Nine months of attacks exceed the entire 2025 total
South Korea's central bank and three state lenders recorded 1,024,478 hacking attempts between January and September 2026, exceeding the 934,858 attempts detected throughout 2025 by 89,620, or 9.6%. The institutions reported no successful breaches resulting from those attempts, even as separate attacks on commercial banks exposed customer information.
Contents
- Nine months of attacks exceed the entire 2025 total
- How quickly have detected attempts increased?
- Why IBK accounts for most of the activity
- Disruption is the most common recorded attack
- No reported breaches, but a narrower claim than complete safety
- What the AI attack warning actually established
- Commercial bank customers face confirmed exposure
- Security allocations are not the same as security spending
- Proposed investment and the wider vendor problem
- What remains unresolved
- Key Points
Figures submitted to People Power Party lawmaker Kang Min-kuk and disclosed on October 11 put the cumulative count at 4,986,964 attempts from 2020 through September 2026. Industrial Bank of Korea (IBK) accounted for 91.9% of that total, reflecting its extensive internet and mobile banking services for individual and corporate customers.
The distinction between attempted attacks and confirmed breaches is central to understanding the figures. A detected attempt does not establish that an attacker entered a system or stole information. Conversely, the absence of a successful intrusion in this dataset does not mean every associated service or outside provider escaped disruption or exposure.
Separate incidents illustrate that distinction. An intrusion into an outside training provider exposed information belonging to 186 Bank of Korea employees in May and June 2026. Commercial banks have also disclosed customer data leaks, prompting regulators to order inspections of systems accessible from the internet, stronger authentication and access controls, and greater sharing of attack methods and suspicious IP addresses.
The pressure extends beyond the number of attacks. Parliamentary disclosures describe security budgets that were not fully spent, uneven staffing at state lenders, and an emerging threat from artificial intelligence tools that can accelerate the search for vulnerabilities.
How quickly have detected attempts increased?
The annual figures show an uninterrupted rise since 2020. By September 2026, the count was already about 2.86 times the 358,800 attempts recorded during all of 2020. The comparison is especially striking because the latest period covers nine months rather than a complete year.
The sequence also shows that the increase did not begin with the latest commercial bank breaches:
- 2020: 358,800 attempts across the four institutions.
- 2021: 564,430 attempts.
- 2022: 585,563 attempts.
- 2023: 738,312 attempts.
- 2024: 780,524 attempts.
- 2025: 934,858 attempts. The Bank of Korea's Gyeonggi IT Center opened in October.
- January through September 2026: 1,024,478 attempts.
- October 11, 2026: The latest figures were disclosed through Kang.
Detected attempts measure activity encountered by security systems, rather than the number of individual attackers or successful compromises. Repeated automated requests can generate many detections. IBK's explanation also indicates that the scale of services exposed to outside users matters when comparing institutions.
There is a small numerical inconsistency in the published totals: the listed annual figures add up to 4,986,965, one more than the stated cumulative total of 4,986,964. That difference does not change the reported trend or the concentration of attempts at IBK.
Why IBK accounts for most of the activity
IBK recorded approximately 4.584 million attempts during the cumulative period. Korea Development Bank (KDB) followed with 399,379, while the Bank of Korea recorded 3,076 and the Export-Import Bank of Korea recorded 510.
IBK attributed its much larger count to internet and mobile services comparable in scale to those of commercial banks. Those services connect the lender to both personal and business customers, creating more opportunities for hostile traffic to reach publicly accessible systems.
The figures do not, by themselves, establish that IBK has weaker defenses than the other institutions. Its explanation concerns the volume of services and detected attempts, while the four institutions reported no resulting breaches in the cumulative dataset.
The Bank of Korea's Gyeonggi IT Center, which houses its main computing servers, recorded 145 attempts after opening in October 2025. That count concerns a particular facility and should not be treated as interchangeable with the central bank's total across systems and years.
Disruption is the most common recorded attack
Denial of service accounted for 2,275,006 attempts, or 45.6% of the cumulative total. Such attacks seek to make a service unavailable, for example by overwhelming it with requests or consuming the computing resources needed to serve legitimate users.
The next largest categories were information gathering, with 866,776 attempts; malware, with 475,026; and unauthorized access, with 456,783. Information gathering can involve probing systems to identify software, exposed functions or weaknesses. Malware is malicious software, while unauthorized access attempts seek entry without valid permission.
