2,189 Incidents Reported to FSS Over Five Years
Lotte Insurance Detected Incident After 902 Days, Toss Bank After 670 Days

In the past five years, more than 90 incidents have occurred at financial companies—including banks, insurance firms, and savings banks—where electronic financial accidents went undetected for over a month. In some cases, it was found that certain financial institutions failed to recognize incidents for nearly three years. This has led to calls for strengthening internal monitoring systems to promptly detect and address incidents.


Lotte Insurance Headquarters Building, Jung-gu, Seoul. Lotte Insurance

Lotte Insurance Headquarters Building, Jung-gu, Seoul. Lotte Insurance

View original image

According to materials submitted by Assemblyman Kim Hyungyeon of the Rebuilding Korea Party, a member of the National Assembly's Political Affairs Committee, to the Financial Supervisory Service (FSS) on October 5, a total of 2,189 electronic financial and breach incidents were reported to the FSS from 2022 through August of this year. Out of these, 91 cases at 43 different companies took more than 30 days from the occurrence of the incident to its recognition by the financial institution. Seventeen incidents were not recognized for over a year after they occurred.


Thirty-two financial companies identified a total of 75 incidents only after 30 days had passed. Among electronic financial service providers such as simple payment and payment gateway operators, 11 companies experienced 16 such incidents.


The company with the slowest recognition time was Lotte Insurance. A program error that occurred on November 1, 2023, was not recognized until April 21 this year, a delay of 902 days. Toss Bank also took 670 days to identify a program error that occurred on May 7, 2022, finally detecting it on March 7, 2024. AIA Life Insurance failed to recognize a program error that happened in November 2024 until 621 days had passed.


In the banking sector, there were also cases where incidents went undetected for hundreds of days. Hana Bank uncovered a program error 507 days after it occurred in April 2025 and compensated 1.12 million won to 112 customers as a result. Shinhan Bank only recognized a program error from December 2023 after 471 days. At Shinhan Bank, there were a total of four cases that took more than 180 days to be detected, the highest among the nation’s five major banks (KB Kookmin, Shinhan, Hana, Woori, and NH NongHyup).


Among electronic financial service providers, Tmoney discovered a program error from January 2024 after 428 days, finding it in March of last year. The company compensated a total of 7.27 million won to 6,071 affected customers as a result of this incident.


Toss Bank had the highest number of cases (nine) where more than 30 days were required to recognize the incident. Suhyup Bank and KB Kookmin Bank each had seven cases, while Woori Bank, Shinhan Bank, and KakaoBank each had five. Among electronic financial service providers, Viva Republica and Tmoney each had three cases.


The majority of the long-unrecognized incidents were found to be due to internal program errors rather than external attacks like hacking. Of the 91 cases detected more than 30 days after occurrence, 81 were due to program errors, accounting for 89%. This highlights the importance not only of security systems to prevent external attacks, but also of internal monitoring to ensure that computer programs are operating correctly.


EXIMBAY only became aware of a data breach that happened in October 2022 after 309 days, in August 2023. iM Bank recognized an incident caused by a security vulnerability after 178 days had passed. Lotte Card, which experienced a large-scale data breach last year, took 19 days to detect a malware attack incident from the time it occurred.



Assemblyman Kim stated, "Consumers trust banks with their money and personal information, but if banks do not become aware of incidents for several months, who are consumers supposed to trust?" He added, "I intend to scrutinize whether accident prevention and response systems within the financial sector, as well as supervision and oversight by the financial authorities, are functioning properly in light of these repeated incidents."


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing