Skip to content
Banks promise full compensation after hacks, but many may get left out

Banks promise full compensation after hacks, but many may get left out

Koreajoongangdaily • October 8, 2026

Major Korean banks have promised to cover losses tied to recent data breaches, but the challenge of proving causality and current rules on phishing victims mean few will actually receive compensation.

The fallout from a series of cyberattacks on Korea’s financial sector is shifting to fears of secondary losses. Major banks have promised to fully compensate customers for financial damage but proving that fraud such as voice phishing stemmed directly from recent data leaks could be difficult.

Customers who have been tricked into transferring money themselves also remain outside the scope of the current compensation system.

Financial companies affected by customer data leaks have announced compensation plans and are conducting internal reviews and taking additional steps to prevent further damage.

Hackers used multiple IPs used to hide origins of financial cyberattacks: Police

Hackers used multiple IPs used to hide origins of financial cyberattacks: Police

Shinhan Bank likely to face collective lawsuit over customer data breach

Shinhan Bank likely to face collective lawsuit over customer data breach

28 IP addresses behind recent hacking attacks against Korean financial institutions: Watchdog

28 IP addresses behind recent hacking attacks against Korean financial institutions: Watchdog

Korea cuts funding for AI cyber center

Korea cuts funding for AI cyber center

“We will take full responsibility and fully compensate customers for financial losses [including secondary damage] caused by the leak,” Shinhan Bank said.

KB Kookmin Bank and Hana Bank, which both experienced hacking on Oct. 2 , have also said they will fully compensate customers if damage linked to the breaches is confirmed.

Shinhan Bank's breach reportedly exposed personal information belonging to 25,000 customers. KB Kookmin Bank reported a leak involving 100 customers, while Hana Bank said information on 90 customers was affected.

Financial authorities issued a consumer alert at the “caution” level on Oct. 6 and said it could be elevated to the level of “warning” if actual cases of damage emerge.

Authorities specifically warned of voice phishing schemes that could use the leaked financial information. Scammers could pose as bank employees or loan consultants and approach potential victims with details such as their income or borrowing limits to make the fraud appear more convincing.

Authorities advised consumers not to click internet links sent by text message or install unfamiliar apps. Customers concerned identity theft were also advised to use services that allow them to block unauthorized financial transactions.

Even if suspected voice phishing losses emerge, however, identifying where the personal information used in the crime came from could prove difficult.

“It would be difficult to determine whether information used in a voice phishing scam was leaked in these incidents involving financial companies or obtained through some other route,” a financial authority source said. “Damage with a clear causal link, such as unauthorized payments, may be eligible for compensation. If secondary damage occurs, each case will need to be reviewed individually based on the type of loss and how it happened.”

The scope of compensation also remains unclear.

The Financial Supervisory Service and banks introduced a voluntary compensation system in 2024 that shares responsibility for losses from non-face-to-face financial fraud. However, under the current rules, customers who are deceived by scammers and transfer money themselves are excluded from compensation eligibility.

The government has sought to introduce a no-fault compensation system that would require financial companies to cover at least part of the losses suffered by customers who transfer money after falling victim to voice phishing since last year.

However, the relevant amendment to the telecommunications fraud damage refund act remains pending in the National Assembly.

“Compensation for losses caused by customers directly transferring money would depend on the legislation passing,” a financial authority source said. “It does not apply under the current system.”

Past promises of full compensation by financial companies have not automatically resulted in payments for every reported loss.

Seoul Guarantee Insurance pledged full compensation after a ransomware attack in July last year caused service disruptions. In reality, however, compensation was only paid in 24 cases where a causal link was established out of 79 total claims filed through September of that year. The payments totaled 11.9 million won ($8,900).

Disagreements could therefore arise between financial companies and victims over whether future losses were actually caused by the latest data leaks.

“There have been cases involving insider leaks or inadequate security management, but it is difficult to find a precedent for several financial companies being hit at the same time by external attacks like this,” a financial industry source said. “Broad compensation standards need to be developed in consultation with the authorities.”

Compensation for the data leaks themselves, separate from any financial losses that follow, is another issue. Moves toward class-action litigation related to the latest breaches began on Oct. 7.

A court previously awarded some victims 100,000 won each in compensation over personal data leaks involving KB Kookmin Card, NH NongHyup Card and Lotte Card in 2014.

“In the past, compensation for emotional distress was often paid only to consumers who joined lawsuits,” Kang Hyeong-koo, vice president of the Korea Finance Consumer Federation, said. “This time, broader compensation should be considered for the personal data leak itself.”

BY PARK HYUN-JU [[email protected]]

This article was originally written in Korean and translated by a bilingual reporter with the help of generative AI tools. It was then edited by a native English-speaking editor. All AI-assisted translations are reviewed and refined by our newsroom.