Korean Banks Still Run 50-Year-Old COBOL as AI Hacks Mount

■AI Hacking Shock: Fragile Information Security Infrastructure Support Systems Holding Personal Data Left Unguarded Externally Accessible Services Also a Blind Spot Aging Systems Make Patching Vulnerabilities Difficult Information Security Budgets Shrink at Major Banks Routine Oversight Needed, Not One-Off Checks

Finance|
| Updated 2026.10.05. 23:36:19
|
By Shin Joong-seopjseop@sedaily.com
||
null - Seoul Economic Daily Finance News from South Korea

As it happens, the second round of selections falls on the 7th — just after a simultaneous wave of AI-driven hacking attacks on banks, savings banks and capital firms from late last month through early this month.

Experts agree that easing network separation rules for AI security in the financial sector, including the second round of selections, must be accelerated. KB Kookmin Bank, the country's largest lender, was left out of the first round. Security industry officials say the thresholds of 2 trillion won in total assets and 300 employees remain too high a hurdle.

That has prompted calls to speed up follow-up selections and make the arrangement permanent to widen participation. "Even if firms want to run AI to block AI-driven hacking, the financial sector's distinctive network separation rules make that difficult," a security industry official said on the 5th. "Circumstances differ by company, but the selection process needs to move faster to enable AI-based defense."

Some argue the scope of privacy verification and AI security inspections should be broadened as well, with greater security investment to allow close scrutiny of business-support websites and applications. One or two life insurers were also reportedly scanned on the same day in reconnaissance ahead of possible hacking attempts. Toss Bank was found to have fended off hacking attempts from the same IP address used by the attacker who struck Shinhan Bank.

"Financial authorities appear to have focused their AI diagnostics on major systems and failed to examine business-support services closely enough," another security industry official said. "Had they found and patched vulnerabilities in those services, they could have blocked leaks through the same route." The point is that diagnostics should extend to any externally accessible service that holds personal data.

Critics also say individual financial companies must sharply expand investment and hire more specialists. According to information security disclosures compiled by the Korea Internet & Security Agency, Shinhan Bank spent 36.9 billion won last year, down 0.4% from a year earlier, while Woori Bank spent 36.4 billion won, down 18.1%. KB Kookmin Bank spent 43.3 billion won, up 1.9%, and Hana Bank spent 37.2 billion won. "Deregulation needs to come with a sharp increase in information security spending," a financial industry official said.

The small number of financial firms certified under the Personal Information & Information Security Management System (ISMS-P) reflects the same problem. "The financial sector has built its security framework around network separation," said Lee Sang-geun, a professor in the School of Smart Security at Korea University's Graduate School of Information Security. "It's an approach of digging a big moat to keep enemies out, and the belief that they were cut off from the outside led them to relatively neglect internal defenses."

Others note that extending AI hacking defenses across financial IT systems will require stronger capabilities to diagnose and patch legacy systems. "In many cases, functions have been bolted onto aging legacy programs for decades, so even when a vulnerability is known it is hard to fix," a senior financial industry official said. "Not only is it hard to find experts who understand and can overhaul these systems, but years of patchwork updates mean the risk of cascading failures can't be ruled out."

According to financial authorities and the Financial Security Institute, some financial companies are still using old programming languages such as COBOL. Longstanding business processes and data linkage structures make switching languages difficult, so firms stick with the old approach. KB Kookmin Bank went so far as to recruit staff last December to automate the conversion of COBOL to Java using AI.

Within the financial industry, there are calls to translate certifications and AI security tools into real improvements in defense capability — meaning the continuous monitoring of systems that handle personal data and the patching of vulnerabilities must become routine management practice.

Original reporting by Shin Joong-seop for Seoul Economic Daily.

AI-translated from Korean. Quotes from foreign sources are based on Korean-language reports and may not reflect exact original wording.

Watch · Seoul Economic Daily

More →
1:05

AI KEY

Preview
Korean Corporate Intelligence HubKOSPI · KOSDAQ · 12 sectors

A live, cap-weighted view of every KOSPI and KOSDAQ sector, with same-day Korean reporting distilled by company — built for foreign investors, correspondents and analysts who need to scan Korea before the next session.

Korea Company Atlas

Preview
Market Ontology · The Feedback LoopKFTC 2025 · 92 groups · 121,954 articles

An English ontology of the Korean market — how companies, the media, the government and the National Assembly move each other in a loop. Korea's named controlling persons and designated business groups are a mechanism, not a risk to be priced blind.

SIGNAL

Now live
English Edition · Capital MarketsM&A · IPO · PE · Fund Flows

SIGNAL English Edition is live — Korea's deal desk reporting in English. M&A, IPOs, private equity and fund flows, covered daily for global institutional investors. Browse free; subscriber-only scoops at the 50% intro rate.