Security Issues in the Korean & Global Financial Sector in June 2026

Security Issues in the Korean & Global Financial Sector in June 2026

Statistics on Malware Distributed to the Financial Sector


In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third Attack Stage, demonstrating that multi-stage attack chains—progressing from the initial distribution of bait to the installation of additional malware and ultimately to Information Theft—are widely used.

Among malicious attachments, HTML accounted for the largest share. By file extension, html, js, exe, and vbe were concentrated at the top, with a high proportion of script-based extensions such as js, vbe, vbs, bat, and hta, as well as web document-based extensions such as html, htm, and shtml. This suggests active use of HTML-based phishing pages, HTML smuggling (a technique that uses browsers to conceal and deliver Malicious Files), executing scripts, and LOLBins (a method that exploits legitimate tools).

In the case of Korean-language attachment file names, numerous file names were identified that masqueraded as business documents, tax and payment receipts, and HR and contract-related documents. It was determined that threat actors structured file names to resemble actual business documents in order to gain trust.

Statistics on accounts of Korean industries exfiltrated via Telegram


Cases were documented where domestic account information, collected through malware infections and phishing emails, was leaked to attackers through the Telegram API. The emails used keywords such as “money transfer,” “receipt,” and “voicemail,” and opening the malicious links or HTML attachments led to login pages. During June, domestic financial sector accounts leaked via Telegram accounted for 5% of the total.

Major Deep Web & Dark Web Issues in the Financial Sector


Database Leakage Cases were highlighted as a major threat being sold on the dark web. Notable examples included Canada Life data from canadalife.Com, the Robinhood user database from robinhood.Com, and the Prudential Financial policyholder and beneficiary database from prudential.Com. Each was described as containing sensitive information such as names, email addresses, phone numbers, addresses, account information, Social Security numbers (SSNs), bank account information, and insurance information.

Numerous ransomware and data extortion threats were also identified. LAPSUS$ posted AYA Bank Public Company Limited (ayabank.Com) as a victim, mentioning a data dump of approximately 120 GB along with files related to finance, credit cards, and customer payments. MORPHEUS claimed to have approximately 680 GB of data from HDFC Asset Management Company (HDFC AMC) at hdfcfund.Com, while Qilin posted the Central Bank of Libya (CBL) at cbl.Gov.Ly as a victim.

In terms of cases involving the sale of access credentials, posts related to a Brazilian fintech company were identified. On DarkForums, items listed for sale included access to the WordPress main domain, GitHub organization administrator accounts, MSSQL SA accounts, S3, MinIO, Grafana, and production environments, as well as customer KYC documents and bank account information. Additionally, posts claiming that credit card data from OneFly and Bridgepay was being sold were identified.

Overall, threats to the financial sector in June were characterized by a combination of phishing-based Initial Breach, malware distribution, account information theft, dark web data sales, ransomware, and the trading of access rights.