
AI-generated summary
Over a period of approximately 2 years and 9 months from 2024, 18 incidents presumed to be hacking from overseas occurred in the financial sector, and only a small number of these cases involved the attackers being identified.
In 13 cases, only the country is estimated by IP… In 3 cases, even the country is ‘unknown’
Electronic finance and on-to-business also identified only 1 out of 12 cases... “It is important to develop technology to identify attackers”
(Seoul = Yonhap News) Reporter Kang Soo-ryun = Amid the recent series of hacking incidents in the financial sector, it was found that the attackers were not identified in most of the overseas hacking incidents that occurred after 2024.
According to data submitted by People Power Party lawmaker Song Eon-seok, a member of the National Assembly's Political Affairs Committee, from the Financial Supervisory Service on the 9th, there were 18 incidents presumed to be hacking from overseas at financial companies over a period of about 2 years and 9 months from 2024 to the 8th. Among these, the attackers were identified in only two cases.
The hacking incident of Seoul Guarantee Insurance [031210] in July last year was confirmed to be the work of the international ransomware organization ‘GUNRA’. At that time, the server was infected due to a ransomware attack and service was suspended for about 64 hours, and Seoul Guarantee Insurance compensated customers 11.91 million won.
In the Baro Savings Bank breach in April of this year, the ransomware group 'INC Ransom' directly demanded payment and the subject of the attack was identified.
Of the remaining 16 cases, the attack IP in 13 cases was estimated to be overseas through domain searches, detection of internal security equipment, and investigation of breach incidents, and in 3 cases, the attack subject could not be identified and was classified as 'foreign country unknown'.
Accidents presumed to be hacking origins from China include Lotte Card, which suffered an information leak of 2.97 million customers last year, and SC First Bank and KB Life Insurance incidents in the same year.
In addition, attacks are believed to have occurred in the United States, Bulgaria, Vietnam, Indonesia, Japan, Hong Kong, Taiwan, Seychelles, Thailand, and the United Kingdom. However, even if an overseas IP has been confirmed, it is difficult to identify the actual attacker and its country.
The Financial Supervisory Service recently shared 28 attack IPs, excluding duplicates, along with some country information with the financial sector, emphasizing that caution should be taken in interpreting them due to the possibility of bypass access.
The Financial Supervisory Service also explained in the data submitted to the office of the National Assembly member, "In most cases, attackers alter IPs or access bypasses through virtual private networks (VPNs), etc., so it is virtually impossible to identify the attacker using only national information on the IP location."
Separately, it was not easy to identify the attacker in the overseas hacking incidents that occurred at electronic financial companies and online investment-linked financial companies during the same period.
Among the 12 incidents that occurred in the industry, there was only one incident in which the attacker was identified.
In the case of a distributed denial of service (DDoS) attack that occurred at Eximbay, an electronic financial company, in 2024, the subject of the attack was able to be identified by receiving an attack warning email in the name of 'Alpha Jackals', an external hacker group.
On the other hand, CoM Payments, where a hacking incident using a security vulnerability occurred in late August, was contacted directly by an attacker, but only assumed that the country of the attacker was China.
As police are tracking the attacker of a recent financial hacking incident, it has also been raised that the person behind the attack may be a 26-year-old person living in Guangdong Province, China.
CrowdStrike, a global cybersecurity company based in the United States, assumed the mastermind by detecting clues in the conversation records of 'Claude Code', a generative artificial intelligence (AI) coding tool obtained from the attacker's server. However, the person identified as the hacker reportedly denied any involvement.
As hacking attacks using AI agents are increasing, it is pointed out that it is necessary to have a system and defense system that can identify the attacker.
Rep. Song Eon-seok said, "It is urgent to build an AI-based defense system to respond to hacking. In particular, attackers can bypass or disguise IP addresses, so it is difficult to identify the attacker using foreign IP alone, so developing technology to track the attack path and identify the actual attacker is becoming important."
Meanwhile, according to data from the congressman's office, in relation to this financial sector infringement incident, as of the 6th, no additional infringement incidents occurred other than the seven companies Shinhan, KB Kookmin, Hana, BNK Busan Bank, Yegaram, Welcome Savings Bank, and Hyundai Capital.
AI outlook — possibilities, not facts
The construction of AI-based defense systems in the financial sector will accelerate.
Likely · Within months
Investment in the development of attack path tracking and identification of actual attackers will increase.
Possible · Within months

This month, 6 of the top 10 ETF returns listed in Korea were secondary battery-related products, a result that reflects the improvement in performance of related companies due to the expansion of AI data centers and increased demand for ESS. On the other hand, individual investors made net purchases of inverse ETFs, betting on a decline in the KOSDAQ.

U.S. investment bank Goldman Sachs will pay a total of $500 million in special stock compensation to about 20 top executives. This is in accordance with the long-term performance compensation system introduced in 2021, and is the result of reflecting management performance, such as achieving a 150% stock price return over the past five years.

Coupang has sued South Korea's Personal Information Protection Commission to overturn a record 620 billion won fine imposed following a major data breach affecting over 37 million users and various privacy violations.

SK Group Chairman Choi Tae-won visits Gwangju Military Airport, the site of the Honam semiconductor cluster, on the 9th to check the progress. This is Chairman Choi's first visit to the military airport site, and he will tour the site where the ammunition depot where the semiconductor fab will be located is scheduled to be relocated.

The International Monetary Fund (IMF) announced on the 8th that it has reached a working-level agreement to provide additional financial support worth approximately 1.6 trillion won to Pakistan. Pakistan has maintained macroeconomic stability even in the aftermath of the Middle East war, but it was assessed that risk factors still exist.

To mark the 100th anniversary of Hangeul Day, the food, distribution, and household goods industries are developing Hangul fonts and introducing products and experience events using the Korean language one after another.