Seven financial firms have confirmed customer data exposure in a broad hacking campaign, but only Shinhan Bank disclosed the incident to the market. Current rules require regulatory reporting and customer notification when at least 10,000 people are affected, while separate market disclosure is not mandatory, making smaller breaches difficult for customers to identify. Some firms, including Welcome Savings Bank and Hyundai Capital, reportedly took five days to detect the attacks, raising concerns that attackers may have extracted data gradually to avoid detection.

Financial regulators are expanding inspections beyond banks and card companies to securities firms and major insurance agencies as the risk of combined data being misused grows.