Security · October 11, 2026
Also published in Português (Brasil)
4,777 security vulnerabilities found in banking sector, 109 unresolved
During simulated hacking exercises conducted over the past five years, domestic banks discovered 4,777 security vulnerabilities; however, 109 of these have reportedly not been addressed. Concerns have emerged that despite increasing interest income in the banking sector, investments in information security have decreased.
On October 8, during a National Assembly audit meeting, a lawmaker raised issues regarding the management of security vulnerabilities and the lack of investment in information protection within the banking sector. According to the disclosed data, a total of 4,777 vulnerabilities were identified across 20 banks during simulated hacking exercises, with 109 remaining unaddressed by the time of the report.
Notably, one specialized bank has been criticized for not improving a security vulnerability identified in 2024, citing system obsolescence as the reason. The use of artificial intelligence (AI) in simulated hacking has also been deemed inadequate, with only nine instances reported over the last five years.
Investment in information security among banks has reportedly decreased. The same lawmaker indicated that security investment for major banks in 2025 will be 5.9% lower compared to 2022. Meanwhile, interest income for banks increased from 55 trillion won in 2022 to 60.4 trillion won in 2025, highlighting a disparity between rising profits and reduced security investment.
These findings come amid a rise in hacking attacks targeting domestic financial institutions utilizing AI-based automated tools. The issue of unaddressed vulnerabilities and the need for increased security investment is expected to be a key topic during the audit.