Those four categories total 4,073,591 attempts. They therefore do not account for every attempt in the cumulative figure, and a breakdown of the remaining categories has not been specified.
The prominence of denial of service explains why the consequences of an attack can extend beyond stolen information. A banking website or transaction service can become difficult to use even when an attacker does not gain control of an internal system.
Kang Min-kuk, the People Power Party lawmaker who released the figures, described the stakes for institutions handling public and corporate finance:
An attack on a state lender could disrupt financial systems at home and abroad and put sensitive government and corporate information at risk," Kang said. "We must build defenses against the surge in AI-powered cyberattacks and work with financial authorities to run cyberattack simulations.
No reported breaches, but a narrower claim than complete safety
The four institutions said the attempts counted from 2020 through September 2026 did not result in breaches. Separate disclosures, however, describe earlier disruption and an exposure involving a Bank of Korea contractor.
A distributed denial of service attack intermittently slowed access to the central bank's website in December 2023. In May and June 2026, an intrusion into an outside training provider's system exposed personal information belonging to 186 central bank employees. These incidents show why service disruption, an intrusion into a bank's own systems and an exposure at a vendor must be distinguished.
Another disclosure put the Bank of Korea's 2026 count at 136 attempts through October 2, compared with 30 during all of 2025. Internet accessible targets included its main website, economic statistics portal and electronic library. The central bank said it recorded no successful intrusions, disruptions or data leaks between the beginning of September and October 2.
The Export-Import Bank separately reported 283 attempts through October 5, compared with 36 in all of 2025. Of those 283, 272 came from overseas IP addresses. The address locations identify where traffic appeared to originate, not necessarily the nationality or physical location of the attacker.
That disclosure also said the lender detected 197 attempts over the preceding five years. Combined with the latest 283, this produces 480, rather than the 510 in the broader cumulative account. Different cutoffs or counting methods may explain the difference, but no reconciliation has been published in these accounts.
What the AI attack warning actually established
The Financial Security Institute held a financial AI security seminar for approximately 160 security officers on September 17. Documents obtained by Social Democratic Party lawmaker Han Chang-min described a case presented there as South Korea's first financial sector attack involving an AI agent.
An AI agent is software that can carry out a sequence of tasks using an AI model, rather than simply answer a question. In the case described at the seminar, an attacker instructed an agent based on DeepSeek to locate financial server programs.
The agent reportedly found and exploited vulnerabilities within a day, installed software allowing remote control, and searched internal servers. The targeted financial company blocked the attack before further malware could be installed. Its identity was not given.
The institute urged continuous monitoring of systems exposed to the internet, warning that inspections once or twice a year could miss this kind of activity. It also identified a weakness in assessment coverage: application programming interfaces, the connections through which websites and apps exchange data, are included in vulnerability checks, but financial companies select which systems to inspect.
Reports have linked the subsequent commercial bank incidents to AI tools. Authorities were still investigating the role of AI, however, including whether it automated parts of the attacks. President Lee Jae Myung said AI appeared to have been involved, but the exact methods had not been established. The seminar case demonstrates a reported capability, not proof that every recent breach used the same technique.
Commercial bank customers face confirmed exposure
Seven financial institutions were identified in the recent sequence of hacking incidents: Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital.
Shinhan disclosed that an unauthorized external party bypassed authentication on a service connected to lending and obtained personal and credit information associated with about 25,000 customers. Exposed details included names, telephone numbers, annual income and calculated borrowing limits.
Shinhan chief executive Jung Sang-hyuk apologized and pledged full compensation for losses linked to the incident. A Seoul law firm was recruiting affected customers for a proposed damages lawsuit, with intended claims of 100,000 to 300,000 won per participant. A filing date had not been announced.
At KB Kookmin, an attack on a mobile work support system compromised information belonging to 119 customers. Personnel from KB Kookmin, Hana, Hyundai Capital and Welcome Savings Bank had attended the September security seminar. Shinhan was represented by an officer from its financial group, while BNK Busan was not listed among attendees.
The attendance records show that several affected organizations received the warning shortly before their incidents. They do not establish which specific failures allowed each intrusion, or whether a particular preventive measure would have stopped it.
