The Bank of Korea and the state-run Export-Import Bank of Korea have reported sharp increases in attempted attacks this year. Separately, a law firm is preparing a damages lawsuit over a Shinhan Bank data breach affecting about 25,000 customers, while confirmed and suspected leaks involving a public-sector training platform and two major churches have extended concerns beyond finance.
Data released Wednesday by Rep. Lee Jong-wook of the opposition People Power Party showed that the Export-Import Bank detected 283 hacking attempts this year through Oct. 5, nearly eight times the 36 recorded in all of last year.
The total already exceeded the combined 197 attempts recorded over the preceding five years, according to materials submitted to the lawmaker by the state-invested bank.
Attempts involving harmful IP addresses and related activity jumped to 230 from 19 last year, accounting for 81.3 percent of this year’s total. Attempts to access its web systems rose to 53 from 17.
Of the 283 attempts, 272 originated from overseas IP addresses, including 128 in the United States, 56 in Singapore and 18 in China. Those locations indicate where the traffic originated, rather than necessarily identifying the attackers’ nationality.
The lender said it had suffered no hacking-related damage, including leaks of personal or credit information, over the past six years. It operates a cybersecurity monitoring center around the clock and shares threat information with the finance ministry’s cyber safety center.
The Bank of Korea recorded 136 hacking attempts this year through Oct. 2, about 4.5 times the 30 detected in all of last year.
The latest was an unauthorized access attempt against its website from a Netherlands-based address in September, adding to 135 attempts detected in the first eight months of the year.
Targets have mainly been systems accessible through the internet, including the central bank’s main website, economic statistics portal and electronic library.
Some earlier incidents caused disruption or exposed personal information. A distributed denial-of-service attack intermittently slowed access to the central bank’s website in December 2023. In May and June this year, an intrusion into a system used by an outside training provider exposed the personal information of 186 Bank of Korea employees.
The central bank said it recorded no successful intrusions, service disruptions or data leaks between the beginning of September and Oct. 2.
For commercial bank customers, the fallout is already moving toward the courts.
S Law Firm, based in Seoul’s Seocho district, is recruiting Shinhan Bank customers affected by its recent breach, according to a notice posted on the firm’s website Tuesday. Customers who received a breach notification or can otherwise verify that their information was exposed are eligible to join.
The firm plans to file a damages lawsuit once enough plaintiffs sign up. Each participant is expected to seek between 100,000 won ($74) and 300,000 won. The participation fee is 10,000 won, plus a 10 percent contingency fee.
Shinhan disclosed last week that an unauthorized external party had bypassed authentication on a loan-related service and obtained personal and credit information linked to about 25,000 customers.
The exposed information included names, phone numbers, annual income and calculated borrowing limits, along with other details submitted during loan applications. Shinhan Bank CEO Jung Sang-hyuk apologized and said the bank would fully compensate customers for losses linked to the incident.
Similar intrusions have also been identified at KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital.
Authorities are investigating signs that artificial intelligence may have been used to automate parts of the attacks. President Lee Jae Myung said Tuesday that AI appeared to have been involved, although authorities have yet to determine how it was used.
Outside finance, personal information belonging to more than 100,000 users was exposed from an online training platform run under the Anti-Corruption and Civil Rights Commission.
The platform provides ethics and integrity training for public institution employees, private school staff and others working at organizations affiliated with the public sector. Compromised records included names, user IDs, encrypted passwords, phone numbers, employers and job titles.
The Korea Integrity and Civil Rights Training Institute, which oversees the service, said the records came from an older system used before the platform moved to the cloud in April 2025. Information on the current system was not affected, it said.
An outside contractor had retained the old records instead of deleting them after the transition. The remaining records have since been deleted, and the institute pledged tighter oversight of vendors and their handling of personal information.
Suspected breaches at two major Seoul churches have raised concerns over the exposure of membership, donation and internal administrative records.
Cybersecurity company Oasis Security said it found data linked to Yoido Full Gospel Church and SaRang Church on an overseas hacker’s server.
The material associated with Yoido Full Gospel Church included about 960,000 member records updated over the past two years and roughly 330,000 donation records. Electronic approval documents and internal messenger records were also found. The record count does not necessarily represent the number of individual members affected. Data linked to SaRang Church included information on about 89,000 members and 286 employees, according to Oasis Security.
The company said the attacker gained administrator access to Yoido Full Gospel Church’s database. At SaRang Church, stolen login credentials appeared to have been used to enter the system and access other internal networks.
Both churches are investigating the extent and cause of the suspected breaches.
Yoido Full Gospel Church said the Korea Internet & Security Agency had notified it of signs of a possible personal data leak and that it was working with authorities and cybersecurity specialists to establish what happened. SaRang Church said it had formed an emergency task force, reported the incident to relevant authorities and begun measures to prevent further damage.
Copyright ⓒ Aju Press All rights reserved.



