
Hyundai Capital said personal data belonging to its loan brokers was exposed in a hacking attack, following a string of similar breaches at South Korea's commercial banks.
The company said on the 3rd that it had confirmed an attack through an overseas IP address on a query page for its mortgage loan brokers at around 5:08 p.m. on the 2nd.
The exposed information covered 146 loan brokers and included their resident registration numbers, internal broker identification numbers, names, mobile phone numbers, email addresses and registration numbers with the Credit Finance Association. No retail customer data was exposed, and the attackers did not access or target internal systems, the company said.
Hyundai Capital said it detected the repeated data-query attacks during a security review prompted by the widening hacking damage across the financial industry. Immediately after confirming the leak, it blocked the attacking IP address and the page in question and set up an incident response task force. It reported the case to the Financial Supervisory Service and the Korea Internet & Security Agency (KISA) that afternoon.
"We promptly notified the mortgage loan brokers whose information was exposed, are conducting a thorough review of all externally accessible web pages, and are continuously running real-time monitoring of all web pages," a Hyundai Capital official said.
Yegaram Savings Bank also suffered a breach of customer data in a hacking attack. In a notice and apology issued the previous day under the name of its chief executive, the lender said an unidentified hacker accessed a server containing customer information on the 30th of last month, exposing names, dates of birth and contact details. The scale of the leak is estimated at about 40,000 people.
Yegaram Savings Bank said it had completed emergency steps including suspending the affected services and blocking external IP addresses, and had strengthened security monitoring to prevent further damage. "We will verify the damage reported through our customer center and provide support for related remedy procedures," the bank said.
KB Kookmin, Shinhan, Hana and BNK Busan Bank had earlier disclosed that personal data of customers and outsourced staff was exposed in external hacking attempts. Woori Bank and NH NongHyup Bank also experienced similar attempts. The Financial Services Commission, the Financial Supervisory Service and the Financial Security Institute are investigating the extent of the damage across the financial sector.






