Seoul orders probe as financial hacks widen

by Lee Jung-woo Posted : October 4, 2026, 15:32Updated : October 4, 2026, 15:32
South Korean President Lee Jae Myung speaks during the 48th meeting of senior secretaries and aides at Cheong Wa Dae in Seoul on Oct 1 2026 Courtesy of Cheong Wa Dae
South Korean President Lee Jae Myung speaks during the 48th meeting of senior secretaries and aides at Cheong Wa Dae in Seoul on Oct. 1, 2026. Courtesy of Cheong Wa Dae

SEOUL, October 04 (AJP) - South Korean President Lee Jae Myung on Sunday ordered a thorough investigation into a widening wave of cyberattacks on financial companies, as evidence emerged that the campaign had reached beyond major banks into savings banks, capital firms and mutual-finance networks.

Lee instructed officials to investigate the breaches and devise countermeasures with a “grave awareness” of the seriousness of the incidents, presidential spokesperson Kang Yu-jung said.

The latest findings suggest the attacks were considerably broader than previously known.

The Korean Federation of Community Credit Cooperatives detected attempted access from the same attacker IP address linked to the breach at Shinhan Bank, while NongHyup’s mutual-finance network faced similar intrusion attempts. Both blocked the attacks without confirmed data leaks.

Welcome Savings Bank, meanwhile, found that information belonging to corporate customers had been compromised. A financial industry official said the number of institutions targeted could be “far greater” than those disclosed publicly.

The Financial Services Commission and Financial Supervisory Service have been investigating the incidents since Shinhan reported its breach on Sept. 30.
 
This image was generated by ChatGPT AJP Lee Jung-woo
This image was generated by ChatGPT. AJP Lee Jung-woo

FSC Chairman Lee Eog-weon on Sunday convened an emergency meeting with financial regulators, the Financial Security Institute, industry associations and the chief executives of seven affected financial companies, including Shinhan, KB Kookmin, Hana and Busan banks.

Authorities are also examining whether artificial-intelligence agents were used to automate parts of the attacks, including the search for vulnerable systems. Similarities in timing and tactics have raised suspicions that some of the incidents may be connected, although officials have not established that a single group was responsible and some attacks appear not to have involved AI.

What has drawn particular scrutiny is where the hackers struck. Rather than breaking through the heavily protected core systems that process customer transactions, attackers appear to have targeted peripheral employee-facing websites and support applications where authentication and monitoring were less stringent.

At Shinhan, a service used by loan brokers became one route for the breach. The attack is believed to have continued for about 30 hours and exposed 25,727 records. At KB Kookmin, attackers targeted mobile systems used by employees for more than 42 hours, exposing customer and staff information, according to data submitted to lawmakers.

The pattern points to an uneven security perimeter across the financial sector: banks may heavily fortify their central networks while maintaining numerous externally accessible employee and support services that can offer attackers a softer point of entry. As AI makes it possible to scan large numbers of systems and test vulnerabilities at greater speed, those peripheral systems can become increasingly difficult to defend through conventional monitoring alone.

The FSC had already begun reassessing that model before the latest breaches. Tests conducted this year found that advanced AI tools could examine millions of lines of source code within hours and systematically identify potential vulnerabilities, prompting regulators to explore wider use of AI-based defensive tools and changes to Korea’s strict network-separation rules.

The latest attacks are likely to accelerate that overhaul. Financial authorities are considering stronger management of internet-exposed systems, faster security patching and greater use of AI to detect attacks — an effort regulators have described as using “AI to defend against AI.”

AJP Takeaways

- 
President Lee Jae Myung ordered a thorough investigation as cyberattacks spread across banks, savings banks and mutual-finance networks.

- Hackers appear to have exploited weaker employee-facing and support systems rather than banks’ heavily protected core transaction networks.

- Regulators are considering tighter controls on internet-exposed systems and wider use of AI-based defenses as attackers increasingly use automation to find vulnerabilities.