AIComputers

Korea Ratings Flags Cyber Risk as Credit Factor for Banks

The rating agency's new report names IT outsourcing concentration and operational resilience as key evaluation items for banks.

Korea Ratings has published a report titled "Cyber Risk and Credit Risk of Financial Companies in the AI Era," in which it argues that cyber risk is evolving into a complex credit risk factor for financial companies, according to inews24.com.

The rating agency said it plans to consider introducing exposure-measuring metrics into its qualitative cyber risk assessment. It also listed IT outsourcing concentration and operational resilience as key evaluation items for banks.

The report comes after a series of intrusion incidents at South Korean banks. Shinhan Bank, KB Kookmin Bank and Hana Bank recently suffered breaches targeting external business interfaces such as loan recruiter, employee and sales support systems.

In the Shinhan Bank incident, about 25,000 customers' personal information was leaked through an attack on a loan recruiter-only service. At KB Kookmin Bank and Hana Bank, 119 and 89 customers' personal information were leaked respectively.

In 2025, Lotte Card suffered a large-scale personal information leak, and Korea Ratings downgraded the mapping of its "management and risk management" evaluation factor in its regular assessment in March 2025.

Quick answers

What did the Korea Ratings report say about cyber risk?

Korea Ratings said cyber risk is evolving into a complex credit risk factor for financial companies and that it plans to consider introducing exposure-measuring metrics for its qualitative cyber risk assessment.

Which evaluation items did Korea Ratings list for banks?

It listed IT outsourcing concentration and operational resilience as key evaluation items for banks.

Source