Hacking attempts targeting the Bank of Korea and South Korean state-run banks surpassed 1.02 million through September this year, already exceeding last year’s annual total. In the private banking sector, just two weeks after the Financial Security Institute publicly disclosed AI-based attack cases and issued warnings, Shinhan, KB Kookmin, and Hana Bank suffered a chain of hacking breaches, putting the entire financial sector’s security framework under scrutiny.
According to data obtained by Representative Kang Min-kuk of the ruling People Power Party, who serves on the National Assembly’s Finance and Economy Planning Committee, from the Bank of Korea, Korea Development Bank, Industrial Bank of Korea, and Export-Import Bank of Korea, a total of 4,986,964 hacking attempts were recorded against these four institutions from 2020 through September of this year. No actual breaches resulting in system compromise occurred, however.
The number of hacking attempts has risen annually from 358,800 in 2020 to 934,858 last year. Through September of this year alone, the figure reached 1,024,478 — nearly three times the full-year total for 2020.
By institution, the Industrial Bank of Korea was the primary target, accounting for 91.9% of all attempts, followed by the Korea Development Bank with 399,379 attempts, the Bank of Korea with 3,076, and the Export-Import Bank of Korea with 510. IBK officials explained that because the bank offers internet and mobile banking services like commercial banks, it naturally detects a higher volume of attacks.
The Bank of Korea’s Gyeonggi IT Center, which houses the central bank’s core computing servers and opened in October last year, has recorded 145 intrusion attempts since its launch. Denial-of-service attacks, which paralyze systems to block normal services, were the most common attack method at 45.6%.
AI Attacks Become Reality Two Weeks After Warning
The private banking sector has already been breached by AI-driven attacks. Seven institutions — Shinhan, KB Kookmin, Hana, and BNK Busan Bank, along with Yegaram and Welcome Savings Bank, and Hyundai Capital — have recently suffered hacking incidents in succession.
Most of these financial firms had received AI hacking warnings just two weeks before the incidents. According to documents obtained by Representative Han Chang-min of the Social Democratic Party, who serves on the National Assembly’s Political Affairs Committee, the Financial Security Institute convened approximately 160 financial security officers on the 17th of last month for a “Financial AI Security Threat Response Seminar.”
At the seminar, the Financial Security Institute disclosed the first case of an AI agent attack in South Korea’s financial sector. When an attacker instructed a DeepSeek-based AI agent to locate financial server programs, the AI penetrated security vulnerabilities within a single day, planted remote-control malware, and proceeded to search internal servers. The targeted financial firm reportedly blocked the attack just before additional malware could be installed.
The Financial Security Institute urged attendees to maintain constant monitoring of externally exposed systems, warning that inspections conducted once or twice a year cannot catch such attacks. The warning ultimately became reality. Analysts believe the chain of hacking attacks also used AI models including DeepSeek as penetration tools, targeting externally connected systems such as loan solicitor inquiry pages and employee mobile apps.
Personnel from KB Kookmin Bank, Hana Bank, Hyundai Capital, and Welcome Savings Bank — all hacked two weeks later — had attended the seminar but failed to prevent the breaches. Shinhan Bank was represented by a Shinhan Financial Group officer, while BNK Busan Bank was not on the attendance list.
Gaps also exist in financial firms’ mandatory security inspections. The Financial Security Institute noted that APIs — the channels through which data flows behind websites and apps — are included in vulnerability assessment items, but financial companies themselves select which systems to inspect.
Security Budgets Allocated but Less Than 70% Executed
Financial institutions’ routine budget execution for information security has also been lackluster. According to data submitted by financial authorities to Representative Park Sung-hoon of the People Power Party, the top 20 financial companies by frequency of IT system failures allocated 438 billion won (approximately $326.6 million) for information security last year, but actual spending came to only 305 billion won (approximately $227.5 million) — an execution rate below 70%.
Shinhan Bank suffered a breach of its loan solicitor inquiry page, exposing the personal information of more than 25,000 customers. The bank had allocated approximately 45.3 billion won (approximately $33.8 million) for information security last year but spent only 31.7 billion won (approximately $23.6 million), a 69.9% execution rate. This year’s information security budget of 40.5 billion won (approximately $30.2 million) represents a cut of more than 10% from last year.
KB Kookmin Bank had personal information of 119 customers compromised through an attack on its mobile work support system. The bank allocated 67.6 billion won (approximately $50.4 million) for information security last year but executed only 39.3 billion won (approximately $29.3 million), a mere 58.1% execution rate.
Representative Park stated, “Inadequate security investment cannot be dismissed as a matter of management efficiency; it is a question of trust in the financial system.” He added, “Regulators should not keep producing after-the-fact measures every time an incident occurs, but should conduct a comprehensive review of security investment practices and hold accountable those found to have been negligent.”
Belated Security Investment After Incidents
As customer anxiety grows in the wake of the hacking incidents, financial firms are belatedly moving to expand investments. KB Kookmin Bank is considering raising its information security budget to over 100 billion won (approximately $74.6 million) next year. The bank is also pursuing upgrades to its intrusion detection and prevention systems and web firewalls to counter AI hacking attacks with AI.
Shinhan Bank plans to allocate the industry’s largest information security budget and recruit AI security experts and white-hat hackers. Hana Bank is investing hundreds of billions of won to strengthen its security framework and is reviewing the implementation of a zero-trust security architecture. Woori Bank is also considering increasing its security budget by more than 20% and expanding its specialist workforce by over 10%.
The hacking incidents have reignited debate over easing network separation regulations for financial firms. Proponents of maintaining the regulations argue they are essential for security, while opponents contend that leveraging AI and cloud technologies for security actually requires regulatory relaxation. Lee Bok-hyun, Chairman of South Korea’s Financial Services Commission, said during last week’s parliamentary audit, “We are pursuing the lifting of network separation regulations on the premise of security, in order to support innovation and strengthen security capabilities in the financial sector.”
The following table summarizes the major financial firms affected by the hacking incidents and the scale of damage.
| Financial Firm | Attack Vector | Personal Data Exposed |
|---|---|---|
| Shinhan Bank | Loan solicitor inquiry page | 25,000+ individuals |
| KB Kookmin Bank | Mobile work support system | 119 individuals |
Note: BNK Busan Bank, Hana Bank, Yegaram and Welcome Savings Bank, and Hyundai Capital also suffered hacking incidents, but specific exposure figures have not been disclosed.
Click Here For The Original Source.
