Singapore · Tuesday, October 6, 2026
asianomistAsia’s economy, daily.
Banks

South Korea's FSC Mandates Bank Security Checks After Cyberattacks

The Financial Services Commission on Friday, October 2, directed all banks and credit card firms to review IT systems following data breaches at Shinhan Bank and KB Kookmin Bank affecting thousands of customers.

By Grace TanuwijayaPublished 3 October 20262 min read
Photo: Tima Miroshnichenko / Pexels

FSC Orders Sector-Wide Security Review

South Korea's Financial Services Commission (FSC) on Friday, October 2, mandated that all banks and credit card companies undertake comprehensive security assessments. This directive follows a series of cyberattacks that impacted major lenders, including Shinhan Bank and KB Kookmin Bank.

The financial regulator stated its intention to promptly collect the findings from these checks. The FSC plans to utilise this information to formulate new strategies for bolstering digital security across the entire financial industry.

Data Breaches Affect Four Major Banks

The order comes after multiple data breaches. Shinhan Bank reported on Thursday, October 1, that a hack of its communications infrastructure exposed data for approximately 25,000 clients. KB Kookmin Bank's internal review also identified a leak of over 100 customer records following an external intrusion.

Financial industry sources further indicated that Hana Bank and BNK Busan Bank also experienced data breaches on Friday. The attacks specifically targeted less-secure systems, such as Shinhan Bank’s loan agent service and KB Kookmin Bank’s mobile work-support system, often utilising artificial intelligence agents.

Regulator Details Required System Checks

Secretary General Shin Jin-chang chaired an emergency FSC meeting to exchange threat intelligence on the recent breaches and coordinate responses. Shin emphasised the necessity for financial companies to conduct exhaustive reviews of all IT systems accessible from outside their networks.

The FSC instructed firms to catalogue all externally accessible IT assets and services, scrutinise security weaknesses, and verify access controls. Companies must also reduce external exposure of sensitive data and confirm robust authentication for internal information access.

The FSC, Financial Supervisory Service (FSS), and Financial Security Institute (FSI) have launched on-site inspections at the four affected banks.

Why it matters

This regulatory push will likely drive substantial investment in cybersecurity infrastructure and compliance for South Korean financial institutions. Banks and credit card companies face increased scrutiny to protect customer data and maintain public confidence.

The FSC's swift action, including on-site inspections and a coordinated information-sharing framework, aims to mitigate future risks. Financial firms must now prioritise system upgrades and employee training to meet these heightened security standards, potentially leading to higher operational costs in the short term as they implement the mandated changes.

This article is journalism, not investment advice; consult a licensed professional before making financial decisions. Market data is indicative, may be delayed, and should be verified with your broker or exchange before use.

Comments.

Comments are moderated. We remove what is unlawful, abusive or off-topic, and and you remain responsible for what you post.

Reader comments open soon. Until then, corrections and responses go to our newsroom, and we publish what we get wrong on Corrections.