Breaking
RUIlya Sorokin scored a shutout in the NHL match, the Islanders won with a score of 6:0BRLula faces Flávio Bolsonaro in a polarized presidential election with high rejection and promises of changeJPDodgers win the first game of the district series, Ohtani has one hit, Munetaka Murakami hits his first home run in PSSESuspicious metal object in the water outside Helsinki turned out to be wreckageCNThe co-pilot of a flight from Dubai to Tel Aviv attacked the captain with an ax and the passenger subdued him before landing safely in Saudi ArabiaRUAustralian intelligence agencies are checking the background of Flydubai co-pilot suspected of trying to take control of the planeBREight candidates are running for government of Rio Grande do Norte in the 2026 electionsCNDodger outfielder Tucker's double start in playoff game helps team winARA Ukrainian drone attack on Belgorod causes civilian casualtiesRUVegan-feminist Ivanna Kutsenko was eliminated in the Northern Military District zone in UkraineRUIlya Sorokin scored a shutout in the NHL match, the Islanders won with a score of 6:0BRLula faces Flávio Bolsonaro in a polarized presidential election with high rejection and promises of changeJPDodgers win the first game of the district series, Ohtani has one hit, Munetaka Murakami hits his first home run in PSSESuspicious metal object in the water outside Helsinki turned out to be wreckageCNThe co-pilot of a flight from Dubai to Tel Aviv attacked the captain with an ax and the passenger subdued him before landing safely in Saudi ArabiaRUAustralian intelligence agencies are checking the background of Flydubai co-pilot suspected of trying to take control of the planeBREight candidates are running for government of Rio Grande do Norte in the 2026 electionsCNDodger outfielder Tucker's double start in playoff game helps team winARA Ukrainian drone attack on Belgorod causes civilian casualtiesRUVegan-feminist Ivanna Kutsenko was eliminated in the Northern Military District zone in Ukraine
BackAI hacking attacks spread information leakage throughout the financial sector... Review of complete overhaul of the authorities' security system
AI hacking attacks spread information leakage throughout the financial sector... Review of complete overhaul of the authorities' security system
BREAKING
연합뉴스52 minutes agoTech3 min readSouth KoreaView original

AI hacking attacks spread information leakage throughout the financial sector... Review of complete overhaul of the authorities' security system

Quick Look

Hackers using AI have attacked from all directions, from commercial banks to savings banks, capital companies, and mutual finance companies, leaking a large amount of customer information, and the financial authorities are expected to acknowledge the limitations of existing security capabilities and push for a complete overhaul of the financial sector's security system.

AI-generated summary

Why It Matters

A hacking attack using AI occurred targeting the financial sector, and the same attacker IP as the customer information leak at Shinhan Bank was also detected at other financial institutions such as the Saemaul Geumgo Federation.

Font size

(Seoul = Yonhap News) Reporters Bae Young-kyung, Han Ji-hoon, Chae Sae-rom, Kang Soo-ryun, Lee Do-heun, and Kang Ryu-na = Circumstances are emerging that hackers using artificial intelligence (AI) agents have targeted not only major commercial banks, but also savings banks, capital companies (installment finance companies), and mutual finance companies.

Financial authorities believe that existing security capabilities have limitations in preventing new attacks using AI, and are expected to push for a complete overhaul of the financial security system.

◇ Attack regardless of first and second financial institutions… Securities, insurance, and cards are ‘unconfirmed’

According to financial authorities and the financial sector on the 4th, the Saemaul Geumgo Federation reportedly confirmed an attempt to access the same attacker's Internet address (IP) that stole customer personal information from Shinhan Bank.

The Saemaul Geumgo Federation blocked abnormal access from these overseas IPs with its own security equipment, so it did not suffer any damage from information leaks.

It is known that a similar intrusion attempt was made at Nonghyup Mutual Finance, which shares a network with NH Nonghyup Bank, but the defense was successful.

Yegaram Savings Bank announced on the 2nd that the names, dates of birth, and contact information of approximately 40,000 customers were leaked due to a hacking attack on the 30th of last month.

Hyundai Capital also recognized that the names, contact information, email addresses, and resident registration numbers of 146 loan originators were leaked.

It has been reported that Welcome Savings Bank has also discovered the leak of corporate customer information due to a hacking attack and is currently investigating the exact extent of the damage and the circumstances surrounding the leak.

In the past few days, a wide range of hacking attacks were carried out simultaneously, regardless of first and second financial institutions.

A key official in the financial sector pointed out, “Even if there was no information leak, if you suffer a hacking attack, you must report the breach to the financial authorities.” He added, “There may be far more financial companies that have been attacked this time than are known to the outside world.”

However, it has been reported that no traces of the same attack have been confirmed to date in the securities, insurance, and credit card industries and in government-run banks such as IBK Industrial Bank of Korea and the Export-Import Bank of Korea.

Lee Eok-won, the head of the financial authorities, and Lee Chan-jin, head of the Financial Supervisory Service, will hold an emergency inspection meeting at the Seoul Government Complex this afternoon by convening the heads of all financial sector associations and CEOs of financial companies that have suffered breaches.

Representatives of Shinhan, Kookmin, Hana, Busan Bank, Hyundai Capital, Yegaram, and Welcome Savings Bank are scheduled to attend the meeting.

◇ IP usage in 8 countries… Targeting ‘gaps’ such as internal apps

Authorities note that this attack was not aimed at a specific company, but that vulnerable financial companies were exposed during the random attack using AI.

Since the attack time and methods are similar, it is highly likely that they are the same group. However, there are differences, such as AI not being used in some attacks, so it is expected that it will take time to identify the subject.

In particular, hackers have one thing in common: they steal information by intelligently digging into 'gaps' in employee or non-critical business support systems rather than customer financial business systems.

