According to the report at BraveNewCoin:
"The employee PC, not the head office server, was hacked. Personal information such as mobile phone and email address of some users were leaked. However, some customers were found to have been stolen from because of the disposable password used in electronic financial transactions.”
Few more details on how it was done here: http://biz.khan.co.kr/khan_art_view.html?artid=201707031758001&code=920100 where the attacker posed as an executive of Bithumb.