SEOUL — South Korea’s central bank is facing renewed scrutiny over its cybersecurity after hackers breached an external system and exposed personal information belonging to 186 Bank of Korea (BOK) employees.
The breach, which occurred between May 9 and June 8, involved a GitHub system operated by a contractor responsible for the BOK’s online training program. Information reportedly exposed included employees’ names, email addresses, phone numbers, job positions, duties and encrypted passwords.
The BOK said the contractor notified the central bank of the incident on June 11. The affected employees were informed the following day, and the case was reported to South Korea’s Personal Information Protection Commission.
Cyberattacks against BOK are also rising
The employee-data breach comes as the number of cyberattacks targeting BOK-operated internet systems has increased sharply this year.
According to data submitted by the central bank to National Assembly lawmaker Lee Jong-wook, BOK systems recorded 135 hacking attempts between January and August 2026. That figure is already 4.5 times the 30 attempts recorded during all of 2025.
Of this year’s attacks, 125 involved unauthorized-access attempts, while 10 involved malware, according to the data.
Across the period from 2021 through August 2026, BOK recorded 2,063 hacking attempts. Unauthorized access represented the overwhelming majority, with 1,951 cases, followed by 95 malware incidents, 16 information-gathering attempts and one distributed denial-of-service attack.
The attacks primarily targeted internet-connected services including the central bank’s main website, economic statistics portal and electronic library.
Most of the recorded attempts originated outside South Korea, with 2,024 overseas attacks compared with 39 originating domestically during the period covered by the data.
BOK says detection numbers are affected by security changes
The year-by-year figures do not necessarily represent a straightforward increase or decrease in the underlying threat.
BOK noted that changes to its cybersecurity systems affected the number of attacks detected. The number of recorded incidents fell significantly after the bank moved its email server to the cloud and strengthened login requirements in 2022.
The central bank already maintains an information-security office and an operational-risk framework designed to identify and control risks affecting its core functions, including monetary policy and payment-settlement systems.
The latest breach, however, has put attention on the security risks that can arise through third-party systems and contractors, rather than only through BOK’s directly operated networks.
Calls grow for a broader security review
Lee Jong-wook said the central bank should not take the employee information leak and repeated website disruptions lightly.
He called for an examination of the causes of the incidents, a review of the BOK’s overall security system and measures aimed at preventing similar breaches from happening again.
The incident also follows a previous BOK privacy-related episode in 2023, when personal information contained in an application for a statistical survey assistant position was temporarily exposed on the bank’s website. The information was removed the following day and the affected applicant was notified.
For a central bank responsible for critical financial and payment infrastructure, the latest incident highlights a broader cybersecurity challenge: protecting sensitive information does not end with the systems operated directly by the institution.
As cyber threats continue to target financial organizations, the pressure on BOK is now shifting toward a more difficult question — how securely can a central bank protect its information when outside contractors and interconnected systems are part of the equation?
WWC ONE MEDIA G,A