← Back to News
Fraud

Seoul orders financial firms to block outside access after hacks

South Korea’s financial regulator convened the entire sector on Sunday, October 4, and told firms to block all nonessential external access by default after intrusions at Shinhan Bank and five other lenders exposed personal data.

South Korea’s Financial Services Commission (FSC) told every financial firm in the country on Sunday, October 4, 2026, to block by default all outside access not indispensable to consumer services or to the work itself. Chairman Lee Eok-won gave the order at a 2 p.m. emergency meeting of the whole sector at the Government Complex Seoul. A string of intrusions had begun at Shinhan Bank on September 30 and spread to other banks, a savings bank, and a capital firm.

Financial Supervisory Service (FSS) Governor Lee Chan-jin attended, with the Financial Security Institute, the science ministry, the privacy regulator, the National Police Agency, and the Korea Internet & Security Agency. The heads of every industry association joined, from banks, card issuers, and insurers to savings banks, cooperative lenders, fintechs, and DAXA, the crypto exchange alliance, along with seven major financial firms the FSC did not name.

6
firms reporting leaks before the meeting
Seoul Economic Daily
≈25,000
Shinhan Bank customers affected, the bank said
The Korea Herald
≈40,000
people estimated to be affected at Yegaram Savings Bank
DigitalToday
2
large banks, Woori and NH Nonghyup, that blocked the attacks
DigitalToday

External access blocked unless indispensable

Every firm, including smaller cooperative lenders, savings banks, insurers, brokerages, and fintechs, must inventory all its internet-facing IT assets and services, re-examine vulnerabilities, authentication, access controls, and intrusion detection, and report findings to the FSC and the FSS. Firms must also confirm that threat intelligence already shared, such as attacker IP addresses and methods, feeds their detection and blocking systems and that security patches are installed. A firm that neglects that information and suffers a similar breach faces strict action under the law.

Outside access is to be cut as a rule. Where it cannot be avoided, access rights and viewable data must be kept to the minimum. The FSC singled out systems used by employees and by outside staff such as loan brokers and outsourcing vendors, which it said were behind the recent breaches. Those systems must not store or display personal credit information unnecessarily, and firms must check thoroughly for any route that skips or bypasses authentication.

🔑
Side doors, not core banking
Most attacks hit external web pages and servers that loan brokers and employees use for convenience, areas with relatively little oversight, the FSC found, according to the Seoul Economic Daily. Basic security was inadequate, and more data was stored than the work required. The intrusions centered on auxiliary systems rather than internet or mobile banking, DigitalToday reported.
FirmSystem breachedData exposedPeople affected
Shinhan BankLoan broker query serviceNames, phone numbers, incomeAbout 25,000 customers
KB Kookmin BankStaff mobile work systemNames, phone numbers, addresses119 people
Hana BankSales support systemResident ID numbers, names, addresses89 customers
BNK Busan BankWebpageNames, phone numbers, emails11 outsourced developers
Yegaram Savings BankCustomer data serverNames, birth dates, contact detailsAbout 40,000 (estimate)
Hyundai CapitalHousing loan agent query pageNames, phone numbers, resident ID numbers146 housing loan agents
Leaks reported before the October 4 meeting

Woori Bank and NH Nonghyup Bank were also attacked but blocked the attempts, with no leak confirmed. Police opened a preliminary investigation into the Shinhan, KB Kookmin, Hana, and BNK Busan cases. Whether a single attacker lay behind all the incidents had not been established. Some attacks raised the possibility that AI agents were used, DigitalToday wrote, a hypothesis investigators had not confirmed.

Compensation, and a watch for voice phishing

Breached firms must quickly and accurately gauge what leaked and the potential harm to consumers, and immediately act to prevent further leaks or financial losses. Where consumer harm is confirmed, they should notify those customers in detail and do their utmost to deliver relief and compensation promptly. They must also brace for secondary fraud such as voice phishing and smishing by tightening abnormal-transaction detection and customer alerts.

Agencies and firms are to share attack IP addresses and methods quickly, and the government will widen threat sharing beyond finance. Under the principle of defending against AI attacks with AI, firms should join government AI security testing and move toward AI-based, zero-trust security.

Financial security “goes beyond protecting the computer systems of individual financial companies,” Lee said, according to the Seoul Economic Daily’s translation. “We must use this situation as an occasion to review the entire information security system from square one and raise security to a higher level.”

Glass office towers lit at dusk behind a traffic light
Every financial firm, from the largest banks to fintechs, must now inventory its internet-facing systems.
September 30, 2026
Shinhan reports a breach
Regulators open an on-site investigation the same day.
October 1, 2026
About 25,000 customers
Shinhan Bank discloses the scale of its leak.
October 2, 2026
First emergency meeting
The FSC sends a security checklist to all firms; leaks surface at Hana Bank and BNK Busan Bank.
October 3, 2026
Leaks spread
Yegaram Savings Bank and Hyundai Capital confirm leaks.
October 4, 2026
Whole-sector meeting
Nonessential outside access is to be blocked by default.

On October 6, President Lee Jae Myung said “signs have emerged” that AI agents were deployed in at least some of the attacks, The Record reported. Citing The Wall Street Journal, it said data on at least 68,000 people had reportedly been exposed at seven or more financial institutions.

Provenance

Published October 4, 2026

5 sources, 5 distinct domains

↗ Financial Services Commission, press release on the October 4 emergency meeting of the entire financial sector (Korean), posted October 6, 2026 · fsc.go.kr↗ Seoul Economic Daily, Korea Orders Financial Firms to Block Outside Access After Hacks, October 4, 2026 · en.sedaily.com↗ DigitalToday, Hacking emergency spreads from banks to savings banks and capital firms in South Korea finance sector, October 4, 2026 · digitaltoday.co.kr↗ The Korea Herald, FSC orders banks, card firms to conduct security checks, October 2, 2026 · koreaherald.com↗ The Record, South Korean officials believe AI agents were used to hack several banks, October 6, 2026 · therecord.media
← All news