Skip to content

Invest2 publishers2 min readPublished

FSC chief Lee Eok-won promises strict accountability for whichever Korean lender is breached next

FSC chairman Lee Eok-won told Korean financial firms they will be held strictly accountable under law if the hacks that hit six lenders happen again. The threat covers future breaches, so for the firms already hit the cost so far is five requests, including security checks and customer compensation.

The Investor · Invest desk

Photograph accompanying FSC chief Lee Eok-won promises strict accountability for whichever Korean lender is breached next
Photo: en.sedaily.com

What happened

  • Lee said hackers went after less-managed areas such as external web pages and servers used by loan brokers and by employees for convenience.
  • Leaks that began at Shinhan, KB Kookmin, Hana and BNK Busan banks reached Yegaram Savings Bank, where personal data on an estimated 40,000 customers was confirmed leaked.
  • At Hyundai Capital, attackers took some personal information on 146 mortgage loan agents.
  • The FSC had planned to collect firms' holiday self-inspections on Oct 7 and moved the meeting up after Hyundai Capital and Yegaram Savings Bank were hit.
  • Lee said data usable for fraudulent payments had not yet leaked, but warned of voice phishing and smishing built on the stolen information.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • exposure Any Korean financial firm breached after Oct 4 becomes the first test of whether the FSC's 'strictly accountable' warning produces penalties under existing law.
  • cost For the six firms already hacked, the first bill is customer compensation, third on Lee's list of five asks.
  • contradiction One report calls the attacks AI-driven while Lee said only that AI use could not be ruled out, so AI-against-AI defense spending is being sized to an attacker authorities have yet to identify.

Lee Eok-won's threat comes with a condition. Regulators will "hold firms strictly accountable under the relevant laws if similar breaches occur," the Financial Services Commission chairman said at Sunday's emergency meeting, with Financial Supervisory Service Governor Lee Chan-jin beside him [1][2][3]. That puts the legal exposure on whichever firm is breached next. The six already named, Shinhan, KB Kookmin, Hana and BNK Busan banks plus Yegaram Savings Bank and Hyundai Capital [1], were handed a list of requests: security checks across every sector, fewer external points of contact, prompt consumer protection and compensation, faster sharing of threat intelligence, and systems that "defend against AI attacks with AI" [7]. The FSC did not announce sanctions against any of the six or set a spending requirement for the five points [7].

The second request is the one that changes daily operations. The broker-facing pages and staff-convenience servers Lee described [4] are the external contact points that request targets. The records taken at Hyundai Capital belonged to mortgage loan agents [10]. "No matter how solid a security system is, a single unmanaged gap can become the weak point of the entire system," he said [5]. For the capital firms and savings banks the breaches spread to [14], I'd expect the cheapest compliance is closing or restricting those pages. The cost falls on the brokers and employees who used them.

If no new breach occurs, the warning is never tested and the industry pays for the checks. If another firm is hit, the FSC has to show what "the relevant laws" produce as a penalty [1]. The third route runs through the compensation request [7], and that bill falls on the six firms already breached.

In my view the record shows a regulator that has moved faster without yet using penalties. Lee asked the industry to act [7], and his accountability language covers breaches that have not happened [1]. For a lender's security budget, the new element is a stated legal downside to a breach after Oct 4 [1][2]. The counter-case is that existing Korean law already carries penalties heavy enough to make a forward-looking warning costly on its own. A supervisory inspection of the six that ends in sanctions, or a compensation order with a won figure attached, would prove me wrong.

The attacker profile is still unsettled. "The possibility of attacks using AI cannot be ruled out," Lee said [8]. A Seoul Economic Daily report dated Oct 3 called the attacks artificial intelligence-driven [12]. Authorities say they still need to verify whether one group carried out all the leaks [11].

What to watch

  • Whether supervisors open formal inspections of Shinhan, KB Kookmin, Hana, BNK Busan, Yegaram and Hyundai Capital, and whether any of them end in sanctions.
  • A breach at any Korean financial firm after Oct 4, the first case the 'strictly accountable' warning would cover.
  • Compensation terms the breached firms offer customers, and any rise in voice phishing or smishing that uses the leaked data.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories