Lee Ok-yeon, the Chairman of the Financial Services Commission, emphasized the need to expedite the establishment of AI-based security systems, stating that the possibility of hacking using artificial intelligence (AI) cannot be dismissed in light of recent breaches in the financial sector. The financial authorities are conducting urgent inspections of vulnerable systems and authentication processes across the entire financial sector, and they have pledged to hold accountable those who neglect to respond to shared attack information, should similar incidents occur.
According to the financial sector, Chairman Lee convened an emergency meeting at the Government Seoul Building at 2 p.m. on the 4th, gathering heads of financial associations and CEOs of affected financial companies to assess the response situation. Initially, the financial authorities planned to hold an emergency response meeting on the 7th, but the schedule was moved up due to reports of ongoing breaches in savings banks and capital firms following those in banks.
The meeting included Chairman Lee, Lee Chan-jin, the head of the Financial Supervisory Service, and leaders from major financial associations, including banking, investment, life insurance, non-life insurance, savings banks, credit finance, and fintech. Representatives from financial companies that experienced breaches, such as Shinhan, KB Kookmin, Hana, BNK Busan Bank, Welcome, Ye-garam Savings Bank, and Hyundai Capital, were also present.
In his opening remarks, Chairman Lee stated, "No matter how robust a security system is, a single unmanaged gap can lead to vulnerabilities in the entire system. While no sensitive information has been confirmed to have been leaked so far, the possibility of secondary damage, such as voice phishing, cannot be ruled out. Therefore, we must remain vigilant and proactively respond with full force."
He added, "Cyber threats do not recognize boundaries between financial and non-financial sectors. We will strengthen the cooperation system among relevant ministries, including the Ministry of Science and ICT and the National Police Agency, to respond to breach threats on a government-wide level."
Chairman Lee also mentioned the potential use of AI in these breaches, stressing the need to enhance security systems in response. He stated, "While I cannot say definitively, we cannot rule out the possibility of hacking attacks using AI. As new types of frequent cyberattacks may continue, we must hasten the establishment of security systems that defend against AI attacks with AI."
He continued, "With the rapid changes in AI development, hacking methods that exploit unexpected vulnerabilities are spreading quickly. I hope the financial sector actively participates in policies such as AI security testing and accelerates the transition to AI-based security systems."
The financial authorities suspect that the recent series of hacking incidents may have been carried out by the same attacker. This suspicion arises from the discovery of the same attacker's Internet Protocol (IP) address across multiple financial companies, as well as indications that the attacker continued the attacks while changing IP addresses.
In particular, it is presumed that the attacker may have conducted large-scale automated attacks on multiple financial companies using AI tools. The main attack routes focused on auxiliary systems, such as employee and loan recruitment support systems or websites, rather than the core systems that handle key financial transactions.
To prevent similar incidents from recurring, the Financial Supervisory Service has instructed all financial institutions to conduct a thorough investigation of services with inadequate authentication procedures and to correct any errors, with the possibility of service suspension if necessary. Additionally, banks and card companies have been directed to complete their self-checks by October 6, while securities, insurance, savings banks, and electronic financial service providers must finish by October 8. After analyzing the results, any deficiencies identified will require prompt remediation.
Chairman Lee stated, "Despite the availability of shared attack information and incident cases, if similar incidents occur due to negligence in necessary inspections and responses, we will hold those responsible strictly in accordance with relevant laws."
Currently, the financial sector is on high alert following the discovery of widespread hacking attacks at Shinhan, KB Kookmin, Hana, BNK Busan Bank, and others between September 30 and October 3. In response, President Yoon Suk-yeol has also directed thorough investigations and the establishment of countermeasures.
Kang Yu-jeong, the Chief Spokesperson for the Blue House, stated on the 4th, "President Yoon has been briefed on the recent incidents of personal information leaks at financial and public institutions and the current response status. He has instructed that a serious approach be taken to ensure thorough investigations and the establishment of effective measures."
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.
