Bank of Korea Data Breach Highlights Rising Cybersecurity Risks for Financial Institutions

Photo=Motionelements

Cybersecurity is emerging as a growing operational risk for financial institutions and other critical infrastructure operators in South Korea, with a recent breach at the Bank of Korea exposing employee data and a surge in attacks against the central bank’s internet systems underscoring the challenge for companies and investors with exposure to the country’s financial sector.

The Bank of Korea said a cyberattack between May 9 and June 8 compromised personal information belonging to 186 of its employees, including names, email addresses, phone numbers, job titles, departments and encrypted passwords. The incident involved a GitHub system operated by an outside contractor that provides online training services for the central bank.

The breach illustrates a broader security challenge facing institutions that increasingly rely on cloud services, outside vendors and internet-connected systems. For investors, such incidents can create operational, regulatory and reputational risks that extend beyond the directly affected organization, particularly when third-party systems are involved.

The Bank of Korea said the contractor notified it of the breach on June 11. The central bank informed affected employees the following day and reported the incident to South Korea’s Personal Information Protection Commission.

The central bank has also faced a sustained stream of attempts to penetrate its own internet-facing systems. From 2021 through August this year, the Bank of Korea detected 2,063 hacking attempts, according to data submitted to Rep. Lee Jong-wook of the People Power Party, a member of the National Assembly’s Planning and Finance Committee.

The attacks declined from 1,557 in 2021 to 192 in 2022, 97 in 2023, 52 in 2024 and 30 in 2025. Through August this year, however, the bank had already recorded 135 attacks—4.5 times the total for all of 2025.

Most of the attacks involved attempts to gain unauthorized access. There were 1,951 such incidents during the period, compared with 95 involving malware, 16 involving information gathering and one DDoS attack.

Foreign sources accounted for 2,024 of the attacks, while 39 originated domestically.

The systems targeted were largely public-facing services, including the Bank of Korea’s main website, its economic statistics website and its electronic library. Such systems can serve as entry points for attackers seeking to disrupt services, gather information or probe an institution’s broader network.

The Bank of Korea said security changes helped reduce attacks detected in 2022. In February that year, it moved its email servers to the cloud and tightened login rules, limiting repeated attempts to access email accounts using automated password guesses.

The central bank has also experienced an actual service disruption. On December 19, 2023, a DDoS attack caused intermittent delays in accessing its website. The bank said it restored domestic service by blocking overseas connections and later restored broader access. No financial information was compromised, it said.

The latest employee-data breach follows another information-exposure incident at the central bank. On June 23, 2023, an application submitted by a candidate for a temporary statistical survey position was inadvertently posted on the Bank of Korea’s website. The document contained the applicant’s name, date of birth, address, contact information, education and employment history, personal statement and reasons for applying. The bank removed the document on June 24 and notified the applicant.

For financial companies, technology providers and investors watching South Korea, the incidents highlight a broader cost of digital dependence: security exposure increasingly extends across vendors, cloud infrastructure and public-facing services. The Bank of Korea’s experience also shows how a decline in detected attacks can reflect changes in security architecture rather than a permanent reduction in the underlying threat.

“The Bank of Korea, as the country’s central bank, should not take employee data breaches and repeated website disruptions lightly,” Lee said. He called for an examination of the causes of the incidents and a comprehensive review of the bank’s security systems to prevent similar breaches from recurring.

User_logo_rmbg
WooJae Adams

Share:

Facebook
Threads
X
Email