Welcome Savings Bank confirms leak of up to 2,200 corporate customer records
Version 2: New details since the previous report: two online investment-linked finance firms, PFCT and Mowda, were additionally found to have leaked customer data, and one outlet says it is not yet established whether those incidents belong to the same AI-driven hacking campaign that hit the banks.
In short
Welcome Savings Bank confirmed that corporate customer information was leaked in a hacking attack, with up to 2,200 records estimated to be affected. The bank found the breach during its own inspection the previous day and reported it to the authorities; the data is believed to include corporate names, contact names, emails and phone numbers. Two online investment-linked finance firms also reported leaks, and financial authorities have held an emergency meeting on hacking threats across the sector.
Why it matters
The case extends a series of hacking-related leaks from commercial banks into savings banks and other parts of South Korea’s financial sector, prompting the financial regulator to hold an emergency meeting and warn of strict accountability for repeat incidents. Asia Economy said a police pre-indictment review, if confirmed as a formal investigation, would be the first major cyber case handled under a revised criminal procedure law that took effect on October 2. The documents give no indication of cross-border or market-wide impact.
Key facts
- Welcome Savings Bank confirmed that corporate customer information was leaked in a hacking attack and reported it to the authorities, and said it found the attack during its own inspection the previous day. [ 1 , 2 , 3 , 8 ]
- Up to 2,200 corporate customer records are estimated to have leaked, including corporate names, contact person names, email addresses and phone numbers. [ 1 , 2 , 3 , 8 , 9 ]
- The bank said it is still determining the exact circumstances and the scale of the leak. [ 1 , 2 , 3 , 8 ]
- Two online investment-linked finance firms, PFCT and Mowda, also reported leaks; PFCT said about 300 customers’ personal information was affected and Mowda warned that personal and credit information may have leaked. [ 6 , 8 , 9 ]
- Police opened a pre-indictment review covering Shinhan Bank, KB Kookmin Bank, Hana Bank and BNK Busan Bank, Asia Economy reported. [ 3 ]
- Financial authorities held an emergency meeting on hacking threats; Newsis reported that Financial Services Commission Chairman Lee Eok-won called for top-level vigilance and warned of strict accountability for security lapses. [ 5 ]
- Kyunghyang Shinmun reported it is not yet confirmed whether the two online investment-linked finance firms’ leaks are part of the same AI-driven hacking campaign, and that those firms were not among the participants in the authorities’ emergency meeting. [ 8 ]
Confirmed by several sources
- Welcome Savings Bank confirmed that corporate customer information was leaked in a hacking attack and reported it to the authorities. [ 1 , 2 , 3 , 4 , 8 , 9 ]
- Up to 2,200 corporate customer records are estimated to have leaked, including corporate names, contact person names, email addresses and phone numbers. [ 1 , 2 , 3 , 8 , 9 ]
- The attack was discovered during the bank’s own inspection the previous day. [ 1 , 2 , 3 , 8 ]
- The bank said it is still establishing the exact cause and scope of the leak. [ 1 , 2 , 3 , 8 ]
- Leaks have spread from commercial banks to savings banks and other parts of the financial sector. [ 3 , 4 , 9 ]
- Two online investment-linked finance firms also reported customer information leaks. [ 6 , 8 , 9 ]
- Financial authorities held an emergency meeting on hacking threats across the financial sector. [ 5 , 8 ]
Still unclear
- The exact number and scope of leaked records Every outlet describes the 2,200 figure as an estimate, and the bank says it is still determining the scale.
- The cause of the breach and who was behind it The bank says the circumstances are under investigation; only Asia Economy reports that hackers used AI agents, a single-source claim.
- Whether the police pre-indictment review becomes a formal investigation Only Asia Economy reports the review, and it states that a formal investigation has not been confirmed.
- Whether the two online investment-linked finance firms’ leaks are linked to the AI-driven hacking campaign Kyunghyang Shinmun states this is not yet confirmed, and reports that those firms were excluded from the authorities’ emergency meeting.
- The full set of regulatory response measures Only Newsis reports the meeting’s measures, and its article text is truncated.
What local media are saying
Timeline, local time
- Yonhap reports that Welcome Savings Bank confirmed a corporate customer data leak of up to 2,200 records and reported it to the authorities. [ 1 ]
- Seoul Economic Daily reports the bank discovered the hacking during a security inspection and reported it to financial authorities. [ 2 ]
- Asia Economy reports that the police cyber terror investigation unit opened a pre-indictment review covering Shinhan, KB Kookmin, Hana and BNK Busan banks, and that AI-agent hackers targeted a broad range of financial firms. [ 3 ]
- Chosun Ilbo reports that the leaks are spreading from commercial banks to savings banks and the wider financial sector. [ 4 ]
- Newsis reports that financial authorities held an emergency response meeting and that FSC Chairman Lee Eok-won warned of strict accountability. [ 5 ]
- Yonhap reports in an aggregate story that two online investment-linked finance firms were also affected. [ 6 ]
- Kyunghyang Shinmun reports details of the PFCT and Mowda leaks and says it is not confirmed whether they belong to the same hacking campaign. [ 8 ]
- Asia Economy reports the list of financial firms where personal data leaks have been identified so far. [ 9 ]