South Korea is facing renewed scrutiny over the cybersecurity of its financial industry after new figures revealed that attackers behind most suspected overseas hacking incidents targeting financial companies since 2024 have yet to be identified.
According to data from South Korea’s Financial Supervisory Service, cited by opposition lawmaker Song Eon-seok on October 9, attackers were identified in just two of 18 suspected overseas hacking incidents reported by financial firms since 2024. The other 16 cases remain unresolved in terms of identifying those responsible.
The figures come as several South Korean financial institutions have reported customer information leaks following a series of recent cyberattacks, raising questions about the industry’s ability to identify attackers and protect sensitive data.
The latest findings have also intensified calls for stronger cybersecurity systems, including greater use of artificial intelligence (AI) to help financial institutions detect suspicious activity and investigate attacks.
Most Attackers Remain Unidentified
The data cited by Song show that investigators have struggled to establish who was behind many suspected overseas attacks.
Of the 16 unresolved cases, 13 were associated with internet protocol (IP) addresses believed to be located overseas. The country of origin could not be determined in the remaining three cases. Countries associated with some of the IP addresses included China, the United States, Bulgaria and Vietnam.
However, identifying an overseas IP address does not necessarily reveal the attacker’s actual location or identity. Cybercriminals may route their activity through intermediary systems or use virtual private networks to obscure where an attack originates.
This distinction makes investigations more complicated: identifying a digital connection is not the same as establishing who carried out a cyberattack.
Previous Ransomware Attacks Disrupted Financial Services
Two cases in the report illustrate how cyberattacks have affected South Korean financial companies.
- Seoul Guarantee Insurance: The company suffered a ransomware attack attributed to the international group GUNRA in July 2025. The incident disrupted operations for approximately 64 hours.
- Baro Savings Bank: The bank experienced an attack in April 2026 attributed to the ransomware group INC Ransom.
These incidents are among the two cases in which the attackers were identified, according to the reported data.
The remaining unresolved cases underscore the difficulty of tracing attacks across international networks, particularly when investigators have limited information about the people or groups responsible.
Recent Bank Data Leaks Add to Industry Concerns
The findings arrive amid a separate series of cyberattacks affecting South Korean financial institutions, including Hana Bank, KB Kookmin Bank and Shinhan Bank.
South Korean authorities have launched investigations into the recent incidents, while cybersecurity specialists have examined whether AI-powered tools were used to help conduct the attacks.
On October 8, reporting based on an assessment by U.S. cybersecurity firm CrowdStrike described a possible connection between recent attacks and an unidentified, potentially Chinese-speaking individual who allegedly used AI-assisted security tools. However, the person’s identity and the full scope of the incidents remain unconfirmed.
These recent investigations are distinct from the broader figures covering suspected overseas hacking incidents since 2024. Authorities have not established that all the incidents involved the same attacker or method.
Lawmaker Calls for AI-Based Cybersecurity Defenses
Song called for South Korea to accelerate the development of AI-based defense systems, arguing that financial institutions need better technology to identify attackers and trace their activities.
AI-powered security tools can help analysts identify unusual network activity, process large volumes of security alerts and investigate potential vulnerabilities. However, their effectiveness depends on the quality of the available data, appropriate oversight and how quickly institutions respond to detected threats.
The challenge is particularly important for financial companies, which handle sensitive customer information and operate services that people rely on for everyday transactions.
Stronger defenses will need to be accompanied by effective incident reporting, coordinated investigations and measures to limit the exposure of customer data when breaches occur.
What Comes Next for South Korea’s Financial Cybersecurity?
The latest figures highlight two related challenges: preventing cyberattacks and identifying those responsible after an incident occurs.
Financial companies and regulators face pressure to strengthen their defenses as cyber threats become more sophisticated. Investigators must also distinguish reliable evidence about an attacker’s identity from clues that indicate only the possible origin of internet traffic.
The government’s response to the latest bank incidents, along with any improvements in detection and attribution capabilities, will be important indicators of whether the sector can address these weaknesses.
The bottom line: South Korea’s financial industry has reported 18 suspected overseas hacking incidents since 2024, but attackers were identified in only two. As investigations continue into recent customer-data leaks, the demand for stronger cybersecurity and more effective identification methods is growing.
WWC ONE MEDIA G,A