Online investment-linked finance (P2P) has reportedly been targeted by hacking attacks prior to recent breaches in the banking sector. Some of the Internet Protocol (IP) addresses used in these attacks overlap with those used in the Shinhan Bank breach. Financial authorities plan to convene an emergency meeting with the P2P finance sector to investigate these connections.
According to the financial sector on October 5, the Financial Services Commission (FSC) is set to gather the Online Investment-Linked Finance Association and the P2P companies involved in recent personal information leaks on October 6.
The FSC has been compiling data on companies that have confirmed actual information leaks or attempted attacks after additional hacking-related personal information leaks were reported in the P2P sector the previous day.
Currently, the P2P companies confirmed to have experienced personal information leaks include PFCT (formerly PeopleFund) and Mooda. PFCT reported that on September 27 at 3:30 a.m., unauthorized external access led to the leak of personal information for 302 customers. The leaked information included names, resident registration numbers, and phone numbers, but did not involve loan-related data.
Mooda also reported that from noon on the same day until 2 a.m. the following day, a third party illegally accessed its website, raising concerns about potential information leaks.
These incidents occurred before the breaches reported in the banking sector. KB Kookmin Bank's initial breach was recorded on September 27 at 11:19 p.m., followed by Shinhan Bank at 6:04 p.m. on September 28, and Hana Bank at 12:16 p.m. on September 30. PFCT and Mooda were attacked earlier on September 27, both in the early morning and afternoon.
Commonalities have also been found among the IP addresses used in the attacks. The Financial Security Institute shared the IP addresses identified during the Shinhan Bank attack with the financial sector on October 1, and P2P companies have reported matches with their own breach records.
As a result, it is increasingly likely that the attacks on P2P companies and banks were carried out by the same attacker or group. Financial authorities are expected to confirm the connections based on the breach paths, attack methods, and IP addresses of each company.
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.