Unlike customer service counters, we targeted internal homepage menus and apps that did not require strict authentication procedures.

For example, at Shinhan Bank, the 'Loan Counselor Application Loan Progress Inquiry' service used by loan recruiters was used as a route for information leakage.

According to data submitted by Shinhan Bank to the National Assembly, the attacker IP is believed to have been first introduced at 6:04 pm on the 28th of last month. The attack continued for approximately 30 hours until midnight on the 30th, and 25,727 pieces of personal information were leaked.

After becoming aware of the attack at 9:30 a.m. on the 29th, the bank blocked IPs and suspended some services, but attacks targeting six services, including loan application results inquiries on the mobile website, continued.

The hacker obtained valid customer numbers through random input and stole information, and used IPs from several countries, including Korea, the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, and the United Kingdom.

KB Kookmin Bank suffered damage through ‘RM Agent’ and ‘PB Agent’, mobile work support systems for employees.

According to data obtained by the office of Democratic Party of Korea lawmaker Park Min-gyu, the attack continued for 42 hours and 41 minutes from 11:19 p.m. on the 27th of last month to 6:00 p.m. on the 29th. A total of 153 pieces of information, including information on 20 executives and employees, customer names, and mobile phone numbers were leaked, including the encrypted resident registration numbers of some customers.

◇ Authorities “The possibility of additional damage cannot be ruled out”

Some banks where customer information was leaked are known to have temporarily suspended the operation of 'satellite sites' with exposed security vulnerabilities and are keeping an eye on the possibility of secondary damage.

These banks kept customer reporting channels open and promised to provide full compensation in case of damage.

There is also the possibility that, in addition to financial companies where accidents are already known, there may be other companies that have not yet identified damage.

A high-ranking financial authority official said, “We cannot rule out the possibility that additional damage will occur beyond what has been reported to the authorities so far.”

In particular, it is pointed out that non-financial companies with relatively poor information security capabilities may experience delays in detection and response even if they encounter a similar attack.

An official from the financial sector expressed concern, saying, “Private companies may be breached by AI hacking and not be aware of the fact,” and added, “If secondary damage occurs through such a route, it could become a much bigger problem.”

◇ A complete overhaul of the financial security system is expected to be promoted.

There are growing voices calling for a joint response led by financial authorities or across the entire industry.

Another official pointed out, “Advanced AI hacking seems to have gone beyond the level of entrusting response to individual companies,” and added, “There are clear technical limitations in telling companies to stop it on their own and hold them accountable if they fail.”

Even within the authorities, it is judged that it is difficult to block new methods that use AI to find and attack vulnerabilities with existing security capabilities. Accordingly, concerns are being given to the extent to which the security system in the financial sector should be reformed.

In fact, at the emergency response meeting chaired by the Financial Services Commission on the 2nd, it was reported that there was an opinion that a new system was needed as the current response system was disabled. The authorities are expected to convene financial company representatives this afternoon to continue related discussions.

The easing of network separation regulations being promoted by the Financial Services Commission is expected to accelerate.

Currently, domestic financial companies are subject to network separation regulations that require business systems to be separated and blocked from external communication networks for security reasons.

The authorities are in the position that network separation regulations should be completely lifted for financial companies with response capabilities so that they can defend against rapidly evolving AI attacks with AI.

We have been conducting a deregulation test since last June by selecting companies that wish to participate, and companies participating in the second test will be selected on the 7th.

What to Watch

AI outlook — possibilities, not facts

  • Financial authorities will push for a complete overhaul of the financial security system.

    Likely · Within weeks

  • Easing network separation regulations will accelerate.

    Possible · Within months

Open Questions

  • What is the identity of the forces behind the attack?
  • Are there any other financial institutions that have suffered additional damage?
  • What is an effective defense system against AI-based attacks?

Related Topics

This article was originally published by 연합뉴스.

Related Stories

Seoul Research Institute holds a seminar on urban science and technology cooperation through AI and robotics at COEX on the 6th
Developing·

Seoul Research Institute holds a seminar on urban science and technology cooperation through AI and robotics at COEX on the 6th

The Seoul Research Institute announced on the 4th that it will hold an 'Urban Science and Technology Cooperation Seminar through Artificial Intelligence and Robotics' at COEX in Gangnam-gu at 10 am on the 6th. Co-hosted with the Seoul AI Foundation and the Quebec Government Representation to Korea, it shares AI and urban robot policies and international joint research cases in Seoul, Quebec in Canada, and Flanders in Belgium.

연합뉴스
2 min read
Spread of AI hacking threats: Concerns over personal information leakage from OTT, beauty, and payments to banks
Developing·

Spread of AI hacking threats: Concerns over personal information leakage from OTT, beauty, and payments to banks

As personal information leaks continue to occur in communication, distribution, and online platforms, as well as OTT, payment, beauty platforms, and major commercial banks, sensitive life information such as name and contact information, as well as income, loan limit, and consultation and treatment information, is being exposed. In particular, recent banking incidents have raised the possibility of attacks using artificial intelligence, raising concerns that if leaked information is combined, it could lead to secondary damage such as customized phishing.

연합뉴스
2 min read
Former OpenAI employee raises AI safety concerns: “Not enough efforts are being made”
Developing·

Former OpenAI employee raises AI safety concerns: “Not enough efforts are being made”

David Robinson, a former Open AI safety employee, criticized AI companies for focusing on speed rather than safety, and that Open AI's method of improving when it discovers a problem increases the risk of failure. He warned that as AI gets smarter, it could behave differently during testing and deployment, arguing that it needs layers of safety measures like a nuclear power plant.

연합뉴스
2 min read
More on this topicai hacking