
Personal information leakage incidents caused by hacking are occurring simultaneously across the banking sector. Following consecutive external hacking attacks that resulted in customer data leaks at Shinhan Bank, KB Kookmin Bank and Hana Bank, personal information of 11 outsourced employees was leaked at BNK Busan Bank. Woori Bank and NH NongHyup Bank also received external hacking attacks, but it has been confirmed that no customer information was leaked.
According to financial industry sources on the 2nd, Hana Bank reported to the Financial Supervisory Service on the same day that an information leakage incident had occurred due to an external hack. After news emerged the previous day (the 1st) that a data leak affecting 25,000 individuals had occurred at Shinhan Bank, Hana Bank immediately launched inspections and identified hacking attempts and information leakage during the process.
According to Hana Bank’s internal investigation, an external hacking agent attempted abnormal access to the internal sales support system (ODS) used by internal employees, resulting in the leakage of customer information for a total of 89 individuals. The leaked information includes resident registration numbers, names, addresses, email addresses, phone numbers, mobile numbers and workplace names.
After detecting signs of intrusion, Hana Bank convened an emergency response task force and incident response team composed of its ICT Group, Financial Consumer Protection Department and other units. It also took measures such as urgently blocking and inspecting the IP address that attempted the attack and similar systems. In addition, it is individually notifying affected customers in accordance with relevant regulations and procedures. If actual damage occurs due to the information leakage, the bank plans to provide full compensation in accordance with relevant regulations.
Hana Bank stated, “We are taking this incident very seriously,” adding, “We will make every effort to thoroughly identify the cause and establish measures to prevent recurrence in close cooperation with relevant institutional investors.”
Busan Bank also announced that it identified an external web server attack attempt using an AI agent at 9 p.m. on the same day, but determined that major attacks were blocked. It further revealed that during subsequent inspections, signs of exposure of personal information for 11 outsourced development employees were confirmed through some web pages with insufficient session verification, and it immediately blocked those pages.
Busan Bank is continuing monitoring to check for any additional abnormal signs. The targets identified so far are 11 outsourced development employees, and the related information includes names and phone numbers. The web page where this information was displayed has been fully blocked, restricting external access.
To prevent similar incidents, the bank plans to strengthen monitoring of AI-based attacks and conduct additional inspections using an attack surface management (ASM) approach targeting all publicly accessible web pages.
Woori Bank and NongHyup Bank also announced that multiple hacking attempts occurred during a similar period, but no information leakage took place.
Previously, at Shinhan Bank on the 30th of last month, a dedicated mobile homepage called “M Shinhan,” used by loan solicitors to check customers’ loan status, was breached, resulting in the leakage of personal information and loan-related data for a total of 25,000 individuals. At Kookmin Bank, on the 30th of last month, an employee mobile business support system was hit by an external attack, causing the leakage of information including the names, phone numbers, addresses and encrypted resident registration numbers of 119 customers.
The security industry is also paying attention to the possibility that AI agents were utilized in a series of recent attacks targeting the financial sector. When AI agents are used, they automate “credential stuffing” attacks, which involve attempting logins by mass-inputting personal information obtained externally. However, further investigation is needed regarding the specific attack methods and the identity of the attacking organization.