The Financial Services Commission extended a caution-level cyber alert through Oct. 15 on Friday, citing fresh dark-web posts that advertised username-and-password pairs allegedly taken from deprecated loan-recruiter portals shut on Oct. 8. Banks must keep phishing hotlines staffed over the Hangul Day weekend and push app notifications warning customers not to reuse credentials scraped before the portal blackout.

The alert, first raised Tuesday when the ASAP information-sharing platform circulated breach-linked phishing domains, now adds a credential-dump dimension. Security teams at three lenders told InfoHandle Network they saw automated login attempts against retail internet banking using combos from the post; none succeeded because multi-factor authentication blocked the sessions. Still, the volume—tens of thousands of attempts per hour—forced temporary rate limits on VPN entry points.

Regulators closed public recruiter lookup tools to stop brokers from being impersonated. Criminals who had hoarded portal logs before the cutoff began releasing samples to prove “inventory,” a classic extortion pattern. The FSC said it cannot verify every listed credential but treats the dump as credible enough to warrant customer warnings.

Institutions must rotate outbound SMS sender IDs used for fraud alerts—a measure ordered earlier this month—and refresh web login pages to highlight the Oct. 8 policy change. Credit-card issuers piggybacked on the notice with October fraud-awareness push messages, separate from rewards marketing.

What customers should do

Official guidance unchanged: change passwords if you ever uploaded documents to a third-party loan broker site, enable app-based login approvals, and hang up on callers claiming to be prosecutors seeking remote access. The FSC said legitimate agencies never request banking tokens by phone.

Analysts expect the caution flag to drop only after a full week without successful account takeovers traced to the dump. Until then, the recruiter portal closure’s security benefit comes with a noisy aftershock—credential lists outliving the websites they targeted.

Bank playbooks over the long weekend

Lenders scheduled extra fraud-analyst shifts despite the national holiday, rotating teams between Seoul and Busan operations centers. One midsize bank tested machine-learning velocity checks tuned to the leaked combo format, reducing false positives that plagued similar incidents in 2024. Customers who call hotlines hear a recorded reminder that recruiter portals are closed, then a prompt to freeze cards if they shared PDFs with unknown brokers.

Insurance units tied to banking groups said cyber riders on homeowner policies do not cover credential stuffing losses, a gap consumer groups want clarified in plain Korean. The FSC promised a template disclosure by month end.