For most customers, the immediate concern was whether their money was still there. Few cared to change their passwords or other account details, let alone withdraw their money.
The breaches exposed a gap between banks’ heavily guarded transaction systems and the employee and partner services supporting them.
Shinhan, KB Kookmin and Hana spent nearly 124 billion won ($92 million) on cybersecurity last year, yet attackers penetrated those peripheral systems and stole personal information.
Cho, a resident doctor in his 30s, checked his account after hearing the morning news.
“All I needed to know was if my money was still there,” he said.
Hyun, a welfare center worker in her 30s, learned of the breach through a banking app notice.
“I was worried about whether my money was safe,” she said. “I'm also wondering whether I should change my banking app and account passwords.”
Authorities said last Thursday that no direct financial losses had been reported, but warned that stolen information could be used in phone scams and fraudulent text messages.
The banks’ main internet and mobile banking transaction systems were not breached. The attacks instead exposed customer information through loan inquiry pages, mobile employee tools and an outside sales-support system.
Shinhan reported that 25,727 customers’ information was exposed. KB Kookmin reported 119 affected customers and employees, while Hana reported 89 customers.
The pattern raises questions about whether banks gave these smaller systems the same scrutiny as their core banking services.
According to Financial Supervisory Service data submitted to People Power Party lawmaker Lee Yang-soo, Hana spent 53 billion won on information security in 2025, KB Kookmin 39.3 billion won and Shinhan 31.68 billion won.
The figures cover personnel, infrastructure and other services, without showing how much went toward the systems that were compromised.
At KB Kookmin, almost 68 hours passed between the first intrusion and the bank recognizing the incident.
Attackers accessed RM Agent and PB Agent, mobile support tools for employees, from late Sept. 27 until about 6 p.m. on Sept. 29. The bank recognized the incident around 7 p.m. the following day — roughly 25 hours after the attacks had stopped.
The breach affected 99 customers and 20 employees, according to material submitted to the National Assembly. Exposed information included names, mobile phone numbers and some encrypted resident-registration numbers.
Shinhan detected suspicious activity about 15 hours after the first access on the evening of Sept. 28. Blocking an IP address did not end the attack: intruders continued targeting six services, switching addresses as the bank blocked them.
The attackers repeatedly entered different customer numbers to locate valid records, using IP addresses traced to eight countries. The bank made its final IP block shortly after midnight on Sept. 30.
Exposed data included loan application information, names, phone numbers and some identity-verification information.
At Hana, attackers targeted ODS, a system employees use to process customer paperwork outside branches. The attack lasted more than 10 hours on Sept. 30, and the bank identified the leak early on Oct. 2 — about 42 hours after the intrusion began.
Hana said the server was separated from its transaction systems and that no account balances or transaction histories were exposed.
The breaches came despite established security programs and, in Shinhan’s case, top regulatory assessment scores.
Shinhan said in its half-year report that it had received an S grade with 100 points in the Financial Services Commission’s assessment of personal credit information management and protection, its sixth consecutive year with the top grade. It also holds domestic and international information-security certifications.
KB Financial Group opened a cybersecurity center in January, pairing teams that simulate attacks with teams responsible for monitoring and defense. Hana says its integrated security monitoring center operates around the clock.
Regulators are now pressing firms to examine the less visible systems connecting banks with employees, contractors and loan brokers.
Following an on-site investigation launched after Shinhan’s Sept. 30 report, authorities shared attacker IP addresses and methods across the sector on Oct. 2. At a wider meeting on Oct. 4, the FSC and FSS ordered checks of all internet-facing systems, particularly authentication, access controls and vulnerabilities.
Firms were told to block unnecessary external connections, limit permissions for essential access and check whether support services unnecessarily stored or exposed personal credit information. Authorities also called for prompt customer notification, compensation for losses and protection against follow-on scams.
Banks and card companies were given until Tuesday to complete their reviews. Securities firms, insurers, savings banks and electronic financial businesses have until Thursday.
Authorities are examining whether AI helped automate the attacks, although its precise role remains unconfirmed. Regulators urged firms to strengthen AI-based defenses and adopt zero-trust security, which requires verification rather than assuming a user or device can be trusted.
Police said Tuesday they had formally opened a case under the Information and Communications Network Act and assigned a 28-member cyberterror investigation team.
For the time being, consumers are opting to sit tight.
“I haven't changed anything since,” said Lee, a consultant in their 50s. “I just thought the banks would strengthen security.”
A university student who declined to be named said he had heard little discussion of the breaches.
“I don't think the leaked information is likely to be mine,” he said.
Copyright ⓒ Aju Press All rights reserved.