspective) on its externally facing web pages.
It is reported that while there were hacking attempts against Woori Bank and NH NongHyup Bank, they were blocked by internal security systems and no data breaches were confirmed.

As major banks have faced hacking attacks and resulting data breaches around the same time, concerns regarding financial security are mounting. In the case of some banks, it is estimated that they were targeted by hacking attacks using AI agents to identify security vulnerabilities, drawing attention to the importance of strengthening cybersecurity related to AI.
The secondary financial sector was also a target of hacking attacks. Yegaram Savings Bank experienced a massive leak of information involving approximately 40,000 people. On the 2nd, through a "Notice and Apology Regarding Personal Data Breach" issued in the name of CEO Moon Yoon-seok, Yegaram Savings Bank stated that some information was leaked on September 30 when a hacker accessed a server containing customer personal data. The hacked information included customer names, dates of birth, and contact information.
Yegaram Savings Bank implemented emergency measures, including suspending related services and blocking external IPs, and is operating a customer service center for damage relief. The bank advised customers that if damages occur due to the data breach, they may claim damages under the Personal Information Protection Act or apply for mediation through the Personal Information Dispute Mediation Committee. It is reported that Yegaram Savings Bank was attacked through a vulnerability in an external solution program.
At Hyundai Capital, a home loan agent inquiry page was attacked on the 2nd via an overseas IP. As a result, the personal information of 146 agents (names, phone numbers, emails, resident registration numbers, and agent numbers) was leaked. Hyundai Capital reported the incident to financial authorities and the Korea Internet & Security Agency (KISA) and launched a dedicated response team.
With the ongoing hacking and data breach incidents targeting financial firms, financial authorities have also embarked on emergency inspections. On the 2nd, the Financial Services Commission held an emergency situation response meeting with the Financial Supervisory Service, the Financial Security Institute, major commercial banks, credit card companies, the Korea Federation of Banks, and the Credit Finance Association to share information on breach cases, attack types, and methods, and to discuss response directions.
On the afternoon of the 4th, a meeting will be held gathering associations from the entire financial sector—including banking, financial investment, insurance, credit finance, savings banks, mutual finance, fintech, and virtual assets—as well as representatives of the financial firms where incidents occurred. Financial Services Commission Chairman Lee Bok-hyun is expected to attend to receive reports on the current status of the incidents and discuss additional measures.