South Korea’s banks are preparing for a wave of highly personalized fraud attempts after cyberattacks exposed personal information held by seven financial companies. More than 60,000 people were affected, according to MBC, with compromised data including names, contact details, workplaces, income and loan information. Authorities have not reported direct financial losses linked to the breaches so far, but the range of leaked details could help criminals make deceptive calls and messages sound credible.

The affected companies include Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. Investigators found the same attacker internet addresses in some incidents, while similarities in methods and patterns appeared across other attacks. Financial authorities believe an attacker may have changed addresses while targeting several companies, but the available evidence does not establish a final attribution.

Affected institutions
Seven banks, savings banks and finance companies
People affected
More than 60,000 individuals
Direct financial losses
None reported in the available evidence

The attacks focused on systems that were less protected than core banking infrastructure. KB Kookmin Bank lost information through a mobile work-support system used by employees, while Hana Bank’s sales-support system was accessed. Officials and security specialists said external web servers, staff tools and systems considered less important may not have received the same scrutiny or strict authentication applied to primary financial servers.

Artificial intelligence is suspected of helping automate the search for those gaps. MBC reported indications that an AI agent was used to scan across the financial sector rather than concentrate on a single company. The pattern suggests a model in which automated tools identify accessible services, test weaknesses and repeat the process across multiple institutions. Authorities have not publicly established precisely which AI tools were used or how much of the operation was automated.

Secondary systems became the route into financial data

The wider activity was not limited to companies where information was stolen. The same two United States-based internet addresses used against Shinhan Bank attempted to access Toss Bank servers 14 times during January, July and August, according to material provided to a lawmaker and reported by Maeil Shinmun. Toss Bank said it detected and blocked every attempt, with no actual damage. The Korea Federation of Community Credit Cooperatives also blocked an intrusion associated with an address linked to the Shinhan incident.

For customers, the most immediate danger is not an instant withdrawal from an account but fraud built around real personal details. A caller could pose as a bank employee, refer to a customer’s loan or income, and offer a lower interest rate or a higher borrowing limit. A message could claim to provide compensation for the breach, then direct the recipient to a malicious application or a page designed to capture financial information.

Experts cited by MBC assessed the risk of money being removed directly or transactions being blocked as relatively low because account passwords and other information usable for unauthorized payments were not found among the exposed data. Financial authorities likewise said they had found no indication that sensitive data directly usable for fraudulent payments had leaked. That assessment does not remove the danger of social engineering, which depends on persuading victims to surrender additional credentials or install malicious software themselves.

Customers receiving a message about the incident should avoid opening any included internet link. They should instead enter the financial company’s official application or website independently, or contact the institution through a verified customer-service number. Requests to install an application, disclose a password, provide an authentication code or transfer funds should be treated as warning signs, even when the sender appears to know accurate personal or loan information.

  • Do not open links sent in messages claiming to verify the data breach
  • Use the institution’s official application, website or verified telephone number
  • Reject requests for passwords, authentication codes, application installation or money transfers

The Financial Services Commission convened an emergency meeting with regulators, the Financial Security Institute, industry associations and major financial companies. It called for a full review of information-security systems, stronger detection of unusual transactions and timely consumer guidance. The commission also urged the industry to accelerate defenses that use AI against AI-assisted attacks. President Lee Jae Myung ordered a thorough investigation and the preparation of countermeasures.

Authorities demand broader defenses and closer monitoring

Attention now rests on whether investigators confirm a common operator, identify additional compromised systems or detect fraud using the leaked records. Financial authorities have said companies should respond quickly with relief and compensation if actual losses occur. The incident also puts pressure on institutions to extend core-system security standards to employee platforms, sales tools and externally accessible servers that can provide attackers with an easier route to valuable data.