South Korea’s financial regulator has ordered every bank, insurer, card issuer, savings bank, securities firm and fintech in the country to run emergency security checks. The order followed a South Korea bank data leak wave that reached six financial firms in five days. The Financial Services Commission set no public deadline for the checks.
The order applies only to financial companies licensed in South Korea. It does not reach the overseas subsidiaries of Korean banks, and it creates no obligation for firms in other markets.
Which Firms Reported Leaks, and How Many Customers
Six South Korean financial companies disclosed intrusions between 30 September and 4 October 2026, and the published customer counts range from 89 people to about 40,000.
| Firm | Reported scale | Disclosed |
|---|---|---|
| Shinhan Bank | About 25,000 customers | 1 October 2026, incident dated from 30 September |
| Yegaram Savings Bank | About 40,000 customers | Early October 2026, exact date not published |
| Hyundai Capital | 146 housing-loan brokers | Early October 2026 |
| KB Kookmin Bank | More than 100 customers | Found during an internal review |
| Hana Bank | 89 customers | 2 October 2026 |
| BNK Busan Bank | Not separately disclosed | 3 October 2026 |
The lists published by different outlets do not fully agree. The Korea Herald and the Seoul Economic Daily name BNK Busan Bank among the affected lenders; Reuters instead listed Woori Bank. Neither bank’s figure has been published, and the discrepancy has not been resolved by the regulator.
The exposed fields reportedly include resident registration numbers — the national identity number used across South Korean banking — alongside names, addresses and phone numbers. Shinhan’s leak was reported to involve names, phone numbers and annual income. The regulator has not published a confirmed field-by-field breakdown for each firm. The exposure of identity fields held by a financial company is the same category of harm set out in our report on the Revolut data breach.
What the Regulator Ordered Financial Firms to Do
The Financial Services Commission set out six required actions, reported by the Seoul Economic Daily from the 4 October meeting.
- Identify every IT asset and service reachable from outside the firm’s own network.
- Run full security reviews covering vulnerabilities, authentication, access controls and intrusion detection.
- Block outside access as the default policy, except where it is “indispensable for providing consumer services”.
- Cut access rights and the information any account can view to the minimum necessary.
- Establish the scope of the data already leaked and the potential harm to customers.
- Self-inspect and report the results to regulators.
At an earlier emergency response meeting on 2 October 2026, chaired by FSC Secretary General Shin Jin-chang, the banking and credit-card sectors had already been told to “conduct comprehensive checks of all IT systems accessible from outside their networks”. The FSC’s own Korean-language press office published a notice of that meeting on 2 October 2026. Its English-language press release page carried nothing on the incidents as of 5 October 2026, so non-Korean readers are working from news reports rather than from the regulator’s own English text.
Who the Order Covers
The 4 October meeting widened the instruction from banks and card firms to the whole licensed financial sector. FSC Chairman Lee Eog-weon chaired it at the Seoul Government Complex and summoned the industry associations for:
- Banking: commercial and regional banks.
- Financial investment: securities companies.
- Insurance: life and non-life insurers.
- Specialised credit finance: card issuers and instalment or leasing lenders.
- Savings banks and mutual finance: smaller deposit-taking and co-operative lenders.
- Virtual assets and fintech: digital-asset operators and payment companies.
Chief executives of the affected companies were also called in. Chairman Lee said that “financial security goes beyond protecting computer systems of individual companies — it is the foundation of trust and stability”, and, in a statement after the meeting, that “the entire financial sector should carry out swift and thorough security inspections”.
Separately, President Lee Jae Myung ordered on 4 October 2026 what Reuters described as “a thorough investigation and response measures over recent personal data leak incidents at banks, finance companies and public agencies”, widening the inquiry beyond the financial regulator to public bodies.
How the Attackers Got In
The intrusions did not go through core banking systems. The Seoul Economic Daily reported that the attacks targeted external web pages and servers used by loan brokers and by employees for work convenience, where basic security measures were inadequate. The Korea Herald identified a loan agent service and an employee mobile work-support system among the entry points.
The regulator’s working picture is of opportunistic scanning rather than a single targeted raid. Reuters reported that the attackers appeared to have scanned many institutions rather than singling one out, and that attack traffic came from internet addresses in the United States, Japan, Singapore, Vietnam and Britain. Traffic origin does not establish where an attacker is.
The FSC, the Financial Supervisory Service and the Financial Security Institute are carrying out on-site inspections, and threat intelligence has been shared with the Korea Internet and Security Agency. Our earlier report on the AI agent security guidelines drafted after a 700-agent intrusion covers the wider supervisory debate about automated attacks.
What Has Not Been Established
Several of the most-asked questions have no answer on the public record as of 5 October 2026.
- Who was responsible: authorities say they have not determined whether one actor coordinated the breaches. Opposition lawmakers have called for possible North Korean involvement to be investigated; that is a request for inquiry, not a finding.
- Whether AI was used: the FSC said it could not rule out artificial intelligence being used in the attacks, and Chairman Lee called for an approach in which “AI attacks” are “defended by AI”. No technical evidence has been published either way.
- The deadline: no completion or reporting date for the security checks has been published.
- Penalties: no sanction for firms that fail the checks has been announced.
- Compensation: the regulator says it is overseeing customer protection and compensation, but no scheme, amount or claims process has been published. Affected customers are being notified by their own bank or lender, which remains the official channel for confirming whether an individual account was involved.
Why Searches Show a Figure of 104 Million
Search results for South Korean bank data leaks are dominated by a much larger, much older event, and the two should not be confused.
The figure of about 104 million compromised credit card accounts belongs to the 2014 breach at KB Kookmin Card, Lotte Card and NH Nonghyup Card, long described as South Korea’s worst personal data leak. It prompted a government review of how widely resident registration numbers are used. The 2026 incidents described above involve a far smaller published total across six firms, and a different set of entry points.
Frequently Asked Questions
What Happened in the South Korea Bank Data Leak?
Six South Korean financial firms — Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Hyundai Capital and Yegaram Savings Bank — disclosed customer data leaks between 30 September and 4 October 2026. The entry points were external systems used by loan brokers and staff, not core banking platforms.
Which South Korean Banks Were Affected?
Shinhan Bank, KB Kookmin Bank, Hana Bank and BNK Busan Bank are named by the Korea Herald and the Seoul Economic Daily, along with Hyundai Capital and Yegaram Savings Bank. Reuters listed Woori Bank in place of BNK Busan, and the regulator has not published a single confirmed list.
How Many Customers Were Affected?
The published counts are about 25,000 at Shinhan Bank, about 40,000 at Yegaram Savings Bank, more than 100 at KB Kookmin Bank, 89 at Hana Bank and 146 housing-loan brokers at Hyundai Capital, as of 5 October 2026. No figure has been published for BNK Busan Bank, and the totals may change as inspections continue.
What Did South Korea’s Financial Services Commission Order?
On 4 October 2026 it ordered all licensed financial firms to map their externally reachable systems, run full security reviews, block outside access by default except where indispensable for consumer services, minimise access rights, establish the scope of leaked data and report the results. No deadline was published.
Does the Order Apply Outside South Korea?
No. It applies to financial companies licensed in South Korea. It does not create obligations for firms in other markets or for the overseas subsidiaries of Korean banks.
Was the South Korea Bank Data Leak Caused by AI?
That has not been established. The Financial Services Commission said it could not rule out the use of artificial intelligence in the attacks, but no technical evidence has been published confirming or excluding it.




