South Korea's Financial Services Commission ordered banks and nonbank lenders to cut off nonessential external system access after a coordinated intrusion wave hit seven financial companies, exposing tens of thousands of customer records tied to loan applications and sales platforms.

Chair Lee Eok-won convened an emergency industry meeting on Sunday and told institutions to operate at the highest vigilance level while police and financial supervisors determine whether a single actor used artificial-intelligence tools to probe weak peripheral systems. President Lee Jae Myung separately instructed agencies to investigate thoroughly and draft stronger defenses, his office said.

Where data leaked

Shinhan Bank disclosed the first major breach on Wednesday. Compromised loan-application files included names, mobile numbers, annual income figures and calculated borrowing limits, according to regulators. KB Kookmin Bank reported 153 affected customers and Hana Bank 89.

Among savings banks, Yegaram Savings Bank said about 40,000 people were impacted, while Welcome Savings Bank counted roughly 2,200 cases. Hyundai Capital reported 146 individuals, and BNK Busan Bank said 11 outsourced workers were caught in an attack on a support system. Woori Bank and NH NongHyup Bank said they detected attempts but blocked them before data left their networks.

Authorities said the same attacker internet protocol address appeared across all seven incidents, a pattern that suggests one campaign rather than unrelated copycats. Investigators are also examining traces of Artex, a Chinese-developed penetration-testing platform that can chain automated exploit attempts.

Regulators' immediate steps

The FSC's lockdown directive requires firms to suspend external connectivity unless a connection is essential for customer service or settlement. Lee Eok-won said officials could not rule out AI-assisted attacks and warned that even "nonpayment" data could fuel voice-phishing and fraudulent text messages.

The Financial Supervisory Service ordered an emergency security inspection to be completed by Thursday, focusing on externally exposed assets, authentication controls and intrusion-detection coverage. Regulators stressed that differences in damage do not map neatly to cybersecurity budgets: Shinhan's information-security spending was the lowest among the top four commercial banks this year, yet Woori—which blocked its intrusion—also ranks low on raw spending.

"We need to check the entire security framework to ensure there are no gaps," Lee told reporters, pointing to sales-support and partner platforms that sit outside tightly guarded core banking engines.

Customer risk and political pressure

Officials said they had not seen evidence that credentials usable for immediate wire transfers were stolen, but they cautioned that income and phone data alone can sharpen social-engineering scams. Consumer groups urged lenders to notify victims quickly and extend fraud hotlines as Chuseok holiday travel peaks.

Opposition lawmakers questioned whether record industry profits have outpaced security investment, while the presidential office framed the episode as a national test of digital infrastructure. The FSC said it would propose a broader security-framework overhaul once the inspection concludes, potentially tightening rules on third-party sales systems that attackers increasingly target.