Hacking attacks utilizing artificial intelligence (AI) agents have spread beyond the five major banks to savings banks, capital companies, and mutual finance institutions across the financial sector, according to recent disclosures. Attackers did not target specific financial institutions but instead scanned external systems of multiple financial firms extensively, infiltrating those with relatively weaker security. On October 4, financial authorities urgently convened the entire financial sector to assess damage and review response systems.
According to financial authorities and institutions, Yegaram Savings Bank confirmed on September 30 that approximately 40,000 customers’ personal information, including names, birthdates, and contact details, was leaked due to a hacking incident.
Hyundai Capital also suffered a hacking attack on September 27, resulting in the exposure of information belonging to 146 housing loan agents. The Korean Federation of Community Credit Cooperatives and Nonghyup Mutual Finance detected similar or identical internet protocol (IP) addresses used in prior attacks on banks.
Earlier, the five major banks—KB Kookmin, Shinhan, Hana, Woori, and NH Nonghyup—along with BNK Busan Bank, reported consecutive hacking attempts. At Shinhan Bank, 25,729 customers’ names, mobile phone numbers, loan applications, and applied interest rates were leaked. KB Kookmin Bank saw 119 customers’ names, phone numbers, addresses, and encrypted resident registration numbers exposed, while Hana Bank had 89 customers’ resident registration numbers, names, and workplace details compromised.
As attack traces emerged in savings banks, capital companies, and mutual finance, financial authorities escalated their response. They urgently summoned representatives from all financial sectors on October 4 to review damage and security measures. Lee Eog-weon, Chairperson of the Financial Services Commission, and Lee Chan-jin, Governor of the Financial Supervisory Service, attended. The meeting, originally scheduled for October 7, was moved up by three days due to additional damages identified over the weekend.
Authorities shared attacker IP addresses and methods identified in prior bank attacks with the entire financial sector. They instructed a full inspection over the weekend, during which additional damages at Yegaram Savings Bank and Hyundai Capital were confirmed.
The scope of attacks remains unclear, as multiple IPs were used, with some targeting multiple financial institutions. Authorities are investigating potential undisclosed attacks or data leaks.
No secondary financial damages, such as monetary losses from misused personal information, have been confirmed. However, authorities will monitor whether the leaked data is exploited for voice phishing or financial fraud. Compensation plans for affected financial institutions are also under review.
Notably, attacks focused on peripheral systems used by loan agents and external sales staff rather than core financial transaction networks like internet or mobile banking. Authorities plan to require financial institutions to strengthen authentication and security protocols, particularly for these vulnerable points.






Leave a comment