2,140 Electronic Financial Accidents and 49 Security Breaches Reported from 2022 to August This Year
Standard Chartered Bank Korea Tops Electronic Financial Accidents, KT Alpha Leads Security Breaches
Security Alert Issued for Virtual Asset Exchanges Including Upbit and Bithumb

Amid the growing number of hacking incidents using artificial intelligence (AI) across the entire financial sector, there were more than 2,100 electronic financial accidents caused by internal program errors and system failures within financial institutions just last year. This has prompted criticism that both financial companies and electronic financial service providers need to scrutinize their verification and internal control systems to ensure transaction safety for financial consumers.


An image depicting the management situation of the financial sector struggling to prevent artificial intelligence (AI) hacking and electronic financial fraud. The Asia Business Daily database

An image depicting the management situation of the financial sector struggling to prevent artificial intelligence (AI) hacking and electronic financial fraud. The Asia Business Daily database

View original image

According to an analysis of materials submitted by the Financial Supervisory Service to Assemblyman Kim Hyungyeon of the Rebuilding Korea Party, a member of the National Assembly's Political Affairs Committee, there were a total of 2,189 electronic financial and security breach incidents reported to the Financial Supervisory Service from 2022 to August of this year. Of these, 2,140 were electronic financial accidents due to program errors or system failures, and 49 were security breaches caused by hacking and other illegal intrusions.


By year, the numbers were as follows: 416 cases in 2022, 423 in 2023, 483 in 2024, 528 last year, and 339 cases from January to August this year, demonstrating an upward trend.


Of the 2,140 electronic financial accidents that occurred this year, 1,543 involved financial institutions such as banks, internet-only banks, securities companies, insurance firms, and credit card companies; 592 involved electronic financial service providers including simple payment and payment gateway businesses; and 5 involved virtual asset exchanges.


Among financial institutions, Standard Chartered Bank Korea had the largest number of cases with 83, followed by Toss Bank with 65, KakaoBank with 54, Suhyup Bank with 50, Kakao Pay Securities with 47, KB Kookmin Bank with 46, Toss Securities with 44, Shinhan Bank with 37, Citibank Korea with 35, and 34 cases each for Woori Bank and Lotte Card.


Among electronic financial service providers, Woowa Brothers had the highest with 105 cases, followed by Toss Payments with 59, Naver Financial with 45, Kakao Pay with 41, Danggeun Pay with 30, Google Payment Korea with 26, Gmarket with 26, Viva Republica with 23, KT Alpha with 21, and SK Planet with 17.


By type of incident, program errors, system failures, and human errors accounted for 1,760 cases, which is 82.2% of all electronic financial accidents. For both financial institutions and electronic financial service providers, accidents caused by internal programs and system problems outnumbered those caused by external factors.


Some companies repeated security breaches as well. Among financial institutions, Standard Chartered Bank Korea, IM Bank, Seoul Guarantee Insurance, and Hana Card each experienced two security breaches. For electronic financial service providers, KT Alpha had the most with four cases, while NHN KCP and Toss Payments each had three cases.


The number of fines imposed by the Financial Supervisory Service also increased. From 2022 to August of this year, the Financial Supervisory Service imposed a total of about 1.16 billion won in fines (25 cases) on financial institutions for violations such as failing to ensure the safety of electronic financial transactions.


Among these, Woori Bank was issued an institutional warning and a fine of 40 million won for violating program change control procedures. Lotte Card was separately ordered to suspend part of its business for 1.5 months and was fined 5 billion won. Seven cases involving inspections of electronic financial service providers are currently in the process of sanctions.


During the same period, there were a total of six incidents at virtual asset exchanges. Of these, five were internal incidents: delays in trading or inability to execute trades due to surges in traffic, system operation errors, and incorrect event reward inputs. One was a security breach resulting from external hacking.


By exchange, Upbit reported one electronic financial accident and one security breach, totaling two incidents. Bithumb reported two electronic financial accidents, while Coinone and Digital X (formerly Korbit) each reported one case.


However, the current "Act on the Protection of Virtual Asset Users" only mandates monitoring for abnormal transactions and lacks explicit requirements for reporting electronic financial accidents or security breaches, as well as related sanction provisions. As a result, the actual number of incidents may be higher than reported. According to Assemblyman Kim, there were no records of fines imposed for delayed or unreported incidents at virtual asset exchanges in the materials submitted by the Financial Supervisory Service.



Assemblyman Kim stated, "Financial institutions need to examine whether repeated program errors and system failures are due to weaknesses in their internal verification and control procedures, while also preparing to counter external hacking. Financial authorities should intensively review program changes and verification systems prior to the service launch at companies with frequent incidents. Virtual asset exchanges must also establish systems for promptly reporting major incidents."


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing