Skip to content
>_ITDITDWeb Security Platform

Security Guides

Data breaches at four Korean banks (about 65,000 people): income, loan limits and resident registration numbers leaked — what customers should do

Four Korean banks disclosed customer data leaks in October 2026. What leaked at each bank, and how to handle calls that quote your loan details.

Published 2026-10-03 Updated 2026-10-03 Last verified 2026-10-03 11 min read

For: customers of Shinhan Bank, KB Kookmin Bank, Hana Bank or Yegaram Savings Bank in South Korea, people with family in Korea, and organizations that expose staff-facing or partner-facing systems to the internet. This article is based on the banks' and Korean regulators' statements as reported by Korean media, and does not cover attack or scam techniques.

What customers should do today

1

Check whether you are affected — through official channels

Shinhan Bank added a menu to check whether your data leaked to its website and mobile app, and opened a dedicated hotline (1544-2946). KB Kookmin Bank says it contacted affected customers individually and set up a dedicated help center.

Hana Bank and Yegaram Savings Bank have also posted notices on their websites. To check, use an official app you installed yourself or a website address you typed yourself, not a link in a message.

2

If a caller talks about your loan, hang up and call back

Shinhan Bank's leak included annual income and loan limits as well as names and phone numbers. With that, a scam caller can say "your limit is X million won" and be right.

In Korea, scams by phone like this are called "voice phishing". If someone offers to refinance your loan or raise your limit, do not answer on the spot: hang up, look up the bank's main number yourself and call back. The basics of spotting this are in What is phishing?.

3

Never install apps, send money or read out codes on request

Banks do not ask you by phone or message to install a remote-control app, move money to a "safe account" or read out an authentication code. If you are asked for any of these, stop the conversation.

For phone-side protection, see Smartphone security basics.

4

Block new contracts in your name (Korean public services)

You cannot change your resident registration number. If yours leaked, use the services that stop others from signing contracts in your name.

  • Credit transaction safe-block service (여신거래 안심차단): blocks new loans and new credit cards in your name in advance. Apply at a branch or in the app of a financial institution you already use
  • The Financial Supervisory Service's system for people whose personal data has been exposed (pd.fss.or.kr): once you register, financial institutions apply stricter identity checks
  • The identity-theft prevention service "M-Safer" (msafer.or.kr): alerts you when a new mobile phone line is opened in your name, or restricts new sign-ups
5

If you sent money, report it right away

If you sent money to a scammer, contact the police (112) or your bank immediately and ask them to stop the payment. You can also call the Financial Supervisory Service's help line (1332). The sooner you act, the better the chance of stopping it.

What happened (from the banks' and regulators' statements)

Between October 1 and 3, 2026, banks in South Korea announced one after another that customer data had leaked through unauthorized outside access. The following is what the banks and regulators said, as reported by Korean media.

~25,000
Shinhan Bank (resident registration numbers in 66 cases)
~40,000
Yegaram Savings Bank (estimate, still being checked)
119
KB Kookmin Bank (incl. encrypted resident registration numbers)
89
Hana Bank (7 items incl. resident registration number)
BankPeopleMain items leakedAffected system (as described by the bank)Announced
Shinhan Bank~25,000Name, phone number, annual income, loan limit, etc. For some, resident registration number (66) and CI (97)Inquiry services including a mobile page for outside loan recruitersOct 1
KB Kookmin Bank119Name, phone number, address, encrypted resident registration number, etc. (differs by person)Mobile work-support system for employeesOct 2
Hana Bank89Resident registration number, name, address, email, phone, mobile, employer nameOperations support system (ODS)Oct 2
Yegaram Savings Bank~40,000 (estimate)Name, date of birth, contact details, etc.Server holding customer personal dataOct 2–3

Connecting information (CI) is a value used in Korea to identify a person in place of the resident registration number. Unlike a password, you cannot change it.

  1. Late Sept 29 to early Sept 30

    The period in which unauthorized access to Shinhan Bank's services reportedly took place.
  2. Sept 30

    Shinhan Bank detects the leak and activates its emergency response, blocking outside IP addresses and suspending the affected services. Yegaram Savings Bank finds signs of access to and leakage from a server holding customer data. That night, KB Kookmin Bank becomes aware of possible leakage from abnormal outside access and blocks the server and access route.
  3. Oct 1

    Shinhan Bank announces the leak of about 25,000 people's data and posts an apology from its chief executive on its website. The Financial Supervisory Service begins an emergency on-site investigation of Shinhan Bank, according to reports.
  4. Oct 2

    KB Kookmin Bank (119 people) and Hana Bank (89 people) announce leaks. The Financial Services Commission holds an emergency meeting with the Financial Supervisory Service, the Financial Security Institute and major banks and card companies.
  5. Oct 2–3

    Yegaram Savings Bank announces on its website a leak of about 40,000 people's data (estimate).
What is known (from the banks and regulators)
Transactions
Shinhan, KB Kookmin and Hana say the affected systems are separate from transaction systems and no transaction data such as transfers leaked
Compensation
Shinhan, KB Kookmin and Hana will fully compensate actual losses. Yegaram Savings Bank will support relief procedures where needed
Regulators
The Financial Supervisory Service is carrying out on-site investigations. The Financial Services Commission ordered financial firms to review all internet-facing IT systems, cut unnecessary data exposure and tighten authentication and access control, and to report the results
Other banks
BNK Busan Bank reportedly leaked data on 11 staff of an outside development contractor, not customers. Woori Bank and NH NongHyup Bank were reportedly attacked, with no leak confirmed
Cause
Shinhan Bank says an outside party reached some services by an abnormal method that bypassed authentication. Yegaram Savings Bank says it found signs of access through a vulnerability in an outside software product. No common cause across the four banks has been officially announced

About reports of an 'AI attack'

Some media reports say AI-based tools may have been used in the attacks. These reports mainly cite the views of security experts; as of October 3, 2026, it is not a cause the banks or regulators have officially confirmed. This site does not speculate on the cause.

