Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-06 · updated: 2026-10-06 · tags: [incident, financial-services] · confidence: medium · severity: low · affected_sectors: [financial-services] · au_impact: true

South Korean President Lee Jae Myung ordered a thorough investigation into a series of data breaches at seven financial-services firms — including Hana Bank, Woori Bank, Shinhan Bank and Yegaram Savings Bank — that exposed the personal data of thousands of customers. According to local media, authorities found the same attacker's IP address across all the breached firms, raising the prospect of a single coordinated campaign; the Financial Services Commission called the companies to an emergency meeting on Friday, ordering them to inspect their system defences, with chairman Lee Eok-won saying "we cannot rule out the possibility of attacks using AI." The president's office said he was briefed and directed officials to conduct a thorough investigation "with a grave awareness of the seriousness of the matter." Why it matters: a coordinated, single-operator credential campaign spanning multiple major banks — escalated to presidential level and framed by the regulator as potentially AI-tooled — is a leading indicator of AI-accelerated identity and credential attacks against the financial sector that regulators elsewhere, including APRA-supervised institutions in Australia, are explicitly planning against.

Attribute Detail
Sector Financial Services
Date 2026-10-06
Source Finextra
Reliability Tier 2