← Blog

KB Kookmin Bank Breach: 119 Customers’ Data Leaked

Share on X

KB Kookmin Bank confirmed on October 2, 2026 that personal credit information of 119 customers leaked after abnormal external access to an employee mobile work-support system the night of September 30. Chosun Biz and Korea Times report names, phones, addresses, and encrypted resident registration numbers in the mix — and stress the system was not internet or mobile banking. The disclosure landed one day after Shinhan’s ~25,000-customer loan-inquiry leak, kicking off a multi-bank Korean security scramble.

Canonical: https://breachhistory.com/kb-kookmin-bank/kb-kookmin-bank-mobile2026.

What happened

Kookmin said it spotted possible leakage via abnormal external access, then fully blocked the server and path. Customers were notified individually; a dedicated counseling line joined the main call center; the bank pledged full compensation for resulting losses. Financial transaction systems were described as untouched.

Same-day context matters: Hana (89) and BNK (11 staff) also reported incidents, while FSC/FSS convened an emergency meeting on sector defenses and AI-assisted intrusion tooling suspected in the Shinhan path.

Timeline

  1. Sep 30 night — Abnormal access detected; server blocked.
  2. Oct 1 — Shinhan public fallout continues (~25k).
  3. Oct 2 morning — KB confirms 119-customer leak.
  4. Oct 2 — Hana/BNK reports; FSC emergency meeting.

Data exposed

  • Names
  • Phone numbers
  • Addresses
  • Encrypted resident registration numbers

Encrypted RRN is still sensitive — treat it like hashed-but-identifying national ID material, not harmless noise.

Action items

  1. Use only official KB channels if you were notified.
  2. Ignore “Kookmin security team” crypto or remote-access requests.
  3. Watch SMS KYC links for loan or card upgrades.
  4. If damages occur, use the bank’s counseling center for compensation claims.

Sources

Why employee mobile tools keep getting hit

Sales and support apps sit outside the hardened banking core but still hold customer PII. Attackers prefer them for the same reason brokers do: fast lookups, weaker auth history. Korea’s October wave is a masterclass in that gap.

Technical depth and open questions

Public sources rarely ship full packet captures. Readers should separate three layers: (1) what the victim or regulator attested, (2) what reputable press quoted from those attestations, and (3) what actors claimed on leak sites. Mixing the layers is how unverified counts become “facts” in viral posts. For this incident, stick to layer one and two unless a sentence is explicitly marked as an actor claim.

Open questions usually include exact malware family, full population beyond the first filing, whether backups were hit, and whether downstream vendors were entry points. Absence of answers is normal in week one. It is not permission to invent them.

Phishing and social-engineering playbook to expect

Expect lookalike domains, fake “incident response” WhatsApp accounts, and urgency around deadlines that do not appear in official letters. Ask for a ticket number and hang up; call the number printed on a prior legitimate statement. Do not install remote-support tools. Do not pay cryptocurrency to strangers who claim they can delete your file from a dump.

Employees should treat internal IT tickets that arrive only by SMS as hostile. Vendors should verify purchase-order changes by phone using a known number, not the number in the email signature block.

How this compares to neighboring BreachHistory rows

Cross-read related finance, healthcare, and ransomware claim posts already on BreachHistory for pattern recognition — shared vendor risk, short access windows, and delayed consumer mailings show up again and again in 2026. Use those comparisons to brief executives, not to copy unverified counts from one row into another.

When regulators publish a revised census or the victim issues a post-mortem, the catalog row and this blog’s canonical link are the places to watch. Screenshots age badly; URLs that we update do not.

Checklist for security teams

  1. Inventory every “non-core” system that still stores customer or patient identifiers.
  2. Require phishing-resistant MFA on those systems.
  3. Log and alert on bulk exports.
  4. Pre-draft customer notice templates approved by counsel.
  5. Tabletop a 72-hour extortion email scenario with legal and PR in the room.

Those five steps are cheaper than learning them during an all-hands on a national holiday.

Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.

Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.

Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.

Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.

Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.