A wave of cyberattacks has spread beyond South Korea’s major commercial banks to non-bank lenders, exposing personal information and prompting an emergency review across the financial sector. The incidents involve several institutions and, in some cases, overlapping internet protocol addresses, suggesting that attackers tested similar access points across multiple firms.
Hyundai Capital said attackers targeted a search page used for housing-loan agents, exposing information belonging to 146 agents. The compromised data included names, mobile phone numbers and resident registration numbers. The company discovered that the page had been attacked on September 27 while checking an overseas IP address shared by financial authorities after the Shinhan Bank breach. It then blocked the address and page and formed a dedicated incident-response team.
- Hyundai Capital exposure
- Personal information belonging to 146 housing-loan agents
- Yegaram estimate
- About 40,000 customers potentially affected
- Regulatory response
- Emergency inspection meeting with industry leaders and affected firms
Yegaram Savings Bank separately found signs that an unidentified hacker accessed a server containing customer information on September 30. The lender estimates that names, birth dates and contact details for about 40,000 customers were exposed. It said its review indicated that the attacker did not gain access to or attack internal systems.
The latest disclosures follow breaches at Shinhan, KB Kookmin, Hana and BNK Busan banks. Shinhan’s incident involved information linked to about 25,000 people, while KB Kookmin identified roughly 100 records that may have been exposed through abnormal external access. Woori and NH NongHyup also faced attempted intrusions, but no damage had been identified at the time of reporting. An internal Woori analysis cited by SBS found nine access attempts from three suspicious IP addresses, all blocked by the bank’s firewall.
Common attack routes draw scrutiny
The repeated use of common IP addresses across financial institutions is now a central focus. Cybersecurity experts cited by SBS assessed that artificial intelligence may have helped attackers search for vulnerabilities, test stolen account credentials and exploit weaknesses in identity verification or access controls. That remains an expert assessment rather than a conclusion established by an official investigation.
Customers and loan agents whose records were exposed face the most immediate risk because names, contact details and identification data can support impersonation or further fraud attempts. The Financial Services Commission said it would convene leaders of financial industry associations and executives from affected companies for an emergency inspection meeting. The next questions are whether additional institutions identify compromises, how far the shared attack infrastructure extended and what corrective measures regulators require.
