JupiteX Get the app
Defence & Security11 Oct 2026 · about 6 min

Hacking attempts on BOK, state lenders top 1 million

The brief

South Korea’s central bank and three state lenders recorded 1,024,478 hacking attempts during the first nine months of the year. That total already exceeded the 934,858 attempts recorded throughout 2025. The scale matters because these institutions support important financial operations and hold sensitive government and corporate information. The institutions were the Bank of Korea, IBK Industrial Bank of Korea, KDB Korea Development Bank and the Export-Import Bank of Korea. IBK accounted for 91.9 percent of nearly 5 million attempts recorded across the four institutions since 2020. KDB logged 399,379 attempts, while the Bank of Korea recorded 3,076 and the Export-Import Bank recorded 510. The institutions reported no breaches from these attempts between 2020 and September this year. However, the rise comes alongside customer-data leaks at major commercial banks, prompting regulators to require system inspections, stronger authentication and access controls, and information sharing about attacks.

01

Which South Korean financial institutions faced more than 1 million hacking attempts, and over what period was that total recorded?

South Korea’s central bank and three state lenders recorded 1,024,478 hacking attempts during the first nine months of the year. That total already exceeded the 934,858 attempts recorded throughout 2025. The scale matters because these institutions support important financial operations and hold sensitive government and corporate information.

The institutions were the Bank of Korea, IBK Industrial Bank of Korea, KDB Korea Development Bank and the Export-Import Bank of Korea. IBK accounted for 91.9 percent of nearly 5 million attempts recorded across the four institutions since 2020. KDB logged 399,379 attempts, while the Bank of Korea recorded 3,076 and the Export-Import Bank recorded 510.

The institutions reported no breaches from these attempts between 2020 and September this year. However, the rise comes alongside customer-data leaks at major commercial banks, prompting regulators to require system inspections, stronger authentication and access controls, and information sharing about attacks.

02

What counts as a hacking attempt, and how is it different from a successful data breach?

In cybersecurity, a hacking attempt means someone tried to enter, probe or disrupt a computer system without authorization. It can include denial-of-service activity, information gathering, malware delivery or unauthorized-access attempts. The article counts these efforts even when defenses stop them. That makes an attempt a warning signal, not proof that attackers reached sensitive data.

A successful data breach is different. It means an attack resulted in unauthorized access to protected information or systems. The article reports that the four institutions had no breaches resulting from the recorded attempts between 2020 and September this year. Their systems were targeted, but the attacks did not produce a reported breach.

The distinction matters because a large attempt count does not automatically mean data was stolen. Still, repeated attempts can reveal pressure on financial networks. Regulators responded by ordering inspections, stronger authentication and access controls, and sharing information about attack methods and IP addresses.

03

How rapidly have attempts increased since 2020, and why did IBK Industrial Bank account for most of them?

The number of reported attempts climbed sharply, from 358,800 in 2020 to 1,024,478 during the first nine months of this year. That is nearly three times the 2020 figure. The latest nine-month total also exceeded the 934,858 attempts recorded throughout 2025, showing that the upward trend continued.

IBK Industrial Bank of Korea accounted for 91.9 percent of nearly 5 million attempts recorded since 2020. IBK said its count was high because it operates internet and mobile services for both retail and corporate customers. It described the scale of those services as comparable with commercial banks, which helps explain why it received far more recorded attempts than the other state lenders.

This concentration does not mean IBK suffered a breach. The four institutions reported no resulting breaches between 2020 and September this year. It does show that larger, more widely used digital services face more recorded attack activity and require sustained defenses.

04

What is a denial-of-service attack, and why did it make up the largest share of the recorded attempts?

A denial-of-service attack is an effort to make a website, network or service unavailable by disrupting normal operations. Its immediate goal is access to service, not necessarily theft of information. The article identifies denial-of-service attacks as the largest category among the recorded attempts at the institutions.

They made up 45.6 percent of cumulative attempts since 2020. The article does not give a specific reason for their larger share. It does explain their basic purpose: disrupting normal operations. Other recorded categories included information gathering, malware and unauthorized-access attempts. Together, these figures show that attackers pursued both disruption and possible entry.

The high proportion matters because financial institutions depend on systems being available. A successful disruption could interfere with services and wider financial operations. The institutions reported no breaches from the attempts through September, but regulators have ordered system inspections and stronger controls as attack activity rises.

05

What could happen to customers and financial markets if an attack on a state lender successfully disrupted its systems?

An attack on a state lender matters beyond the institution itself because its systems can connect to broader financial activity. Rep. Kang Min-kuk warned that a successful attack could disrupt financial systems at home and abroad. He also said sensitive government and corporate information could be put at risk.

For customers, a disruption could make online or mobile banking services unavailable or unreliable. The article does not describe a specific customer outage, so that is a possible consequence rather than a reported event. For markets and institutions, a successful disruption could interfere with normal financial operations across borders, according to Kang’s warning.

The current record is more reassuring but not risk-free. The four institutions reported no breaches from attempts between 2020 and September this year. Yet attempts reached 1,024,478 through September, and regulators ordered stronger inspections, authentication, access controls and attack-information sharing.

06

Why are state lenders and the Bank of Korea attractive targets for attackers beyond the money held in individual bank accounts?

State lenders and the Bank of Korea are attractive targets because their importance extends beyond individual customer balances. The article identifies a risk to financial systems at home and abroad. It also highlights sensitive government and corporate information, which gives these institutions significance beyond ordinary retail banking.

The mechanism is systemic reach. If an attack successfully disrupted a state lender or the Bank of Korea’s systems, the effects could extend to wider financial operations. The Bank of Korea’s Gyeonggi IT Center houses its main servers, and it recorded 145 attempts after opening last October. That detail shows that key infrastructure also receives attention from attackers.

The article reports no breaches from the attempts between 2020 and September this year. Still, the threat is rising. Rep. Kang called for defenses against AI-powered cyberattacks and cyberattack simulations with financial authorities, while regulators ordered stronger technical safeguards and information sharing.

07

How do authentication, access controls, system inspections, and attack-information sharing reduce the risk of cyberattacks?

External-system inspections, authentication, access controls and information sharing address different parts of cyber risk. Inspections look for weaknesses in systems reachable from outside. Authentication checks whether a person or device is allowed to connect. Access controls limit what an approved user can reach. Sharing attack methods and IP addresses helps institutions recognize related activity.

Together, these measures can make unauthorized entry harder and reduce the damage if an attacker gets past one barrier. A system inspection may reveal an exposed service. Strong authentication can block an impostor. Permission limits can prevent one compromised account from reaching everything. Shared indicators can help other financial firms identify similar attempts sooner.

Regulators ordered these steps after customer-data leaks at Shinhan Bank, KB Kookmin Bank and Hana Bank. The state institutions reported no resulting breaches through September, but attempts exceeded 1 million. Authorities also face calls for cyberattack simulations and defenses against AI-powered attacks.

This brief was written by AI from the original reporting and checked by other models. Names, figures and quotes come from the source; read it for full context.

Read more in the JupiteX app

Pulse is free. New stories every 4 hours, each one broken into the questions that explain it.

Or read more news on the web