
Personal information infringement incidents are spreading across the banking sector one after another. While customer information was leaked through consecutive external hacking attacks at Shinhan Bank and KB Kookmin Bank, personal information was also leaked from Hana Bank and BNK Busan Bank. These banks are also believed to have been infiltrated by external hacking agents.
According to financial industry sources on the 2nd, Hana Bank reported to the Financial Supervisory Service that day that an information leak incident had occurred due to an external hack. After it was revealed on the 1st that a data breach affecting 25,000 individuals had occurred at Shinhan Bank, Hana Bank immediately launched an inspection and identified evidence of hacking attempts and information leakage during the process.
According to Hana Bank’s internal investigation, an external hacking agent attempted abnormal access to the internal sales support system (ODS) used by internal employees, resulting in the leakage of customer information for a total of 89 individuals. The leaked information includes resident registration numbers, names, addresses, email addresses, phone numbers, mobile phone numbers, and workplace names.
After detecting signs of infringement, Hana Bank convened an emergency response task force and incident response team composed of the ICT Group, the Financial Consumer Protection Department, and other units. The bank also took measures such as urgently blocking and inspecting the IP addresses attempting the attack and similar systems. In addition, it is currently notifying affected customers individually in accordance with relevant regulations and procedures. If actual damage occurs due to the information leak, Hana Bank plans to provide full compensation in accordance with relevant regulations.
Hana Bank stated, “We are taking this incident very seriously,” adding, “We will do our utmost to thoroughly identify the cause and establish measures to prevent recurrence, in close cooperation with relevant institutional investors.”
Busan Bank also detected on the same day that its internal sales support system had been attacked, resulting in the leakage of personal information for 11 outsourced development employees, and reported this to the Financial Supervisory Service. Busan Bank has currently blocked its web page and notified the outsourced development company and related employees of the situation. The bank is strengthening continuous monitoring against similar attacks.
Hacking attacks targeting banks are occurring in succession. At Shinhan Bank, a dedicated mobile homepage called “M-Shinhan,” used by loan recruiters to check customers’ loan status, was infiltrated, leading to the leakage of personal information and loan-related data for a total of 25,000 individuals. At Kookmin Bank, on the 30th of last month, an employee mobile business support system was subjected to an external attack, causing the leakage of information including customer names, phone numbers, addresses, and encrypted resident registration numbers for 119 customers.
The security industry is also paying attention to the possibility that AI agents were utilized in the series of recent attacks targeting the financial sector. When AI agents are used, they automate “credential stuffing” attacks, which involve attempting logins by mass-inputting personal information obtained from external sources. However, further investigation is needed regarding the specific attack methods and the identity of the attacking organization.