Why a caller who knows your real figures still should not be trusted

Many people assume that "if they know my loan limit and income, they must be from the bank", because only the bank was supposed to know those figures.

After Shinhan Bank's leak, that assumption no longer holds. Annual income and loan limits leaked together with names and phone numbers, so a scam caller can quote the right figures.

Not proof the call is genuine

  • They quote your income or loan limit correctly
  • They know your name, date of birth and address
  • They give the bank's name and the caller ID looks similar

What you can check yourself

  • Hang up, call the main number you looked up, and see if you hear the same thing
  • See whether the same notice appears in the official app
  • Notice whether you are being asked to send money, install an app or give a code

What is still unknown

As of October 3, the exact number and scope at Yegaram Savings Bank, how each bank was breached, and whether the leaked data has been misused have not been announced. The Financial Services Commission is reported to have scheduled another meeting for October 7. We will update this article when there is news.

For people who run financial or other systems

The affected systems the banks described were not customer-facing online banking but an inquiry page for loan recruiters, an employee mobile work system and an operations support system. The Financial Services Commission's order also targets "internet-facing systems". The lesson from this case is the peripheral systems that tend to get less attention than the main customer service.

1

Put staff and partner systems on your list of internet-facing systems

When you list the systems reachable from the internet, include not only customer services but also employee mobile work systems, pages for contractors and recruiters, and test servers.

How to build the list is covered in Security inventory checklist. A system that is not on the list never gets reviewed.

2

Make inquiry services return only what the job needs

What leaked at Shinhan Bank was income and loan limits that an inquiry service could return. Review each item an inquiry screen returns; drop items the user's job does not need, or show them partly masked.

The flaw where changing a lookup number shows someone else's data is explained in IDOR (broken authorization).

3

Add multi-factor authentication and lookup limits to peripheral systems

Systems that staff or contractors use from outside need a second check on top of the password (multi-factor authentication). See Choosing multi-factor authentication.

As a first step, set a per-account, per-hour limit on lookups and alert someone when an account reaches 80% of it. That catches lookup volumes no human user would produce.

Sources (public record)

The facts in this article are based on the public sources below. Each bank's notice is on its official website. We have not speculated on unpublished details or causes.

Update history

2026-10-03: First version, based on the banks' statements of October 1–3 and the Financial Services Commission's emergency meeting of October 2. We will update when counts or causes are announced.

FAQ

QWhich banks were affected, and how many people?
A

According to the banks' statements as reported by Korean media, Shinhan Bank about 25,000 people, KB Kookmin Bank 119 people, Hana Bank 89 people and Yegaram Savings Bank about 40,000 people (an estimate; the exact number and scope are still being checked). Separately, BNK Busan Bank was reported to have leaked data on 11 staff of an outside development contractor, not customers.

QWhat was leaked?
A

It differs by bank. At Shinhan Bank: name, phone number, annual income, loan limit and other loan-application information; for some customers also resident registration numbers (66 cases) and connecting information (CI, an identifier used for identity verification in Korea; 97 cases). At KB Kookmin Bank: name, phone number, address, encrypted resident registration number and more (items differ by person). At Hana Bank: seven items — resident registration number, name, address, email address, phone number, mobile number and employer name. At Yegaram Savings Bank: name, date of birth, contact details and more.

QIs the money in my account safe? Were my PINs leaked?
A

Shinhan, KB Kookmin and Hana say the affected systems are separate from internet and mobile banking, and that no transaction data such as transfers was leaked. None of the banks has announced a leak of account passwords or PINs. The bigger risk is phone scams that use the leaked data.

QWere all four attacks carried out by the same attacker?
A

As of October 3, 2026, neither the banks nor the regulators have announced a common cause or a single attacker. Some media reports say AI-based attack tools may have been used, but this is not a cause the banks or regulators have officially confirmed. Yegaram Savings Bank says it found signs of access to its server through a remote vulnerability in an outside software product.

QHow can I check whether I am affected?
A

Shinhan Bank added a menu to its website and mobile app to check whether your data leaked, and opened a dedicated hotline (1544-2946). KB Kookmin Bank says it contacted affected customers individually. For the other banks, check the notice on the official website and the dedicated help line. Use the official app or a website address you typed yourself, not a link in a message you received.

QWill I be compensated if I suffer a loss?
A

Shinhan, KB Kookmin and Hana say they will fully compensate customers for actual losses caused by the leak. Yegaram Savings Bank says it will check any damage and support relief procedures where needed.