Internet addresses linked to a wider hacking campaign against South Korean financial companies also attempted to reach the servers of KakaoBank, K Bank and Toss Bank, according to reports published Tuesday. The activity extended the apparent targeting beyond major commercial banks and nonbank financial institutions to all three of the country’s internet-only banks.

The attempts did not result in confirmed intrusions or customer information leaks at the three internet banks, the reports said. KakaoBank faced repeated approaches beginning in January, while K Bank also recorded attempted access. Toss Bank reportedly encountered attempts on about 10 occasions between January and August.

Banks affected
KakaoBank, K Bank and Toss Bank
Reported outcome
No confirmed customer information leak
Observed period
Attempts were reported from January through August

The reported scale differs between the two accounts. The Dong-A Ilbo said financial authorities identified 28 distinct addresses after removing duplicates from 33 addresses associated with attacks on financial companies. Maeil Shinmun said the Financial Supervisory Service’s digital risk analysis team had identified 19 attacker addresses associated with 12 countries. The available evidence does not explain the difference, which may reflect different counting methods, scopes or reporting stages.

Different counts point to an unresolved scope question

The activity matters because internet banks handle large volumes of mobile transactions, making attempted access a direct test of controls around highly active digital services. The broad geographic distribution of the addresses also complicates attribution because an address location does not necessarily identify where an attacker is based. One report said the campaign was suspected of using an artificial intelligence agent, but the evidence provided does not establish how that tool was used.

The immediate focus is whether further inspection uncovers any intrusion that was not initially detected and whether the address lists are reconciled. Authorities and banks will also need to watch for renewed attempts from related infrastructure. For customers, the key distinction remains that servers were approached, but neither report identified an actual leak of personal information at KakaoBank, K Bank or Toss Bank.