South Korea Orders Full Financial Sector Security Sweep After Major Breaches

South Korean President Lee Jae-myung has demanded a comprehensive investigation into recent data breaches at banks and financial firms, striking a tone of urgency. The order came on October 4, 2026, after multiple hacks exposed sensitive personal information of customers and employees. Authorities are also probing whether artificial intelligence tools played a part in breaching internal systems.

Scope of the Breaches

The security incidents began on October 1 when Shinhan Bank disclosed that about 25,000 customers had their names, telephone numbers, incomes, loan limits, and some resident registration numbers leaked during loan applications. Two days later, KB Kookmin Bank and Hana Bank announced separate breaches affecting 119 and 89 clients, respectively, with data leaks stemming from employee support systems and contractor portals—not from core customer-facing banking apps.

Beyond major banks, smaller institutions were hit too. Yegaram Savings Bank revealed around 40,000 customer records were exposed, and Hyundai Capital confirmed that data tied to 146 home-loan agents was compromised. BNK Busan Bank also reported leaks involving a small number of outsourced workers.

Possible AI Use and Investigation Status

Elements of the Shinhan breach suggest involvement of AI-based automation tools. Shared IP addresses were noted across attacks targeting multiple institutions, indicating potential coordination or shared infrastructure. But experts stress that no single attacker has been linked conclusively across all incidents. Such evidence does not yet paint a full picture of AI conducting independent attacks.

Investigative efforts are underway to identify the exact entry points for each breach. Early findings show that intrusions often occurred through loan-agent websites or staff support systems rather than customer-facing apps. Despite extensive leaks, there’s no indication that financial transaction systems were compromised—customer-facing platforms remain intact so far.

Government Response and Sector-wide Implications

President Lee was briefed on the unfolding breaches and instructed officials to treat the situation with gravity. He has mandated sweeping security audits across banks and card companies to ensure all vulnerable systems are identified and fixed.

The incidents highlight how supporting infrastructure—such as internal operational systems—can become a weak link, even without direct compromise of the main customer interfaces. Agencies are now scrutinizing the security posture of these backend systems.

These breaches are taking place amid growing concern over the Korean Leaks campaign, which previously targeted the country’s financial sector via compromised third-party service providers. Though that earlier campaign is not confirmed to be related, it adds context to the current outbreak.

Analysis:This wave of breaches underscores the evolving attack surface for financial institutions. The fact that entry points have been internal systems or third-party services—not the core banking apps—shows that adversaries are seeking less obvious vulnerabilities. The involvement of AI-based tools, whether in automation or reconnaissance, could mark a new phase in attack sophistication. Going forward, we’ll need to watch how regulators strengthen oversight of not just public-facing cybersecurity, but also internal operational security, employee systems, and third-party vendor risk. The lessons learned here may reshape how financial cybersecurity strategies evolve in South Korea—and globally.