South Korean financial authorities are investigating a series of cyberattacks affecting seven financial companies, with evidence suggesting that the incidents may be linked. The affected institutions are Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. Investigators found that the same internet address appeared in some attacks, although the addresses used against banks differed from those targeting savings banks and the finance company.
- Institutions affected
- Four banks, two savings banks and one finance company
- Regulatory response
- An emergency financial-sector security meeting held on October 4
- Investigative status
- A common attacker and AI-assisted automation remain under examination
The attacks reportedly focused on externally accessible services rather than taking complete control of internal servers through malware. Attackers repeatedly submitted requests and attempted to retrieve customer or employee information through comparatively vulnerable access points. The volume and simultaneous nature of the activity led authorities to examine whether artificial intelligence tools were used to automate the search for weaknesses and repeat access attempts.
Officials have not established that artificial intelligence was used, and the identity of the attacker remains unconfirmed. However, similarities in the methods and patterns across the incidents have raised the possibility that one actor changed internet addresses while targeting several companies. The investigation must still determine the full extent of the exposed information and whether any stolen data has been used for financial fraud or other secondary crimes.
Regulators move to contain further exposure
The Financial Services Commission convened an emergency meeting on October 4 with the Financial Supervisory Service, the Financial Security Institute, industry associations and seven major financial companies. The meeting followed the reporting of an incident at Shinhan Bank on September 30 and was intended to coordinate threat intelligence, prevent additional damage and review security controls across the financial sector.
Authorities called for a comprehensive reassessment of information-security systems and stronger defenses capable of responding to automated attacks. The immediate concern for affected customers is possible misuse of exposed personal information, while financial companies face pressure to identify vulnerable public-facing services before attackers can exploit them repeatedly. Further disclosures from regulators and the institutions will be needed to establish the number of people affected, the precise data involved and whether the suspected connection among all seven attacks is confirmed.
