South Korea’s Lee Orders Investigation, Countermeasures Following Data Leaks at Financial, Public Institutions

Key Takeaways

  • President Lee Jae-myung has ordered a comprehensive investigation and immediate countermeasures following a series of AI-driven data breaches affecting major financial and public institutions.
  • Over 25,000 customers at Shinhan Bank (055550) and approximately 40,000 at Yegaram Savings Bank had personal information compromised, including annual income and borrowing limits.
  • The Financial Services Commission (FSC) has summoned CEOs from across the banking, insurance, and fintech sectors for an emergency meeting on October 4, 2026.
  • New regulations now impose punitive fines of up to 10% of total revenue for companies found negligent in protecting personal data.
  • Authorities suspect the use of advanced AI agents to exploit vulnerabilities in external-facing IT systems, such as those used by loan solicitors.

South Korean President Lee Jae-myung issued a stern directive on Sunday, ordering a thorough probe into a wave of cyberattacks that have compromised the personal data of thousands of citizens. The Blue House stated that the president has demanded "unmanageable" penalties for institutions that neglect security to save costs, emphasizing that data is a national strategic asset in the age of artificial intelligence.

The crisis intensified as major lenders, including Shinhan Bank (055550), KB Kookmin Bank (a subsidiary of KB Financial Group (105560)), and Hana Bank, reported unauthorized access to their systems. Shinhan Bank confirmed that the leak involved sensitive details such as names, phone numbers, annual incomes, and withdrawal limits for roughly 25,000 clients.

The Financial Services Commission (FSC), led by Chairman Lee Eok-won, has accelerated its response by summoning the heads of all financial industry associations and affected CEOs to the Government Complex Seoul. This emergency summit aims to review the security frameworks of not only Tier 1 banks but also secondary institutions like Hyundai Capital and Yegaram Savings Bank, which have also reported recent breaches.

Cybersecurity experts believe the attackers utilized AI-powered agents to scan for vulnerabilities in mobile work support systems and services used by third-party loan recruiters. In response, the Financial Supervisory Service (FSS) has launched on-site inspections to determine if the attacks originated from a single coordinated group or multiple actors.

The government's hardline stance follows the recent implementation of the revised Personal Information Protection Act, which significantly raises the ceiling for administrative fines. Under the new rules, companies responsible for large-scale leaks can face penalties totaling 10% of their annual revenue, a move designed to force a shift from reactive to preventative cybersecurity investment.

Disclaimer: This article is for informational purposes only and does not constitute financial advice. We are not financial professionals. The authors and/or site operators may hold positions in the companies or assets mentioned. Always do your own research before making financial decisions.
Scroll to Top