my timesThe Korea Times
  1. Business
  2. Banking & Finance

AI hacking fears spread to brokerages, insurers, card issuers

Listen

Summary

Brokerages, insurers and credit card issuers in South Korea are checking for cyber weaknesses after suspected AI-assisted attacks breached seven financial firms since the beginning of October. The affected firms are Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. No data leaks have been confirmed at brokerages, insurers or card issuers, but regulators suspect attackers scanned multiple companies for vulnerabilities.


Key Facts

  • The Financial Supervisory Service identified about 30 IP addresses associated with the attacks across multiple countries and territories, including the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, Sweden, Germany and Korea.
  • Reviews are focusing on identity verification and access controls after indications that attackers exploited business support systems and information lookup services used by employees and loan agents.
  • The attacks occurred during October’s extended holiday period, when smaller firms had relatively limited security staffing.
  • The FSS instructed financial firms to identify externally accessible IT infrastructure, assess vulnerabilities, take corrective action and verify that associated IP addresses had been blocked.
By Jun Ji-hye
  • Published Oct 6, 2026 2:50 pm KST
ATMs belonging to major banks are installed in Seoul, Monday. Yonhap

ATMs belonging to major banks are installed in Seoul, Monday. Yonhap

Brokerages, insurers and credit card issuers are stepping up security measures and checking for potential breaches after suspected artificial intelligence (AI)-assisted cyberattacks stole personal data from banks, savings banks and a capital finance company, according to industry officials, Tuesday.

Breaches have been reported at seven firms since the beginning of this month — Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. The incidents suggest the attacks, first reported in the banking sector, are having a broader impact.

Attempted intrusions detected across several parts of the financial sector have led regulators and industry officials to suspect that the attackers were scanning a broad range of companies for weaknesses rather than pursuing a single target.

Further cases may come to light, they warned, noting that smaller firms have relatively limited security staffing and that the attacks were timed during October’s extended holiday period.

At some brokerages, staff responsible for security reportedly worked through the long holiday weekend to conduct internal reviews.

“We have not identified any data leaks in the brokerage industry so far, but we are staying alert and carrying out further checks,” an official at a Seoul-based securities firm said.

Insurers have also reported no confirmed leaks or system intrusions linked to the attacks but continue to monitor for and block potential threats.

“We work closely with the financial authorities to share threat information, including IP addresses associated with breaches,” an official at a Seoul-based insurance company said.

Card issuers, for their part, are conducting their own inspections, paying particular attention to IT infrastructure and services accessible from outside their networks.

Reviews are focusing on identity verification and access controls following indications that the attackers exploited weaknesses in business support systems and information lookup services used by employees and loan agents.

The digital risk analysis team at the Financial Supervisory Service (FSS), the financial watchdog, has identified about 30 IP addresses associated with the attacks across multiple countries and territories including the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, Sweden, Germany and Korea.

The attacker may have used IP addresses in different locations to obscure their trail while searching financial companies’ systems for exploitable weaknesses. The location of an IP address alone does not establish the attacker’s nationality or the actual source of an attack, according to authorities.

Regulators have circulated these IP addresses and security guidance to firms across the industry. Companies have been instructed to check externally accessible IT assets and services for vulnerabilities and verify that the addresses have been blocked.

In a written notice, the FSS called on each firm to identify its externally accessible IT infrastructure, assess vulnerabilities and take corrective action. It also urged companies to review authentication, authorization and validation controls in systems that attackers could exploit to gain entry.

Read More

  • Police launch probe into recent cyber attacks at financial firms
  • AI-powered attacks on banks expose technological lag in Korea's financial cyber defenses
  • Shinhan, Kookmin, Hana data breaches fuel concerns over AI-powered cyberattacks in financial sector


Explore More

  • Q.

  • Q.

  • Q.