[비즈한국] As hacking attacks targeting the financial sector continue, attention is turning to the current state of information security at financial firms. While amendments to the Enforcement Decree of the Information Security Industry Promotion Act are set to make it mandatory for financial firms to disclose their information security status starting in 2027, the number of financial firms participating in voluntary disclosure this year has increased. However, given that these firms still represent a minority of the industry, and considering that data breach incidents continue to occur even at financial institutions recognized as excellent in information security or those actively investing in security, doubts are being raised about the effectiveness of the system.

The Korea Internet & Security Agency (KISA) information security disclosure is a system that requires companies to reveal their investments, human resources, certifications, and user protection activities related to information security. Disclosure is currently mandatory for companies in specific business sectors, listed companies with revenue of 300 billion KRW or more, and companies with an average of 1 million or more daily users (based on the three months immediately preceding the end of the previous year). Under current law, public institutions, financial firms, electronic financial business operators, and small businesses are exempt.
However, with the Ministry of Science and ICT amending the Enforcement Decree of the Act on the Promotion of the Information Security Industry, financial firms will also be required to disclose their information security status starting in 2027. This is because the amendment deletes the provision that explicitly excluded public institutions, financial firms, electronic financial business operators, and small businesses. A Ministry official stated, “We are currently undergoing internal procedures to finalize the bill ahead of its promulgation so that the amendment can be enforced starting January 2027.”
Furthermore, the requirements for designating and reporting a Chief Information Security Officer (CISO) and the 300 billion KRW revenue threshold, which previously applied to listed corporations, will be removed to expand the mandatory disclosure target to all listed corporations. The criteria for calculating user numbers will change from the average of the three months preceding the end of the previous year to the average for the entire previous year, and companies required to obtain Information Security Management System (ISMS) certification will also be included in the mandate. However, considering the difficulties in establishing infrastructure, small businesses will be subject to the rules starting in 2029.
Although the number of financial firms opting for voluntary disclosure ahead of the 2027 mandate has increased, the level remains minimal when looking at the industry as a whole. According to the KISA information security disclosure portal, Viva Republica (Toss) was the first financial firm (excluding holding companies) to disclose its information security status in 2018. The number increased to 2 in 2019, 2 in 2020, 5 in 2021, 7 in 2022, 12 in 2023, 14 in 2024, and 16 in 2025. This year, the number of financial firms engaging in voluntary disclosure jumped to 26.
Among commercial banks, Hana Bank, IBK Industrial Bank of Korea, and KakaoBank disclosed their information security status for the first time this year. NH Nonghyup Bank, Korea Development Bank, K-Bank, iM Bank, Jeonbuk Bank, Kwangju Bank, Kyongnam Bank, and foreign-owned banks have never disclosed their status. Among regional banks, Jeju Bank has been disclosing since 2023, and Busan Bank participated once in 2019.
In the insurance industry, no company has voluntarily disclosed its information security status. Among credit card companies, Lotte Card was the only one to disclose this year, and among capital firms, only Lotte Capital has participated since 2023. In the savings bank industry, only Welcome Savings Bank had disclosed since 2024, but Shinhan Savings Bank joined this year.
The number of companies disclosing information security status in the securities industry has also increased. In 2025, there were only six: NH, SK, Daishin, Shinhan, Toss, and Korea Investment & Securities, but this year it grew to ten with the participation of KB, Yuanta, Hana, and Hyundai Motor Securities. However, considering there are over 60 securities firms in total, this is still far from sufficient.
Virtual asset exchanges are classified as information and communications businesses, not financial businesses. Among the five domestic won-based exchanges (Upbit, Bithumb, DigitalX, Coinone, Gopax), the notable entity is Streami, the operator of Gopax, which has continuously disclosed its information security status since 2018 even though it was not required. Among the five exchanges, those with a disclosure mandate are Dunamu (Upbit) and Bithumb, while Coinone and DigitalX (formerly Korbit) have never disclosed their information security status.

Although the number of companies subject to mandatory information security disclosure will increase significantly starting next year, doubts remain regarding the effectiveness of the system. This amendment to the Enforcement Decree of the Information Security Industry Promotion Act is one of the measures from the “Pan-government Information Security Comprehensive Countermeasures” announced by the government in October 2025. It was introduced to strengthen the security capabilities of private enterprises following large-scale incidents last year, such as the SKT USIM hacking and the Lotte Card data breach.
However, experts point out that a more effective system is needed as hacking techniques become more sophisticated through the use of artificial intelligence (AI). Shinhan Bank, which recently had the information of approximately 25,000 customers leaked, was unable to stop a hacking attack targeting its loan solicitor inquiry system. External attackers reportedly bypassed identity verification procedures and extracted personal information by repeatedly entering values required for information retrieval.
Shinhan Bank has a history of being selected as an excellent company for information security disclosure in 2025 and receiving a Minister of Science and ICT award. This is an award given annually to companies that maintain high levels of information security or perform disclosures faithfully. Despite receiving top grades for six consecutive years in the Financial Services Commission’s regular assessment of personal information utilization and management, as well as top grades in the comprehensive assessment of major information and communication infrastructure, Shinhan Bank was unable to prevent this accident.
It is also difficult to judge security levels solely by the scale of information security investment. Among the four major commercial banks (KB Kookmin, Shinhan, Hana, and Woori) that disclosed their information security status in 2026, Kookmin Bank recorded the largest investment amount as of the end of 2025 at 43.3 billion KRW, followed by Hana Bank (37.2 billion KRW), Shinhan Bank (36.9 billion KRW), and Woori Bank (36.4 billion KRW). However, among them, only Woori Bank has not been identified as having suffered a data breach in recent consecutive hacking attacks.
As of the end of 2025, Welcome Savings Bank’s investment in information security was 3.7 billion KRW. While the amount is smaller compared to commercial banks, the proportion of information security investment relative to information technology investment reached 15.8%. Considering that none of the four major banks mentioned above exceeded 10% (Kookmin 8.2%, Shinhan 7.5%, Hana 9.0%, Woori 9.1%), this is a high figure. However, even Welcome Savings Bank failed to detect a hacking attack on September 27 with its security system and only realized the attack occurred during its own internal inspection process on October 2. This incident resulted in the leakage of 2,299 corporate customer records, including duplicate values.
Consequently, critics argue that evaluations should be based on practical operational levels and records of regular checks, rather than just numeric-centered disclosures. Such opinions were also raised at the public hearing for the Information Security Industry Promotion Act Enforcement Decree held by the Ministry of Science and ICT and KISA last February. A fintech industry official stated, “Hacking attacks on the financial sector occur every day,” adding, “Because attack techniques are constantly evolving and the defense is a reactive process, it is important to monitor the sustainability of security activities.”