South Korea’s Financial Services Commission has urgently summoned the heads of all financial industry associations and the chief executive officers (CEOs) of financial firms hit by hacking attacks during the holiday period. As personal data breach incidents that began at major commercial banks spread to secondary financial institutions such as capital companies and savings banks, the regulator intends to review the security response framework across the entire financial sector, going beyond individual industry-level measures.
According to financial industry sources on the 3rd, the FSC will hold an emergency review meeting on the afternoon of the 4th at the Government Complex Seoul, with participation from association heads across all sectors—including banking, financial investment, insurance, specialized credit finance, savings banks, mutual finance, virtual assets, and fintech—as well as CEOs of financial firms that experienced breach incidents. The meeting will be chaired directly by FSC Chairman Lee Eok-won, with Financial Supervisory Service Governor Lee Chan-jin also expected to attend.
The FSC had originally planned for each financial firm to conduct its own security inspection during the holiday period extending through the 5th, with results to be reported on the 7th. However, as additional damage was confirmed at Hyundai Capital and Yegaram Savings Bank, heightening anxiety, the meeting schedule appears to have been moved up.
The meeting is expected to review the trends and damage status of recent breach incidents in the financial sector and discuss response measures to prevent further spread.
Successive Data Breach Incidents
The financial sector has recently experienced a series of personal data breach incidents caused by hacking. Starting with the leak of approximately 25,000 customer records at Shinhan Bank on the 30th of last month, Hana Bank saw personal information on 89 customers and KB Kookmin Bank on 119 customers leaked on the 1st of this month. On the same day, BNK Busan Bank also confirmed that personal information on 11 outsourced development staff members had been leaked.
The damage that began at major commercial banks has spread to secondary financial institutions. At Yegaram Savings Bank, approximately 40,000 customer records were found to have been leaked, while at Hyundai Capital, partial personal information on 146 mortgage loan solicitors was exposed. Woori Bank and NH NongHyup Bank were also reportedly targeted by hacking attacks, though no data breach damage has been confirmed to date.
| Financial Firm | Scale of Breach | Leaked Information |
|---|---|---|
| Shinhan Bank | ~25,000 people | Loan solicitor mobile quick-lookup service customer information |
| Yegaram Savings Bank | ~40,000 people | Customer personal information |
| KB Kookmin Bank | 119 people | Customer names, phone numbers, addresses, encrypted resident registration numbers |
| Hana Bank | 89 people | Names, resident registration numbers, phone numbers |
| Hyundai Capital | 146 people | Partial personal information on mortgage loan solicitors |
| BNK Busan Bank | 11 people | Outsourced development staff personal information |
Note: Figures compiled from announcements by financial authorities and individual financial firms; some are estimates.
Financial authorities maintain that further verification is needed to determine whether all of these incidents were carried out by the same hacking group. A financial authority official said, “More time is needed to confirm whether the same group carried out the attacks, or whether attacks by different groups coincidentally came to light during this self-inspection process.”
Financial Authorities’ Response
The FSC had already held an emergency situation response meeting on the 2nd, chaired by Secretary General Shin Jin-chang, with participation from the Financial Supervisory Service, the Financial Security Institute, six banks, three credit card companies, the Korea Federation of Banks, and the Credit Finance Association. At that meeting, the FSC directed financial firms to comprehensively identify IT assets and services exposed to the outside and thoroughly inspect security vulnerabilities and access control status.
In particular, the FSC urged firms to inspect all externally accessible systems regardless of whether they are customer-facing services or their type, to ensure no security blind spots emerge. Firms were also ordered to minimize unnecessary external exposure of information and verify whether any pathways exist to access internal information without authentication.
The Financial Security Institute shared relevant threat intelligence, including attacker IP addresses, with the banking sector immediately after receiving the Shinhan Bank data breach report on the 30th of last month. Banks have been conducting self-inspections for external intrusions using the shared IP addresses to check access to their systems and utilizing anomaly detection systems.
Secretary General Shin Jin-chang emphasized, “Maintaining thorough preparedness to prevent incidents such as data breaches is of paramount importance,” adding, “In the event an incident unavoidably occurs, we must be fully prepared to minimize consumer harm through rapid response.”
Impact and Outlook
This emergency summons of the entire financial sector demonstrates that financial authorities view the hacking threat not as a problem for individual financial firms but as a risk to the overall financial system. The inclusion of virtual asset and fintech sectors in the meeting suggests that the scope of security management is expanding amid the growth of digital financial services.
Financial authorities plan to manage and supervise financial firms that experienced breach incidents to ensure consumer protection and damage compensation procedures are carried out without disruption. Secretary General Shin stated, “We will thoroughly analyze the causes of the breach incidents and attack methods, and swiftly prepare necessary institutional improvement measures.”
KB Kookmin Bank immediately blocked the relevant servers and access pathways upon recognizing the possibility of information leakage through abnormal external access, and individually notified affected customers of the breach and methods to prevent secondary damage. The bank plans to fully compensate customers if damage occurs. Shinhan Bank also issued an apology under the name of CEO Jung Sang-hyuk and promised full compensation for customer damages.
Click Here For The Original Source.
