Security Guides
Data breaches at four Korean banks (about 65,000 people): income, loan limits and resident registration numbers leaked — what customers should do
Four Korean banks disclosed customer data leaks in October 2026. What leaked at each bank, and how to handle calls that quote your loan details.
For: customers of Shinhan Bank, KB Kookmin Bank, Hana Bank or Yegaram Savings Bank in South Korea, people with family in Korea, and organizations that expose staff-facing or partner-facing systems to the internet. This article is based on the banks' and Korean regulators' statements as reported by Korean media, and does not cover attack or scam techniques.
What customers should do today
Check whether you are affected — through official channels
Shinhan Bank added a menu to check whether your data leaked to its website and mobile app, and opened a dedicated hotline (1544-2946). KB Kookmin Bank says it contacted affected customers individually and set up a dedicated help center.
Hana Bank and Yegaram Savings Bank have also posted notices on their websites. To check, use an official app you installed yourself or a website address you typed yourself, not a link in a message.
If a caller talks about your loan, hang up and call back
Shinhan Bank's leak included annual income and loan limits as well as names and phone numbers. With that, a scam caller can say "your limit is X million won" and be right.
In Korea, scams by phone like this are called "voice phishing". If someone offers to refinance your loan or raise your limit, do not answer on the spot: hang up, look up the bank's main number yourself and call back. The basics of spotting this are in What is phishing?.
Never install apps, send money or read out codes on request
Banks do not ask you by phone or message to install a remote-control app, move money to a "safe account" or read out an authentication code. If you are asked for any of these, stop the conversation.
For phone-side protection, see Smartphone security basics.
Block new contracts in your name (Korean public services)
You cannot change your resident registration number. If yours leaked, use the services that stop others from signing contracts in your name.
- Credit transaction safe-block service (여신거래 안심차단): blocks new loans and new credit cards in your name in advance. Apply at a branch or in the app of a financial institution you already use
- The Financial Supervisory Service's system for people whose personal data has been exposed (pd.fss.or.kr): once you register, financial institutions apply stricter identity checks
- The identity-theft prevention service "M-Safer" (msafer.or.kr): alerts you when a new mobile phone line is opened in your name, or restricts new sign-ups
If you sent money, report it right away
If you sent money to a scammer, contact the police (112) or your bank immediately and ask them to stop the payment. You can also call the Financial Supervisory Service's help line (1332). The sooner you act, the better the chance of stopping it.
What happened (from the banks' and regulators' statements)
Between October 1 and 3, 2026, banks in South Korea announced one after another that customer data had leaked through unauthorized outside access. The following is what the banks and regulators said, as reported by Korean media.
| Bank | People | Main items leaked | Affected system (as described by the bank) | Announced |
|---|---|---|---|---|
| Shinhan Bank | ~25,000 | Name, phone number, annual income, loan limit, etc. For some, resident registration number (66) and CI (97) | Inquiry services including a mobile page for outside loan recruiters | Oct 1 |
| KB Kookmin Bank | 119 | Name, phone number, address, encrypted resident registration number, etc. (differs by person) | Mobile work-support system for employees | Oct 2 |
| Hana Bank | 89 | Resident registration number, name, address, email, phone, mobile, employer name | Operations support system (ODS) | Oct 2 |
| Yegaram Savings Bank | ~40,000 (estimate) | Name, date of birth, contact details, etc. | Server holding customer personal data | Oct 2–3 |
Connecting information (CI) is a value used in Korea to identify a person in place of the resident registration number. Unlike a password, you cannot change it.
Late Sept 29 to early Sept 30
The period in which unauthorized access to Shinhan Bank's services reportedly took place.Sept 30
Shinhan Bank detects the leak and activates its emergency response, blocking outside IP addresses and suspending the affected services. Yegaram Savings Bank finds signs of access to and leakage from a server holding customer data. That night, KB Kookmin Bank becomes aware of possible leakage from abnormal outside access and blocks the server and access route.Oct 1
Shinhan Bank announces the leak of about 25,000 people's data and posts an apology from its chief executive on its website. The Financial Supervisory Service begins an emergency on-site investigation of Shinhan Bank, according to reports.Oct 2
KB Kookmin Bank (119 people) and Hana Bank (89 people) announce leaks. The Financial Services Commission holds an emergency meeting with the Financial Supervisory Service, the Financial Security Institute and major banks and card companies.Oct 2–3
Yegaram Savings Bank announces on its website a leak of about 40,000 people's data (estimate).
- Transactions
- Shinhan, KB Kookmin and Hana say the affected systems are separate from transaction systems and no transaction data such as transfers leaked
- Compensation
- Shinhan, KB Kookmin and Hana will fully compensate actual losses. Yegaram Savings Bank will support relief procedures where needed
- Regulators
- The Financial Supervisory Service is carrying out on-site investigations. The Financial Services Commission ordered financial firms to review all internet-facing IT systems, cut unnecessary data exposure and tighten authentication and access control, and to report the results
- Other banks
- BNK Busan Bank reportedly leaked data on 11 staff of an outside development contractor, not customers. Woori Bank and NH NongHyup Bank were reportedly attacked, with no leak confirmed
- Cause
- Shinhan Bank says an outside party reached some services by an abnormal method that bypassed authentication. Yegaram Savings Bank says it found signs of access through a vulnerability in an outside software product. No common cause across the four banks has been officially announced
About reports of an 'AI attack'
Some media reports say AI-based tools may have been used in the attacks. These reports mainly cite the views of security experts; as of October 3, 2026, it is not a cause the banks or regulators have officially confirmed. This site does not speculate on the cause.
Why a caller who knows your real figures still should not be trusted
Many people assume that "if they know my loan limit and income, they must be from the bank", because only the bank was supposed to know those figures.
