INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Financial Authority Information Leaked in Voice Phishing Attack

| 2026-10-08 12:17 CRITICAL LOW DATA BREACH PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
A recent incident of personal data leaks at domestic financial institutions has led to concerns about 2nd financial scams, such as voice phishing and smishing, exploiting the leaked information. As of October 6, there were no confirmed cases of customer funds being leaked due to the leak, but regulatory bodies have warned that scammers can access victims' names, incomes, and loan information with precision, making it easy to mistake contact information for a real financial institution employee. The attack works by sending text messages claiming to offer special loans or interest rate reductions, convincing victims to click on URLs or deposit money into their accounts, potentially leading to the theft of personal information stored on mobile devices or hijacked financial transactions. Currently, there is no confirmed status update on the incident's resolution, but authorities recommend using preventive measures such as blocking loan applications and account openings through services like 'Financial Transaction Anxiety Prevention Service'.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope financefinance
Incident Timeline
‎October 6
Regulatory bodies warned on October 6 that leaked personal data from a voice phishing incident did not include passwords or one-time passwords.
organisation OTP
‎October 6 to one month
A financial regulatory agency designated a Special Response Period for Personal Information Leaks from October 6 to one month, requiring financial institutions to operate dedicated counseling channels and strengthen the detection of suspicious transactions.
‎2026/10/08
Threat actors used voice phishing to target individuals, potentially exploiting leaked financial information.
organisation Financial Authority Information Leaks Used
organisation The Financial Services Commission
organisation the Financial Supervisory Service
organisation Loan Anxiety Prevention Service'
organisation payinfo.or.kr
organisation The Financial Supervisory Service's
organisation the Korea Communications Commission Authority
organisation Commission