SEOUL, October 05 (AJP) - Cyberattacks targeting South Korea's financial industry have spread to online investment firms, while regulators say differences in basic security controls appear to have determined how much damage individual companies suffered.
PFC Technologies and Mouda, both online investment-linked finance companies, have disclosed security breaches, expanding the list of affected institutions beyond commercial banks, savings banks and financing companies.
At least seven banks and other traditional financial institutions have reported breaches, including Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital.
Updated figures showed stark differences in the scale of exposure. Shinhan reported 25,727 compromised records, compared with 153 at KB Kookmin and information involving 89 customers at Hana. Yegaram reported about 40,000 exposed records, while Welcome identified roughly 2,200.
Financial authorities found the same attacker IP address in incidents involving commercial banks, although IP addresses identified in attacks on savings banks and financing companies were different. Authorities said the attack methods appeared similar and are examining whether the incidents are connected.
Woori Bank and NH NongHyup Bank were also targeted but successfully blocked the attacks. Securities, insurance and credit card companies have so far reported no confirmed breaches despite facing attempted intrusions.
Regulators and cybersecurity experts said differences in multi-factor authentication, access controls, encryption and management of externally exposed systems appear to have contributed to the wide disparity in damage.
Financial Services Commission Chairman Lee Eog-weon ordered institutions to review externally exposed IT assets and services, authentication and access controls and intrusion-detection systems.
Banks and credit card companies have been instructed to complete emergency security inspections by Oct. 6, while securities firms, insurers, savings banks and electronic financial service providers face an Oct. 8 deadline.
Authorities are also watching for secondary damage, including voice phishing and malicious text-message scams using stolen personal information.
Copyright ⓒ Aju Press All rights reserved.


