Security Budget at 40.6 Billion Won This Year
Less Than Half of KB Kookmin Bank’s Allocation
Five-Year Average at 41.4 Billion Won
Lowest Proportion Among Major Banks
Experts: "Management Must See Security as an Essential Investment"

It has been revealed that, over the past five years, Shinhan Bank consistently allocated the smallest information security budget among the top five commercial banks, despite a recent data breach that leaked information from around 25,000 customers. The proportion of the information security budget within the bank's total IT spending also remained the lowest among the five banks during the same period. With cyberattacks growing ever more sophisticated due to advances in artificial intelligence (AI), industry observers are calling for management to regard information protection not merely as a cost, but as an essential investment, and to proactively enhance security capabilities.



[Exclusive] Shinhan Bank Lags in Security Investment After 25,000-User Data Leak... Ranks Last Among Top 5 Banks for Five Years [Growing Financial Security Threats] ① View original image

According to data titled “Status of Information Security Budgets and Personnel in the Financial Sector over the Past Five Years (2022–the first half of 2026)” from the Financial Supervisory Service, submitted to Assemblyman Kim Jaeseop of the National Assembly’s Political Affairs Committee on October 2, Shinhan Bank’s information security budget for this year is 40.591 billion won, the lowest among the five major banks—KB Kookmin, Shinhan, Hana, Woori, and NH Nonghyup.


KB Kookmin Bank’s budget stands at 86.075 billion won, more than double that of Shinhan. Nonghyup Bank follows with 80.134 billion won, Hana Bank with 63.635 billion won, and Woori Bank with 61.566 billion won. Even compared to Woori Bank, the bank right above Shinhan, the difference is nearly 21 billion won, and Shinhan Bank’s allocation amounts to just 66% of Woori’s.


This gap is not unique to this year alone. From 2022 to this year, Shinhan Bank recorded the lowest information security budget among the five main banks each year. On a five-year average, Shinhan’s annual information security budget stood at only 41.414 billion won. In comparison, Nonghyup Bank allocated an average of 73.25 billion won, KB Kookmin Bank 69.499 billion won, Woori Bank 61.426 billion won, and Hana Bank 56.812 billion won—meaning that, on average, the other banks spent between 15.4 billion and 31.8 billion won more per year than Shinhan Bank.


[Exclusive] Shinhan Bank Lags in Security Investment After 25,000-User Data Leak... Ranks Last Among Top 5 Banks for Five Years [Growing Financial Security Threats] ① View original image

Even when considering each bank’s overall IT budget, the proportion devoted to information security showed a similar trend. Shinhan Bank’s information security budget as a share of its IT budget rose from 7.4% in 2022 to 8.6% in 2023, 8.5% in 2024, 10.0% in 2025, and 9.1% this year. However, in all five years, this percentage was still the lowest among the five major banks. Shinhan’s five-year simple average was 8.7%. Nonghyup Bank averaged 11.4%, Woori Bank 11.0%, Hana Bank 10.4%, and KB Kookmin Bank 10.1%, with all four banks recording double digits and surpassing Shinhan. In comparison, a 2024 IANS and Atiko Search survey of companies, mainly in the United States and Canada, found that information security budgets averaged 13.2% of IT budgets. While industry differences must be taken into account, all five major Korean banks were below this figure, and particularly Shinhan posted only 8.5% in the same year, representing the widest gap.


[Exclusive] Shinhan Bank Lags in Security Investment After 25,000-User Data Leak... Ranks Last Among Top 5 Banks for Five Years [Growing Financial Security Threats] ① View original image

The relatively low information security budget at Shinhan Bank has led to calls for management to prioritize investment in security. President Jung Sanghyuk, who has led Shinhan Bank since 2023, previously served as head of the management planning group, performing the roles of chief financial officer (CFO) and chief strategy officer (CSO), overseeing both finance and strategy. As information security is an area where it is difficult to see short-term returns, experts stress that management must recognize it as a long-term risk management investment, not simply a cost center.


This need has become even more prominent in light of the recent unauthorized access by an external party to Shinhan Bank’s loan recruitment inquiry service, which resulted in the personal and credit information of approximately 25,000 customers being leaked. The leaked data included customer names, phone numbers, annual income, and calculated loan limits; in addition, 66 instances of resident registration numbers and 97 pieces of linked information (CI) were also leaked for some customers. The Financial Supervisory Service is currently conducting an on-site inspection of Shinhan Bank to determine the exact circumstances of the breach and assess the status of internal controls.


Assemblyman Kim stated, “Financial corporations should not stop at simply proposing countermeasures after incidents occur. Instead, they must proactively expand information security budgets and specialist personnel in order to build a system that prevents personal information leaks and IT accidents in advance.”


Experts advise that as AI-driven cyberattacks become more advanced, it is necessary to go beyond merely increasing budgets and to expand specialist personnel and strengthen both prevention and detection capabilities. Seo Ji-yong, a professor of business administration at Sangmyung University, commented, “Financial institutions must shift to a preventive approach to information security instead of focusing on post-incident responses. It is important to bolster specialist personnel, access rights management, oversight of outsourcing companies, continuous anomaly detection, and regular penetration testing systems.”



There are also recommendations to enhance the responsibility and role of top management in order to ensure that security investments translate into practical improvements in prevention capabilities. Chae Sangmi, professor of business at Ewha Womans University, emphasized, “To qualitatively upgrade the information security system, full support and deep understanding from the board of directors and C-level executives are essential. When incidents occur, a regime should be in place to hold the CEO or the executive in charge accountable, not just working-level employees, and, if necessary, a ‘clawback’ system should be introduced to revoke bonuses.”


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing