Hana Bank said on October 2, 2026 that attackers reached its ODS sales support system and exposed personal information for 89 customers, including resident registration numbers, names, addresses, emails, phones, and employer names. Korea Herald quotes the bank stressing ODS is separate from internet and mobile banking and that financial transaction data was not leaked. The admission came hours after KB Kookmin’s 119-customer notice and a day after Shinhan’s much larger loan-inquiry breach — a cluster that pushed the Financial Services Commission into an emergency session.
Canonical: https://breachhistory.com/hana-bank/hana-bank-ods2026.
What happened
Hana said it learned of sector hacking attempts, alerted the FSS, blocked the suspect IP, reviewed similar systems, stood up emergency teams, and began notifying customers with a full-compensation pledge. Officials apologized publicly for customer concern.
Timeline
- Oct 1 — Shinhan confirms ~25k leak; sector on alert.
- Oct 1–2 — Hana detects/contains ODS intrusion path (bank narrative via press).
- Oct 2 — Public confirmation of 89 customers; FSC meeting.
Data and stakes
RRNs plus workplace names enable impersonation that sounds like a bank KYC call from someone who “already knows your employer.” That is the practical fraud model even when core banking ledgers stay dark.
Action items
- Follow only Hana’s official notice channels.
- Refuse remote-support apps from cold callers.
- Document any loss for the compensation process.
- Watch for email change-of-contact scams citing the breach.
Sources
Sector lesson
ODS-class tools are the soft underbelly of relationship banking. Harden them like production, or expect more 89- and 119-person notices after every large peer breach.
Technical depth and open questions
Public sources rarely ship full packet captures. Readers should separate three layers: (1) what the victim or regulator attested, (2) what reputable press quoted from those attestations, and (3) what actors claimed on leak sites. Mixing the layers is how unverified counts become “facts” in viral posts. For this incident, stick to layer one and two unless a sentence is explicitly marked as an actor claim.
Open questions usually include exact malware family, full population beyond the first filing, whether backups were hit, and whether downstream vendors were entry points. Absence of answers is normal in week one. It is not permission to invent them.
Phishing and social-engineering playbook to expect
Expect lookalike domains, fake “incident response” WhatsApp accounts, and urgency around deadlines that do not appear in official letters. Ask for a ticket number and hang up; call the number printed on a prior legitimate statement. Do not install remote-support tools. Do not pay cryptocurrency to strangers who claim they can delete your file from a dump.
Employees should treat internal IT tickets that arrive only by SMS as hostile. Vendors should verify purchase-order changes by phone using a known number, not the number in the email signature block.
How this compares to neighboring BreachHistory rows
Cross-read related finance, healthcare, and ransomware claim posts already on BreachHistory for pattern recognition — shared vendor risk, short access windows, and delayed consumer mailings show up again and again in 2026. Use those comparisons to brief executives, not to copy unverified counts from one row into another.
When regulators publish a revised census or the victim issues a post-mortem, the catalog row and this blog’s canonical link are the places to watch. Screenshots age badly; URLs that we update do not.
Checklist for security teams
- Inventory every “non-core” system that still stores customer or patient identifiers.
- Require phishing-resistant MFA on those systems.
- Log and alert on bulk exports.
- Pre-draft customer notice templates approved by counsel.
- Tabletop a 72-hour extortion email scenario with legal and PR in the room.
Those five steps are cheaper than learning them during an all-hands on a national holiday.
Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.
Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.
Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.
Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.
Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.
Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.