After Shinhan Bank's leak, that assumption no longer holds. Annual income and loan limits leaked together with names and phone numbers, so a scam caller can quote the right figures.
Not proof the call is genuine
- They quote your income or loan limit correctly
- They know your name, date of birth and address
- They give the bank's name and the caller ID looks similar
What you can check yourself
- Hang up, call the main number you looked up, and see if you hear the same thing
- See whether the same notice appears in the official app
- Notice whether you are being asked to send money, install an app or give a code
What is still unknown
As of October 3, the exact number and scope at Yegaram Savings Bank, how each bank was breached, and whether the leaked data has been misused have not been announced. The Financial Services Commission is reported to have scheduled another meeting for October 7. We will update this article when there is news.
For people who run financial or other systems
The affected systems the banks described were not customer-facing online banking but an inquiry page for loan recruiters, an employee mobile work system and an operations support system. The Financial Services Commission's order also targets "internet-facing systems". The lesson from this case is the peripheral systems that tend to get less attention than the main customer service.
Put staff and partner systems on your list of internet-facing systems
When you list the systems reachable from the internet, include not only customer services but also employee mobile work systems, pages for contractors and recruiters, and test servers.
How to build the list is covered in Security inventory checklist. A system that is not on the list never gets reviewed.
Make inquiry services return only what the job needs
What leaked at Shinhan Bank was income and loan limits that an inquiry service could return. Review each item an inquiry screen returns; drop items the user's job does not need, or show them partly masked.
The flaw where changing a lookup number shows someone else's data is explained in IDOR (broken authorization).
Add multi-factor authentication and lookup limits to peripheral systems
Systems that staff or contractors use from outside need a second check on top of the password (multi-factor authentication). See Choosing multi-factor authentication.
As a first step, set a per-account, per-hour limit on lookups and alert someone when an account reaches 80% of it. That catches lookup volumes no human user would produce.
Sources (public record)
The facts in this article are based on the public sources below. Each bank's notice is on its official website. We have not speculated on unpublished details or causes.
- Shinhan Bank (apology and leak-check menu) — shinhan.com
- Asia Economy, on Shinhan Bank's leak of about 25,000 customers (Oct 1, 2026) — view.asiae.co.kr
- Hankook Ilbo, on the FSS emergency on-site investigation (Oct 1, 2026) — hankookilbo.com
- Newsis, roundup of counts and items by bank (Oct 2, 2026) — newsis.com
- Newspim, on Hana Bank and Busan Bank (Oct 2, 2026) — newspim.com / newspim.com (roundup)
- EBN, on KB Kookmin Bank's 119 customers (Oct 2, 2026) — ebn.co.kr
- Korea JoongAng Daily, on KB Kookmin Bank (Oct 2, 2026) — koreajoongangdaily.com
- Korea Economic Daily, on the FSC emergency meeting (Oct 2, 2026) — hankyung.com
- Kyunghyang Shinmun, on Yegaram Savings Bank (Oct 3, 2026) — khan.co.kr / Financial News — fnnews.com
- Daum, on Shinhan Bank's statement (Oct 1, 2026) — v.daum.net
- Identity-theft prevention service — M-Safer (msafer.or.kr) / Financial Supervisory Service — personal data exposure registration
Update history
2026-10-03: First version, based on the banks' statements of October 1–3 and the Financial Services Commission's emergency meeting of October 2. We will update when counts or causes are announced.
Read next
- Other Korean cases this year: TVING (streaming) data breach / CHAEVI (EV charging) data breach
- Defending against impersonation: What is phishing? / Smartphone security basics
- For operators: Security inventory checklist / Choosing multi-factor authentication
- Other 2026 cases: Data breaches and cyberattacks in 2026
FAQ
QWhich banks were affected, and how many people?
According to the banks' statements as reported by Korean media, Shinhan Bank about 25,000 people, KB Kookmin Bank 119 people, Hana Bank 89 people and Yegaram Savings Bank about 40,000 people (an estimate; the exact number and scope are still being checked). Separately, BNK Busan Bank was reported to have leaked data on 11 staff of an outside development contractor, not customers.
QWhat was leaked?
It differs by bank. At Shinhan Bank: name, phone number, annual income, loan limit and other loan-application information; for some customers also resident registration numbers (66 cases) and connecting information (CI, an identifier used for identity verification in Korea; 97 cases). At KB Kookmin Bank: name, phone number, address, encrypted resident registration number and more (items differ by person). At Hana Bank: seven items — resident registration number, name, address, email address, phone number, mobile number and employer name. At Yegaram Savings Bank: name, date of birth, contact details and more.
QIs the money in my account safe? Were my PINs leaked?
Shinhan, KB Kookmin and Hana say the affected systems are separate from internet and mobile banking, and that no transaction data such as transfers was leaked. None of the banks has announced a leak of account passwords or PINs. The bigger risk is phone scams that use the leaked data.
QWere all four attacks carried out by the same attacker?
As of October 3, 2026, neither the banks nor the regulators have announced a common cause or a single attacker. Some media reports say AI-based attack tools may have been used, but this is not a cause the banks or regulators have officially confirmed. Yegaram Savings Bank says it found signs of access to its server through a remote vulnerability in an outside software product.
QHow can I check whether I am affected?
Shinhan Bank added a menu to its website and mobile app to check whether your data leaked, and opened a dedicated hotline (1544-2946). KB Kookmin Bank says it contacted affected customers individually. For the other banks, check the notice on the official website and the dedicated help line. Use the official app or a website address you typed yourself, not a link in a message you received.
QWill I be compensated if I suffer a loss?
Shinhan, KB Kookmin and Hana say they will fully compensate customers for actual losses caused by the leak. Yegaram Savings Bank says it will check any damage and support relief procedures where needed.