South Korean President Lee Jae Myung has ordered a thorough investigation into a series of personal data leaks and cyberattacks affecting banks, financial companies and public agencies, as authorities move to strengthen cybersecurity across the country’s financial sector.
The presidential office said on Sunday that Lee had called for a comprehensive investigation and measures to prevent further incidents following a series of breaches reported by financial institutions.
The latest developments have prompted an intensified response from South Korea’s Financial Services Commission, which held an emergency meeting with financial industry associations, regulators and executives from affected institutions on Sunday.
The meeting was brought forward from October 7 after additional breaches were reported at second-tier financial institutions, according to South Korean media reports.
The regulator had already held an emergency meeting on Friday after several financial institutions reported cyberattacks. Shinhan Bank reported a breach on September 30, while Hana Bank, KB Kookmin Bank and Woori Bank were also reported to have experienced cyber incidents.
The Financial Services Commission said authorities had begun on-site investigations following the Shinhan Bank incident and had expanded their inquiries to other reported cases.
At Sunday’s meeting, FSC Chairman Lee Eog-weon warned that the financial sector must respond with a high level of vigilance as authorities work to determine how the attacks occurred and whether they are connected.
The regulator has directed financial institutions to conduct comprehensive security checks, strengthen access controls and reduce unnecessary external access to their systems.
Financial companies have also been instructed to improve measures for protecting customers and to share information about attack methods, internet protocol addresses and other potential threat indicators quickly across the industry.
The information-sharing measures are intended to help financial institutions identify similar attacks and prevent the spread of cyber threats across the sector.
The FSC said the recent incidents raised concerns about the possibility of similar attacks affecting other financial companies. Its October 2 emergency meeting had focused on sharing information about recent data leaks and attack methods and strengthening the sector’s collective response.
Authorities are also examining whether artificial intelligence could have been used in the attacks. FSC Chairman Lee said the possibility could not be ruled out and called for an approach in which AI is used to defend financial systems against AI-enabled attacks.
The comments point to a broader review of cybersecurity measures across South Korea’s financial industry as authorities investigate the recent breaches.
South Korean media have reported that investigators believe the attacks may have involved broad scanning of multiple financial companies for vulnerabilities rather than attacks against only one institution.
Attack traffic was reportedly traced to internet protocol addresses in several countries, including the United States, Japan, Singapore, Vietnam and Britain, according to data submitted by banks to lawmakers and cited by Yonhap News Agency.
See also: UNIZIK Introduces Digital System to Speed Up Graduation
The origin of the IP addresses does not by itself establish who carried out the attacks.
The breaches have raised concerns over the protection of customers’ personal information within South Korea’s financial system. In one previously reported incident, Hana Bank disclosed that personal information belonging to 89 customers had been exposed, although financial information was not compromised.
South Korea’s financial authorities have been strengthening cybersecurity requirements for major financial institutions, with the Financial Services Commission noting earlier this year that cybersecurity and digital bank-run risks were among areas requiring further improvement in the recovery and resolution plans of systemically important financial institutions.
The country’s main opposition People Power Party has also called for authorities to investigate whether North Korea could be involved, citing previous cyberattacks attributed to Pyongyang against South Korean financial institutions. No official finding linking North Korea to the latest breaches has been announced.
The investigation is expected to determine the methods used in the attacks, the extent of any data exposure and whether weaknesses at individual institutions or broader vulnerabilities across the financial sector contributed to the incidents.

