South Korean president orders probe into data leaks across financial industry


South Korea's President Lee Jae Myung arrives to address the 81st United Nations General Assembly at UN headquarters in New York City, US, September 22, 2026. REUTERS/Eduardo Munoz

SEOUL, Oct 4 (Reuters) - South Korean President ⁠Lee Jae Myung ordered a thorough investigation and response measures over recent personal ⁠data leak incidents at banks, finance companies and public agencies, Seoul's presidential office ‌said on Sunday.

• Financial Services Commission (FSC) Chairman Lee Eog-weon convened an emergency meeting with financial industry associations, regulators and executives from affected institutions on Sunday, warning that the sector must respond with the highest level of vigilance, the ​FSC said in a statement.

• The FSC's Lee said ⁠authorities could not rule out the possibility ⁠that artificial intelligence was used in the attacks and called for an "AI attacks defended by ⁠AI" ‌approach, while also signalling broader upgrades to the financial sector's cybersecurity framework.

• Sunday's meeting came after similar talks on Friday, when the FSC said Shinhan Bank, KB Kookmin ⁠Bank and others had reported cyberattacks, while Yonhap news agency ​reported that Hana Bank and ‌Woori Bank had also suffered breaches.

• The banks could not immediately be reached ⁠for comment outside ​regular working hours on Sunday.

• The financial regulator said authorities had launched on-site investigations after Shinhan Bank reported a breach on September 30 and had since expanded probes into other reported incidents.

• The regulator ⁠directed financial institutions to carry out comprehensive security inspections, tighten ​access controls, minimise external system access and strengthen consumer protection measures.

• It also said attack methods, internet protocol addresses and other threat information would be rapidly shared across the industry to prevent ⁠further incidents.

• Yonhap news agency said regulators believe the attacks may have broadly scanned multiple financial companies for vulnerabilities rather than targeting a single institution.

• Attack traffic was reported to have originated from IP addresses across several countries including the United States, Japan, Singapore, Vietnam and Britain, ​Yonhap said, citing bank data submitted to lawmakers.

• Sunday's emergency ⁠meeting was brought forward from October 7 after additional breaches were discovered at second-tier financial institutions, ​according to multiple Korean media reports.

• The country's main opposition ‌People Power Party said authorities should also investigate ​the possibility of North Korean involvement, citing past cyberattacks attributed to Pyongyang against South Korean financial institutions.

(Reporting by Kyu-seok Shim; Editing by Christian Schmollinger and Sonali Paul)

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Others Also Read