Recent hacking incidents in the financial sector suggest that the same attacker utilized artificial intelligence (AI) tools to conduct large-scale automated attacks on multiple financial institutions. Financial authorities have shared the attacker's internet protocol (IP) addresses and security precautions with approximately 500 firms across the sector and initiated urgent inspections.
According to financial authorities, multiple IP addresses believed to be used by the same attacker have been identified in hacking incidents involving Shinhan, KB Kookmin, Hana, BNK Busan Bank, as well as Yeogaram, Welcome Savings Bank, and Hyundai Capital.
The attacker reportedly changed IP addresses while targeting various financial institutions. Authorities believe the attacker employed AI tools to execute extensive automated attacks.
Data reported by Shinhan Bank to the National Assembly indicates that the hacking incident involved IP addresses from several countries, including South Korea, the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, and the United Kingdom.
Information was leaked through a supplementary system used by employees and loan recruiters at Shinhan Bank. However, customer services such as internet and mobile banking were not affected, and no financial losses have been reported.
Financial authorities have categorized the hacking incidents into three main types: information inquiry services, employee support services, and website services, and are taking appropriate measures.
In the information inquiry services, cases were identified where systems were improperly developed, allowing access to loan application histories or corporate representative information without proper identity verification. Authorities have mandated a comprehensive review of services lacking authentication procedures to correct errors or block services as necessary.
In the employee support services used by private bankers and corporate finance specialists, it was determined that mobile device access controls were inadequate, and web vulnerabilities allowed unauthorized access, leading to information theft. Financial institutions are required to strengthen access controls to only allow connections from pre-registered devices and to promptly improve vulnerable web services.
In the website services, hackers exploited known security vulnerabilities to install malware and steal log files containing customer information. Authorities have instructed immediate remediation of related vulnerabilities or service suspension if necessary.
The Financial Supervisory Service has disseminated the IP addresses used in the attacks and security precautions to about 500 firms in the financial sector and has ordered urgent inspections. Banks and card companies must complete their inspections by October 6, while securities, insurance, savings banks, and electronic financial service providers have until October 8.
Financial institutions are to conduct inspections based on a checklist of 12 items, including blocking attack IPs, investigating potential damages, identifying externally exposed IT assets and services, and enhancing security. Any deficiencies found must be addressed immediately.
Financial authorities plan to conduct on-site inspections at the affected financial institutions and share identified vulnerabilities and improvement cases across the sector to prevent similar incidents in the future.
Since the hacking incidents occurred, financial authorities have held three emergency response meetings. The latest meeting included heads of financial associations and executives from the affected institutions to discuss response strategies.
Lee Ok-yeon, chair of the Financial Services Commission, stated, “The entire financial sector must recognize the seriousness of the current situation and maintain the highest level of vigilance,” urging thorough security checks and consumer protection measures.
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.
