South Korea Issues Fraud Alert After Financial Data Breaches — And the Next Scam Could Look Surprisingly Real

Business

South Korea Issues Fraud Alert After Financial Data Breaches — And the Next Scam Could Look Surprisingly Real

SEOUL — South Korean financial authorities have launched a monthlong special response campaign after a series of data breaches at financial companies raised concerns that stolen personal information could be used in targeted fraud.

The Financial Services Commission and Financial Supervisory Service issued a “caution” consumer alert on Oct. 6 and began a special response period focused on preventing secondary damage from the leaked information.

Seven financial companies have reported data breaches or related incidents: Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. Authorities said no customer funds have been confirmed stolen in connection with the incidents so far.

Authorities Fear a New Wave of Targeted Scams

Officials are particularly concerned that criminals could combine leaked information with other details to make fraudulent messages and calls appear legitimate.

A scammer who already knows a person’s name, address, income or borrowing information could pose as a bank employee or loan adviser and offer a supposedly legitimate financial service. Authorities also warned about fake compensation offers related to the data breaches themselves.

Financial authorities stressed that consumers should not assume a caller or message is genuine simply because the sender knows accurate personal or financial information.

The government also warned that requests for upfront payments, repayment of an existing loan, or installation of an app as a condition for receiving a loan are signs of fraud.

Banks Ordered to Strengthen Fraud Detection

During the special response period, affected financial companies must operate dedicated customer-support channels and immediately report confirmed or suspected secondary fraud to regulators.

Financial institutions have also been ordered to strengthen their fraud detection system (FDS) monitoring. Suspicious information will be shared through ASAP, an AI-powered platform that allows financial institutions, telecommunications companies and investigative agencies to share and analyze voice-phishing information.

The goal is to identify suspicious transactions faster and, when necessary, help stop payments involving suspicious accounts.

Authorities said the special response period will run for one month from Oct. 6, with the possibility of an extension if circumstances require it. The consumer alert could also be raised if actual secondary damage is confirmed.

Financial Sector Under Wider Cybersecurity Pressure

The warning comes as concerns spread beyond banks to brokerages, insurers and credit-card companies.

The FSS has identified around 30 IP addresses associated with the recent attacks across multiple countries and territories. Officials cautioned, however, that the location associated with an IP address does not establish an attacker’s nationality or actual location.

South Korean President Lee Jae Myung has separately said there are signs that AI models were used in some of the recent attacks and called for a rapid investigation and measures to minimize potential damage.

For consumers, authorities are urging extra caution when receiving unexpected financial calls or messages, particularly those referencing recently exposed personal information.

The government says consumers can also use financial-transaction blocking services and the Financial Supervisory Service’s personal-information exposure prevention system to reduce the risk of identity-based financial fraud.

The breaches may have exposed personal information, but authorities are now focused on what happens next — and whether criminals can turn that information into convincing scams.

WWC ONE MEDIA G,A

Get our stories first on Google

More in Business

See all in Business