Attackers unidentified in 16 of 18 reported hacks on South Korean financial firms
A lawmaker cited regulator data on suspected overseas attacks since 2024 as South Korean authorities respond to a separate series of bank data leaks.
South Korean financial firms reported 18 suspected overseas hacking attacks from 2024 through October 8, but the attackers were identified in only two, opposition lawmaker Song Eon-seok said in Seoul on October 9, citing Financial Supervisory Service data. The figures show how much remains unknown about the reported intrusions as regulators respond to a separate series of bank data leaks.
The tally covers attacks reported by financial companies, according to Yonhap News Agency’s account of Song’s report. It does not establish that every incident exposed customer information or caused financial loss. The underlying regulator dataset was not available in the published material, so the figures and the classification of the cases remain attributable to the data Song cited.
What the 18 reported attacks show
Of the 16 cases in which attackers remained unidentified, 13 were linked to internet protocol addresses believed to be overseas. The countries of origin were unknown in three cases. Addresses associated with the cases included locations in China, the United States, Bulgaria and Vietnam, according to Yonhap’s report of the figures.
Those address locations are limited evidence about attribution. Yonhap cautioned that an IP address does not necessarily show where an attacker is physically based. Song called for an AI-based defense system and technology to identify attackers, saying IP addresses can be concealed or disguised. His proposal is a call for action; the report did not establish that such a system would resolve the unidentified cases.
The two identified cases named in the report involved ransomware groups. Yonhap said the international group GUNRA attacked Seoul Guarantee Insurance in July 2025, disrupting its operations for 64 hours. It also reported an April 2026 attack on Baro Savings Bank by INC Ransom. The report did not provide comparable accounts of losses or data exposure across all 18 cases.
How recent bank data leaks fit the picture
The newly cited tally comes after a separate cluster of attacks on South Korean banks. In an October 2 statement, the Financial Services Commission said a September 30 information leak at Shinhan Bank was followed by cyberattacks affecting KB Kookmin Bank and other financial companies. It convened an emergency meeting with the Financial Supervisory Service, the Financial Security Institute, banks, card companies and industry associations to discuss the threats and the sector’s response.
Yonhap reported on October 2 that Shinhan Bank had disclosed a leak affecting about 25,000 customers, including names, telephone numbers and annual income information. Its sources suspected overseas attackers using advanced AI tools; that was a reported suspicion, not a final attribution. Yonhap also said a police cyberterror-response division had begun a preliminary inquiry into the series of bank hacks.
Hana Bank disclosed that information on 89 customers, including resident registration numbers, names, addresses and telephone numbers, had leaked in a hacking attack, Yonhap reported. The bank apologized and pledged to work to prevent a recurrence. Yonhap said Woori Bank and NH Nonghyup Bank had faced similar attempted attacks but blocked unauthorized access, with no personal-information leaks reported in those incidents at the time.
The October 2 account is a snapshot of what was known then, not a complete accounting of the bank incidents as of October 9. The available reporting does not establish how many, if any, of those incidents are included in the 18-case tally. Nor does the tally show how many of its reported attacks resulted in confirmed customer-data theft.
What regulators have asked financial firms to do
The Financial Services Commission said authorities began on-site investigations after receiving reports of the recent incidents and shared threat information, including attacker IP addresses and methods, with relevant agencies. It directed firms to inspect systems and services exposed to the internet, examine authentication and access controls, and close routes that unnecessarily expose information or permit unauthorized access.
Earlier ransomware cases and unresolved exposure
The concern predates the latest bank incidents. Aju Press reported in August 2025 that Financial Supervisory Service examiners inspected Seoul Guarantee Insurance after a ransomware attack disrupted parts of its systems. It also reported scrutiny of Welcome Financial Group subsidiaries following an attack on its lending affiliate Welrix F&I Loan. The inspections show that regulators had previously examined both system disruption and possible exposure of consumer information.
Welcome Financial Group said at the time that it had not confirmed any compromise of personal information and maintained that the Welrix breach affected meeting materials rather than customer data, according to Aju Press. The outlet also reported a ransomware group’s claim that it had taken more than one terabyte of internal files. That claim did not establish the amount taken or whether customer records were among the files.
Sources and context
- Attackers unidentified in most hacking attacks on financial firms: lawmakerYonhap News Agency
- 최근 발생하는 금융권 침해위협에 면밀히 대응해 나가겠습니다. - 금융위원회 사무처장 주재 「긴급 상황대응 회의」 개최Financial Services Commission of South Korea
- (2nd LD) Regulator instructs financial firms to check security systems over series of cyberattacks on banksYonhap News Agency
- Korean financial regulator inspects firms hit by ransomware attacksAju Press
AI-assisted article checked against the listed sources. NewsJaws did not conduct interviews or attend the reported events.
Topics
About NewsJaws Desk
AI-assisted reporting and explainers reviewed against the linked source documents. No claim of on-scene reporting or original interviews.