South Korea’s Financial Services Commission (FSC) told every financial firm in the country on Sunday, October 4, 2026, to block by default all outside access not indispensable to consumer services or to the work itself. Chairman Lee Eok-won gave the order at a 2 p.m. emergency meeting of the whole sector at the Government Complex Seoul. A string of intrusions had begun at Shinhan Bank on September 30 and spread to other banks, a savings bank, and a capital firm.
Financial Supervisory Service (FSS) Governor Lee Chan-jin attended, with the Financial Security Institute, the science ministry, the privacy regulator, the National Police Agency, and the Korea Internet & Security Agency. The heads of every industry association joined, from banks, card issuers, and insurers to savings banks, cooperative lenders, fintechs, and DAXA, the crypto exchange alliance, along with seven major financial firms the FSC did not name.
External access blocked unless indispensable
Every firm, including smaller cooperative lenders, savings banks, insurers, brokerages, and fintechs, must inventory all its internet-facing IT assets and services, re-examine vulnerabilities, authentication, access controls, and intrusion detection, and report findings to the FSC and the FSS. Firms must also confirm that threat intelligence already shared, such as attacker IP addresses and methods, feeds their detection and blocking systems and that security patches are installed. A firm that neglects that information and suffers a similar breach faces strict action under the law.
Outside access is to be cut as a rule. Where it cannot be avoided, access rights and viewable data must be kept to the minimum. The FSC singled out systems used by employees and by outside staff such as loan brokers and outsourcing vendors, which it said were behind the recent breaches. Those systems must not store or display personal credit information unnecessarily, and firms must check thoroughly for any route that skips or bypasses authentication.
| Firm | System breached | Data exposed | People affected |
|---|---|---|---|
| Shinhan Bank | Loan broker query service | Names, phone numbers, income | About 25,000 customers |
| KB Kookmin Bank | Staff mobile work system | Names, phone numbers, addresses | 119 people |
| Hana Bank | Sales support system | Resident ID numbers, names, addresses | 89 customers |
| BNK Busan Bank | Webpage | Names, phone numbers, emails | 11 outsourced developers |
| Yegaram Savings Bank | Customer data server | Names, birth dates, contact details | About 40,000 (estimate) |
| Hyundai Capital | Housing loan agent query page | Names, phone numbers, resident ID numbers | 146 housing loan agents |
Woori Bank and NH Nonghyup Bank were also attacked but blocked the attempts, with no leak confirmed. Police opened a preliminary investigation into the Shinhan, KB Kookmin, Hana, and BNK Busan cases. Whether a single attacker lay behind all the incidents had not been established. Some attacks raised the possibility that AI agents were used, DigitalToday wrote, a hypothesis investigators had not confirmed.
Compensation, and a watch for voice phishing
Breached firms must quickly and accurately gauge what leaked and the potential harm to consumers, and immediately act to prevent further leaks or financial losses. Where consumer harm is confirmed, they should notify those customers in detail and do their utmost to deliver relief and compensation promptly. They must also brace for secondary fraud such as voice phishing and smishing by tightening abnormal-transaction detection and customer alerts.
Agencies and firms are to share attack IP addresses and methods quickly, and the government will widen threat sharing beyond finance. Under the principle of defending against AI attacks with AI, firms should join government AI security testing and move toward AI-based, zero-trust security.
Financial security “goes beyond protecting the computer systems of individual financial companies,” Lee said, according to the Seoul Economic Daily’s translation. “We must use this situation as an occasion to review the entire information security system from square one and raise security to a higher level.”
On October 6, President Lee Jae Myung said “signs have emerged” that AI agents were deployed in at least some of the attacks, The Record reported. Citing The Wall Street Journal, it said data on at least 68,000 people had reportedly been exposed at seven or more financial institutions.