Customer information leaked through loan inquiry and employee support systems at major banks
Hana Bank and BNK Financial Group reported data breaches Friday, extending a string of hacking incidents following customer information leaks at Shinhan Bank and KB Kookmin Bank.
Hana said hackers accessed its sales support system, known as ODS, exposing personal information belonging to 89 customers. The data included resident registration numbers, names, addresses, contact details and employer names.
"The system is separate from internet and mobile banking transaction systems," the bank said, adding that customers' financial transaction information had not been leaked.
Hana said it alerted the Financial Supervisory Service and other authorities Thursday after learning of hacking attempts at another financial institution. It blocked the IP address linked to the suspected intrusion, checked similar systems and activated emergency response teams. The bank is notifying affected customers and will fully compensate resulting losses under applicable rules.
BNK Financial separately reported that 11 records containing outsourced employees' personal information were leaked in a hacking incident, according to local reports.
The breaches at Hana, Shinhan and KB Kookmin involved loan inquiry or employee support systems.
Shinhan said Thursday that information belonging to about 25,000 customers had been leaked, after confirming the breach Wednesday. An attacker bypassed identity verification in a mobile inquiry service loan agents use to check application progress.
The exposed data included names, phone numbers, annual income and calculated loan limits, along with 66 resident registration numbers and 97 CI identifiers used for online identity verification. Shinhan said it blocked external IP addresses and suspended the service.
KB Kookmin said Friday morning that data on 119 customers, including names, phone numbers, addresses and resident registration numbers, had been leaked through an employee mobile support system. The bank detected a possible breach Wednesday night and blocked the affected server and access routes. It said customer banking transactions were unaffected and pledged compensation for resulting losses.
Following the Shinhan and KB disclosures, the Financial Services Commission convened an emergency meeting Friday with the FSS, security officials and industry representatives. Authorities ordered checks of externally accessible systems and called for stronger authentication, tighter access controls and faster sharing of threat information. They also vowed to investigate the attacks and swiftly draw up measures to improve the regulatory framework.
Possible use of artificial intelligence in the attacks is also under scrutiny. Security analysts found traces of an AI penetration-testing tool called ARTEX AI on a server suspected of being linked to the Shinhan attack. Neither the bank nor the financial authorities have officially confirmed whether the tool was used in the breach, according to local reports.
jwc@heraldcorp.com