Security allocations are not the same as security spending
Data submitted by financial authorities to People Power Party lawmaker Park Sung-hoon showed that the 20 financial companies with the most frequent IT failures budgeted 438 billion won for information security in 2025 but spent 305 billion won. That is an execution rate of about 69.6%, leaving 133 billion won unspent.
Shinhan allocated approximately 45.3 billion won and spent 31.7 billion won, a reported execution rate of 69.9%. Its 2026 allocation was 40.5 billion won, about 10.6% below the previous year's budget. KB Kookmin allocated 67.6 billion won and spent 39.3 billion won, an execution rate of 58.1%.
Park Sung-hoon, the lawmaker who obtained the spending figures, framed investment as a matter of public confidence:
Inadequate security investment cannot be dismissed as a matter of management efficiency; it is a question of trust in the financial system.
State lender disclosures also point to uneven resources. KDB's security staff fell from 23 at the end of 2024 to 19 at the end of 2025, before recovering to 22 by June 2026. IBK had 46 dedicated security staff at the end of 2025, while the Export-Import Bank had nine.
A separate IBK staffing measure counted 72.5 internal and outsourced personnel, including 53.5 internal staff and 19 outsourced staff. That broader measure should not be treated as identical to the count of 46 dedicated staff. IBK's 2025 security investment was 66.1 billion won, or 15.1% of total IT investment.
KDB's budget figures contain a larger reporting discrepancy. The Korean figures put its security budget at 17.231 billion won as of the first half of 2026, down from 17.611 billion won in 2025. An English summary gives 172.31 billion and 176.11 billion won, ten times those amounts. Both describe a 2.2% reduction.
Proposed investment and the wider vendor problem
KB Kookmin is considering an information security budget above 100 billion won for 2027, alongside upgrades to intrusion detection, prevention systems and web firewalls. The proposal concerns the size of the budget, not a confirmed increase of 100 billion won.
Shinhan plans additional security investment and recruitment of AI security specialists and ethical hackers. Hana is reviewing a zero trust architecture, which requires access to be checked rather than automatically trusted because a user or device is inside a network. Woori is considering a budget increase above 20% and growth in its specialist workforce above 10%.
A state lender representative said banks conduct penetration tests from an attacker's perspective and plan to continue strengthening investment and inspections. Specific implementation deadlines for these measures were not announced.
Events outside banking demonstrate the exposure created by contractors and retained data. More than 100,000 users of a public sector ethics training platform had information exposed from an older system replaced in April 2025. A contractor had retained the old records rather than deleting them after the transition. The remaining records were subsequently deleted.
Oasis Security also reported suspected exposures involving Yoido Full Gospel Church and SaRang Church. The material associated with Yoido included about 960,000 member records and 330,000 donation records. Those record counts do not establish how many distinct people were affected. Both churches were investigating.
What remains unresolved
The principal unanswered questions concern how the recent commercial bank attackers gained access, how much AI contributed, and whether planned investment will translate into completed security work. No common technical explanation has been confirmed for all seven financial institutions.
The bank figures also need careful interpretation. Different reporting periods, rounded institutional counts and differing staffing measures limit direct comparisons. The reported absence of breaches among the four public institutions is meaningful, but it does not erase the separate evidence of website disruption and vendor exposure.
Regulators have directed financial firms to inspect externally accessible systems, strengthen authentication and permissions, and exchange threat information. Kang has called for simulated attacks and coordinated drills. The next practical test is whether those measures cover the actual services, interfaces and contractors through which sensitive information can be reached.
Key Points
- The Bank of Korea and three state lenders recorded 1,024,478 hacking attempts through September 2026, 9.6% above the full 2025 total.
- IBK accounted for 91.9% of the reported cumulative attempts since 2020.
- Denial of service was the largest attack category, with 2,275,006 attempts.
- The four institutions reported no breaches resulting from the counted attempts, while separate incidents involved disruption and a central bank training provider.
- Recent commercial bank incidents exposed information belonging to about 25,000 Shinhan customers and 119 KB Kookmin customers.
- Authorities were still investigating how AI was used in the recent attacks.
- Twenty financial companies spent 305 billion won of 438 billion won allocated for security in 2025.
- Several banks plan or are considering more investment, but firm completion dates have not been announced.






