BNK Busan Bank has confirmed that personal information belonging to 11 outsourced development workers was exposed after an external attack targeting a web server. The incident occurred at about 9 p.m. on October 1, when an outside party attempted an attack using an artificial intelligence agent. The bank said its main attack was blocked, but a follow-up inspection found signs that information had been visible through some web pages.
The exposed information identified so far includes the names and telephone numbers of the 11 outsourced workers. The bank said it immediately blocked the affected pages and restricted external access after discovering the exposure. It also said it is continuing to monitor its systems for additional signs of unusual activity.
The incident is separate from the customer information breaches reported at several other banks, according to the available reports. A report published on October 2 said that Shinhan Bank, KB Kookmin Bank and Hana Bank had confirmed information leaks linked to hacking, while Woori Bank and NH NongHyup Bank had experienced similar attempts but had not identified information exposure after blocking the attacks. The report said financial authorities held an emergency meeting with banks and card companies that afternoon.
BNK Busan Bank said it will strengthen monitoring for attacks using artificial intelligence and conduct additional checks across publicly accessible web pages using an attack surface management approach. The measures are intended to identify exposed pages and other externally reachable points that could be targeted in future attacks. The bank did not report a broader customer information leak in the evidence available for this incident.
