Invest2 publishers2 min readPublished
Korea orders every bank and card firm to audit exposed systems after leaks at four lenders
South Korea's Financial Services Commission ordered banks and card firms to check every externally reachable IT system after data leaks at four banks. The regulator will collect the returns and use them to build new cybersecurity measures for the financial sector.
The Investor · Invest desk

What happened
- The attacks involved AI agents and hit less-secure systems, including Shinhan Bank's service for loan agents and KB Kookmin Bank's mobile work app for employees.
- Shinhan Bank said on Thursday that data on about 25,000 customers leaked after code related to its communications infrastructure was hacked.
- Industry sources told Yonhap the Shinhan attackers are suspected to be based overseas and used advanced artificial intelligence tools.
- Woori Bank and NH Nonghyup Bank were reportedly hit by similar attacks but blocked unauthorized access, so no personal data leaked, Yonhap said.
- A police division in charge of cyberterror response has opened a preliminary probe into the series of bank hacks.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- cost Card companies with no reported breach now pay for the same system inventory and checklist review as the four banks that leaked data.
- decision Each firm has to decide, system by system, whether to cut what it exposes externally or put authentication in front of internal data, the two fixes the FSC named.
- exposure The four breached banks will compensate customers for any losses under the authorities' oversight, so their bill grows with whatever the leaked data is later used for.
The order's scope follows the route the attackers took. Neither of the two systems named in the attacks is a customer channel [4]. The checks cover every system reachable from outside, whether or not it serves customers and whatever service it offers [5]. The first task is an inventory of all IT assets and services exposed to external access, then a review of their vulnerabilities and access controls [5].
The damage disclosed so far is concentrated. KB Kookmin's own review found more than 100 customers affected [13], and Hana Bank put its count at 89, with resident registration numbers among the leaked fields [14]. Add Shinhan's figure and the three disclosed counts come to about 25,200 customers [1], with Shinhan accounting for about 99% of them [2]. BNK Busan also leaked data, according to financial industry sources cited by the Korea Herald [15], though no count has been reported. Six banks have now been named as targets, and four of them leaked data [3].
For now the FSC is collecting self-reviews against a checklist it will supply [7]. It has sent inspectors from the Financial Supervisory Service and the Financial Security Institute only to the four banks that leaked [19]. If the returns show unauthenticated routes into internal data at banks and card firms alike, the regulator has its case for binding requirements. If the inspections trace the four leaks to a shared component, the fix lands on a supplier and any rule can stay narrow. And if Woori and NH Nonghyup, the two banks that blocked the attacks [16], turn out to be typical, the case is for enforcing controls the banks already run.
I think the sector-wide reading holds on scope and is unproven on rules. The order itself makes the scope sector-wide [1], and the FSC has tied the measures it promised to these returns [2]. "We will thoroughly analyze the causes and methods of the attacks and swiftly develop measures to strengthen the system," said Shin Jin-chang, the FSC secretary general who chaired the emergency meeting [9] [3]. The thesis is wrong if what follows is the same checklist made permanent, with no new requirement attached.
What the four banks end up paying depends on what leaked. Shinhan's exposed fields were annual income, names and phone numbers [12]. "People will only feel reassured once it is confirmed that the leaked information was not directly related to their financial transactions," a financial industry official said, according to the Korea Herald [10].
What to watch
- The FSC's summary of the checklist returns, and whether it finds unauthenticated routes to internal data at firms beyond the four breached banks.
- Findings from the on-site inspections at Shinhan, KB Kookmin, Hana and BNK Busan, especially whether the leaks trace to a shared component or supplier.
- A customer count for BNK Busan and the first compensation figures from any of the four banks.