South Korean bank breach victims push for class-action compensation
Customers of several major Korean banks are forming class-action lawsuits to seek compensation after personal data leaks, amid unclear claim standards.
A series of personal data breaches at three of South Korea's largest lenders—Shinhan Bank, KB Kookmin Bank and Hana Bank—have affected roughly 25,000, 119 and 89 customers respectively, revealing sensitive personal and financial information. Experts warn that the combination of identifiers and income data makes victims especially prone to AI-enhanced phishing attacks. While the banks have pledged full reimbursement for losses directly linked to the leaks, they have not set clear criteria for qualifying claims, prompting affected customers to organize on a Naver forum and enlist Sedam Law for a class-action suit.
The proposed lawsuit will rely on the Personal Information Protection Act, seeking damages of 100,000 to 300,000 won per plaintiff. Industry officials note that establishing a uniform compensation framework will likely require cooperation between regulators and the banking sector.
Why it matters
The case highlights gaps in data-breach compensation rules and the growing threat of AI-driven fraud in South Korea.
How this story developed
- Oct 4 President Lee orders full inquiry into recent bank data breach incidents
- Oct 5 Regulators have ordered banks to block non‑essential external connections and carry out emergency security audits.
- Oct 6 President Lee ordered allocation of manpower and budget for response as police opened a cyber‑crime investigation.
In this story
Related stories
9 in this thread