The addresses were traced to 12 countries and regions, including the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, Sweden and Germany, according to financial authorities and industry sources Tuesday. One was traced to South Korea.
Five addresses were traced to the United States, while Japan, Sweden and Germany had two each.
The Financial Supervisory Service (FSS) narrowed down the list after examining suspicious access linked to recent breaches at Shinhan Bank and other financial institutions.
The regulator has distributed the list across the financial sector and asked firms to complete internal inspections and address any weaknesses by Thursday.
The Financial Services Commission (FSC), the FSC and the FSS shared information on known attacks with financial institutions on Oct. 2 and distributed a security checklist to help prevent similar breaches, according to joint statement on Sunday.
Concerning institutions were told to identify all externally exposed IT assets and services and review vulnerabilities, authentication, access controls and intrusion-detection systems. They were asked to promptly complete the inspections and report the results to the regulator.
Authorities also told firms to check that previously shared threat information had been properly incorporated into their detection and blocking systems. The information included attack IP addresses, methods, intrusion attempts and past incidents.
The filing also called on firms to review external access routes, block unnecessary access and limit essential access to the minimum permissions and information required. Systems used by employees and outside contractors were also to be checked for weaknesses that could allow authentication to be bypassed.
Financial firms have since expanded their reviews to cover a longer period and a wider range of systems.
Toss Bank, a South Korean online-only bank, found that two U.S.- based IP addresses linked to the recent attacks had also attempted to access its servers in January. The same addresses were detected again in access attempts in July and August.
The investigation comes as recent breaches have raised concerns over cybersecurity across the country's financial sector.
Shinhan Bank, one of the firms affected by the recent incidents, disclosed that an unauthorized external party had accessed a loan-related service and obtained personal and credit information linked to about 25,000 customers. The bank has pledged to compensate customers for any losses linked to the breach.
Copyright ⓒ Aju Press All rights reserved.