Hacking attempts against the financial sector using artificial intelligence are rising sharply, but information security staffing at South Korea's state-run financial institutions has remained flat. Budget and personnel allocations rank low in priority, and market participants say restrictions should be eased at least for information security.
Korea Development Bank had 19 employees dedicated to information security as of the end of last year, down from 23 a year earlier, according to financial industry sources on the 6th. The figure stood at 22 as of the end of June this year. Industrial Bank of Korea (024110) had 46 at the end of last year, up by one over the year, but that is less than half the 118 at NH NongHyup Bank, an institution of comparable size.
Major institutions have seen no change over the past year. The Korea Asset Management Corporation, which handles debt relief for vulnerable borrowers, still has nine dedicated staff. The Export-Import Bank of Korea has nine and the Korea Credit Guarantee Fund has eight. The guarantee fund plans to raise its number to 11 in the second half.
Market participants say the response teams are too small relative to the size of the state financial firms. According to cybersecurity company Palo Alto Networks, the average time from an attempted hacking attack to data exfiltration fell to 72 minutes last year from about 285 minutes in 2024 as AI capabilities advanced. Police on the same day escalated their inquiry into the hacking of financial companies into a formal investigation, booking suspects on charges of violating the Information and Communications Network Act and forming a 28-member dedicated investigation team. President Lee Jae-myung said attacks must be detected in advance and blocked preemptively, adding that it is time to overhaul the security paradigm to fit the AI era.






