South Korean lender Hyundai Capital confirmed today that attackers scraped the personal data of 146 of its mortgage loan brokers from a public lookup page. The haul included names, mobile phone numbers, email addresses and resident registration numbers, the Korean national ID that cannot be changed. No retail customer data leaked and no internal systems were reached, according to the company.
The number is small. That is not the point. Four of the six data fields were already public on the page. The other two were not, and one of them stays valid for the rest of the victim's life. Here is what happened, what is confirmed and what is not, and what to do about it.
How 146 brokers' data came off a public page
On 3 October 2026, Hyundai Capital said it had confirmed an attack on its mortgage loan broker inquiry page through an overseas IP address. Per the company, the attack was confirmed at around 5:08 p.m. on 2 October. The page exists so customers can look up public information on the company's mortgage loan brokers. The attackers ran repeated information queries against it.
What came out: 146 brokers' names, mobile phone numbers, email addresses and Credit Finance Association registration numbers, all of which were publicly visible on the page anyway, plus internal broker ID numbers and resident registration numbers, which were not. The company blocked the attacking IP and took the page down, formed an incident response task force, and reported the incident to the Financial Supervisory Service and the Korea Internet and Security Agency (KISA) at about 3:30 p.m. on 3 October. It says it notified the affected brokers directly and is now reviewing every externally accessible web page, with real-time monitoring running.
Now the honesty part. Two things in the coverage conflict, and I will not smooth over it. Early versions of the reporting described the attack as an AI-assisted information query. The latest version of the ChosunBiz report says it has not yet been confirmed whether AI was involved. So AI involvement is reported but unconfirmed. Similarly, neither report says whether the resident registration numbers were fully exfiltrated or merely queryable, or how long the queries ran before detection. Do not trust anyone who fills in those blanks today. Seoul Economic Daily's coverage adds the timing detail and the company quote, and agrees with ChosunBiz on everything else, which is as close to solid ground as first-hour reporting gets.
Why the resident registration number is the real damage
A resident registration number is South Korea's national ID: 13 digits issued to every resident, with the first six digits encoding your date of birth. It is used for banking, employment and identity checks across the country. And unlike a password or a card number, it cannot be changed when it leaks. The RRN is unchangeable per person, unlike the US Social Security number, which can be reissued in some cases.
Think about what the attacker holds. A name, a mobile number, a work email address and a permanent national identifier. The email part means spear phishing with perfect personalisation: mail that knows your name, your job and your ID number. Add the phone and it becomes vishing, the voice-call version, where a scammer quoting your RRN sounds like someone from your bank. And the RRN on its own works for identity fraud in any Korean system that asks for it. A complete starter kit. One that cannot be reissued.
This is also why the "only 146 people" framing misses the damage. 146 emails alone is a spam problem that fades in months. 146 names, phones, emails and permanent national IDs is an identity-fraud inventory that stays useful for decades. The metric is not size. It is rotatability.
The wave this breach belongs to
Hyundai Capital is not a one-off: it is the latest name on a list that has been growing all week across South Korean finance. The same reporting notes Shinhan Bank lost about 25,000 customers' information on 1 October, Hana Bank 89 and KB Kookmin Bank 119 customers on 2 October, and BNK Busan Bank saw 11 outsourced development employees' data exposed. Savings banks are in it too: Yegaram Savings Bank estimates around 40,000 customers affected. Attempts at Woori Bank and NH NongHyup Bank produced no confirmed customer leaks so far. The Financial Services Commission, the Financial Supervisory Service and the Financial Security Institute are now investigating the damage across the sector.
Small brokers' pages and big banks' databases, hit in the same week, in the same pattern: automated information queries, some of them reportedly AI-assisted, hammering externally reachable pages and APIs. The public front door is the new attack surface.
What the attack actually looked like
An information-query attack is a boring name for a simple idea. A public lookup page shows you a little data per search: type a name, get a broker's details. An attacker automates the searching. Ten thousand queries later, the trickle is a dataset. Nothing is broken into. The page does exactly what it was built to do, only at a speed no human uses it at.
That is also why the fix is awkward: the brokers did nothing wrong, and the page was doing its job. The gap is on the server side: query-rate limits, bot detection on lookup endpoints, and field-level access control so that internal identifiers like broker IDs and RRNs never sit behind a public lookup in the first place. Why they sat there is a question the company's incident response task force will have to answer.
If you are one of the 146 brokers
If you are one of the 146 brokers, Hyundai Capital says you have been notified. Treat every unsolicited call, text or email that quotes your resident registration number or broker ID as hostile until proven otherwise. No bank, regulator or Hyundai Capital employee will ask you to confirm those numbers over the phone, because they already have them. Report phishing attempts to KISA, and check whether your address appears in known breach data at Have I Been Pwned (it will not be listed yet; new breaches take weeks to appear). Turn on its breach notifications while you are there.
For everyone else, the general drill stands: check the breach database, assume the phishers have the details, never click through on "verify your account" links. The full checklist lives in our breach response guide.
What an email alias would have changed
An alias would not have stopped the scraping. Nothing on the victim side stops a company page from answering automated queries.
What it changes is everything after. Those 146 email addresses now sit in a dataset paired with names, phone numbers and national IDs. Phishing mail to those addresses will be extremely convincing. If each broker had handed Hyundai Capital a dedicated alias instead of their real work address, every "broker" email would arrive at an address that names its source. The alias list becomes a map of who holds which address, which our guide on telling which website leaked your email walks through. And the day the alias starts receiving mail it should not, it gets switched off. The real work inbox, the one you cannot switch off, stays out of the dataset entirely.
I run AliasFleet, which does this: one alias per site, forwarding to your real inbox, killable in one click. The free tier covers 10 active aliases. The mechanics are explained properly in our guide on what an email alias is.
Can anything undo a leaked resident registration number?
No. That is the honest answer, and it is the reason this breach matters more than its size suggests. The RRNs are out. They do not expire, they are not reissued, and they do not lose their usefulness. The 146 brokers carry this exposure for life.
What can be limited is what the leaked addresses do next. An unchangeable identifier paired with a killable address is a much smaller problem than an unchangeable identifier paired with an inbox you can never switch off. Control what you can. That is the whole game.
Top comments (0)