[Vulnerable Financial Security] ⑤
If Recognized, Additional Security and Management Obligations Apply
Implications for Police and SCIA Jurisdiction
Impact on Accountability and Bank President Appointment
Compromised Systems at KB Kookmin and Hana Banks Unlikely to Qualify

Amid a series of hacking incidents targeting major commercial banks and other financial institutions, a key issue has emerged over whether Shinhan Bank's loan broker inquiry system qualifies as an "electronic financial infrastructure." If it is recognized as such, whether the bank fulfilled additional security and management obligations will be a key part of future inspections and regulatory decisions. Furthermore, this determination could affect jurisdiction over investigations between the police and the Serious Crimes Investigation Agency (SCIA). With potential implications for follow-up inspections and investigations, executive accountability, and the appointment of the next bank president, the financial sector is watching the financial authorities’ deliberations closely.


Will Shinhan Bank's Loan Broker System Be Classified as "Electronic Financial Infrastructure"? Key Variable in Hacking Sanctions and Investigation View original image

According to financial authorities on October 7, the Financial Services Commission is reviewing whether the systems compromised in this hacking incident constitute electronic financial infrastructure under the Electronic Financial Transactions Act (EFTA). The police have also requested an authoritative interpretation from the Commission to clarify investigative jurisdiction with the SCIA.


Among the affected commercial banks, the prevailing view is that the compromised systems at KB Kookmin Bank and Hana Bank are unlikely to be considered electronic financial infrastructure. The system at KB Kookmin Bank was a mobile work system for employees, while Hana Bank’s system was a business support system. In contrast, there is room for interpretation regarding whether Shinhan Bank’s loan broker inquiry system falls under the category of electronic financial infrastructure.


Multiple officials from financial authorities stated, “There are ambiguities about the scope of electronic financial infrastructure, so determining the boundary is crucial. Further review is necessary to decide whether systems like the loan broker inquiry system, through which internal staff access information, count as being used for electronic financial transactions.” They added, “We will closely review the legal requirements and, after delivering an authoritative interpretation, inform the police accordingly.”


Under the EFTA, electronic financial infrastructure refers to information processing systems and telecommunications networks used in electronic financial transactions. Representative examples include systems that facilitate actual financial transactions such as deposit sign-ups, fund transfers, and loan execution via internet or mobile banking. Although Shinhan Bank’s loan broker inquiry system does not directly carry out loan executions, the financial industry notes that it could be seen as part of the infrastructure since it intermediates and facilitates actual loan transactions.


As a result of this incident, Shinhan Bank experienced the largest data leak among the affected commercial banks, with information on approximately 25,000 individuals exposed. In cases where personal credit information of more than 10,000 credit information subjects is leaked, financial companies are required to report the breach to the authorities, and Shinhan Bank exceeded this threshold.


If Shinhan Bank’s loan broker inquiry system is ultimately recognized as electronic financial infrastructure, a central issue will be whether the bank properly fulfilled the mandatory security and management obligations for such facilities. The EFTA mandates that financial companies perform vulnerability assessments and implement necessary remedial measures for electronic financial infrastructure.


The financial authorities have also announced that even if a system does not qualify as electronic financial infrastructure, they will strictly scrutinize the security and management responsibilities of financial companies. However, if recognized as part of the infrastructure, separate statutory obligations—such as vulnerability analysis, assessment, and remedial measures—will also become subject to inspection and sanction. If any management shortcomings or violations of obligations are found, the grounds for imposing regulatory penalties could widen.


A financial sector official remarked, “Electronic financial infrastructure is a critical asset, so the law imposes additional management obligations. If a breach occurs, there is no choice but to thoroughly examine whether these obligations were properly met.”


The authorities’ determination is also expected to impact the way investigative agencies handle the case. The police have requested an authoritative interpretation from the Financial Services Commission regarding whether the breached system qualifies as electronic financial infrastructure. Depending on this judgment, the application of the EFTA, notification to the SCIA, and whether to transfer the case could all be affected.


Another area of interest is whether the investigation will be expanded to target the financial institution itself. Currently, the police investigation is focused on the hacker, but if the system is judged to be electronic financial infrastructure, the scope could extend to direct investigations into the company to examine potential violations of the law related to management. Previously, the police executed a search and seizure at Coupang last December in relation to a large-scale personal information leak.


Ultimately, the authorities’ judgment in this case will not only define Shinhan Bank’s responsibility and the extent of any sanctions, but is also expected to influence security and management standards for the broader financial sector. The decision could set a precedent for how far intermediary systems, such as those used for loan brokering and financial transaction facilitation, are recognized as electronic financial infrastructure.



For Shinhan Bank, the outcome of the authorities’ review could also become a critical variable in the ongoing process to appoint its next bank president. With Chanjin Lee, Governor of the Financial Supervisory Service, emphasizing the role of company subsidiary outside directors in overseeing management as well as the financial holding company itself, it is observed that how responsibility is apportioned through forthcoming inspections and investigations could influence the board’s decisions.


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing