SBS NEWS

News > Society

Realizing It Too Late... Financial Sector Hit by Successive Cyberattacks (Full Video)

Lee Hyun-jung

Published : Oct 3, 2026 11:04 PM

Video

 [Anchor]

Following four commercial banks, a secondary financial institution has also suffered a personal information leak due to a hacking attack. Simultaneous hacking attacks utilizing artificial intelligence are expanding the damage across the entire financial sector.

First, reporter Lee Hyun-jung will report.

[Reporter]

Hyundai Capital stated that personal information of 146 loan solicitors was leaked due to a hacking attack targeting the loan solicitor inquiry page.

Names, mobile phone numbers, and resident registration numbers were compromised.

An official from Hyundai Capital explained, "While reviewing overseas IP addresses shared by financial authorities that hacked Shinhan Bank, we discovered that the page in question was attacked on September 27." They added, "Yesterday (October 2), we immediately blocked the IP and the page, and formed a dedicated task force for incident response."

Yegaram Savings Bank also announced, "We confirmed that an unidentified hacker accessed a server containing customers' personal information on September 30, resulting in a leak of personal information."

It is estimated that the names, dates of birth, and contact information of approximately 40,000 customers were leaked.

It was determined that no access or attacks were made on the internal system.

Previously, personal information was leaked due to hacking at Shinhan, KB Kookmin, Hana, and BNK Busan Bank.

Woo-ri and NH Nonghyup Bank also experienced hacking attempts, but no damage has been identified so far.

According to an internal analysis report by Woori Bank obtained by SBS, nine access histories from three suspicious IP addresses were identified, but they were blocked by the firewall to prevent damage.

It has been confirmed that hacking occurred across multiple financial institutions using common IP addresses, and experts view these as attacks utilizing artificial intelligence.

[Professor Hwang Seok-jin / Dongguk University International Graduate School of Information Security: (It is estimated that they) scanned for vulnerabilities, made authentication attempts using stolen or leaked account credentials, and then used loopholes in identity verification or access control to access the system like normal users.]

As the damage grew, the Financial Services Commission decided to hold an emergency inspection meeting tomorrow at the Seoul Government Complex, summoning the heads of associations across all financial sectors and representatives of the financial companies where the incidents occurred.
 
---
 
[Anchor]

The problem is that amidst these sweeping hacking attacks, no one noticed them in time. This suggests that the attacks targeted vulnerabilities in security, and it is raised as a possibility that artificial intelligence itself may have designed the attacks.

Reporter Jung Seong-jin explains the details.

[Reporter]

Kookmin Bank, where personal information of 119 customers was leaked, first became aware of the incident at 7 PM on September 30.

It was already after the hacking attack had concluded.

The hacking lasted for over 42 hours from 11:19 PM on September 27 until the evening of September 29, two days later, but it was only realized 68 hours later.

Yegaram Savings Bank experienced its first hacking attack on September 18, but remained unaware of the hacking attempt for over 10 days.

As the hacking incident at Shinhan Bank—where personal information of some 25,000 people was leaked—became known and financial authorities launched a full-scale inspection, other financial companies belatedly learned of their data breaches.

When 10 IP addresses that hacked Shinhan Bank were shared with each financial company for verification, it was revealed that Hana Bank and Hyundai Capital had also been attacked from the same IPs.

In the process, it was also confirmed that sweeping hacking attempts had been made against Woori and Nonghyup Bank as well.

Because the targets of the hacking were loan solicitor systems or employee systems rather than the main systems used by customers, security was weak and detection appears to have been difficult.

The security industry suspects that AI was not only utilized in the hacking, but that AI may have even designed the attacks targeting vulnerabilities.

Artex AI, which is presumed to have been utilized in this hacking, is an autonomous penetration testing tool. It is suspected that an AI designed to patch hacking vulnerabilities was instead utilized as a hacking tool to pinpoint weak spots.

[Moon Jong-hyun / Director, Genians Security Center: If you try to access that side (the main site) directly, it's more likely to get caught in monitoring. So there might have been an AI collection phase that gathered information in advance, targeting areas with weaker security or slight vulnerabilities.]

As AI-based hacking attacks emerge as a realistic threat, experts point out that a comprehensive re-examination of security systems is necessary, covering not only core computing networks but also peripheral business systems.
 
(Photo: Lee Chan-su | Video Editing: Park Ji-in, Choi Hye-ran | Design: Kang Yoon-jung, Kim Ye-ji, Seo Seung)