Invest1 publisher2 min readPublished
Korean financial firms must shut outside access to the staff and broker pages hackers used
South Korea's Financial Services Commission will block outside access to staff and loan-broker web pages by default after leaks at six firms. Every page a firm keeps reachable now has to be justified as indispensable to services or work.
The Investor · Invest desk

What happened
- After Shinhan Bank, leaks were reported at KB Kookmin, Hana and BNK Busan banks, then at Hyundai Capital and Yegaram Savings Bank.
- Most attacks went through external pages and servers used by loan brokers and employees, areas the commission said receive relatively less oversight.
- Every financial firm must inventory its externally exposed IT systems, review authentication, access controls and intrusion detection, and report the results to regulators.
- Attacking IP addresses, methods and records of intrusion attempts from the incidents will be shared quickly, with closer cooperation among government agencies.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- cost Loan brokers and employees lose the remote work pages they used for convenience at any firm that cannot show the access is needed, so the workflows built on those pages have to change.
- cost Mutual finance institutions, insurers, securities companies and fintechs with no reported breach pay for the same asset inventory and access review as the six firms that were hit.
- exposure The commission's written finding that basic security measures were inadequate stays on the record if supervisors later move against any of the six firms.
Regulators plan to check the exceptions themselves. They say they will identify and review every external contact point and system access route employees use for work, whether or not it serves customers [11]. Where outside access survives, access rights and the information staff can view are cut to the minimum [7]. That limit targets the commission's finding that firms stored and accessed more information than their work required [5].
The commission moved quickly. Four days separated the first attack, at Shinhan Bank on Sept. 30, from the emergency meeting Chairman Lee Eok-won chaired on Oct. 4 [1][10][1]. Financial Supervisory Service governor Lee Chan-jin and Financial Security Institute head Park Sang-won attended, along with executives of major firms and industry association chiefs [10]. Four of the six firms with reported leaks are banks [2].
If supervisors take a broad view of what the commission's rule counts as indispensable to work, firms will certify most broker and staff pages as necessary, and the bill is mostly the inventory and the report [7][6]. If they read it narrowly, loan brokers lose the remote pages they worked through, and firms have to rebuild how broker business reaches them [4]. The third possibility is sanctions against the six, built on the commission's own statement that their basic security measures were inadequate [5].
I'd expect the narrow reading at the six breached firms, since most of the attacks hit broker and staff pages, and something closer to the broad reading everywhere else [2][4]. The counter-case is capacity. Regulators plan to review every staff access route in the industry while each firm files its own self-inspection [6][11]. With reports arriving from every insurer, securities company and fintech, supervisors will rely heavily on what firms tell them. The view is wrong if broker-facing pages at the six breached firms are still reachable from outside once that review ends.
The commission did not put a cost on the inspections or mention penalties for any of the six, so the order does not by itself show a regulator moving faster to assign liability. The duties it places on breached firms are remedial. They must establish exactly what leaked and how consumers could be harmed, and act to prevent further leaks or financial losses [8].
The one spending direction the commission named is defensive tooling. It urged firms to take part in AI security testing and move to AI-based defenses, under the principle of defending against AI attacks with AI [9]. "We must use this situation as an occasion to review the entire information security system from square one and raise security to a higher level," Lee said [12].
What to watch
- Any FSC or FSS sanction against the six firms that cites the finding of inadequate basic security measures.
- Whether loan-broker pages at the breached firms can still be reached from outside after regulators finish reviewing employee access routes.
- Whether a seventh firm reports a leak through a staff or broker page after the self-inspection reports are filed.