
The same attacker IP was discovered in breaches of 7 companies, including Shinhan, KB Kookmin, and Hana Bank... Financial authorities order emergency inspection
Financial authorities detected circumstances in which the same attacker carried out an automated attack using artificial intelligence (AI) tools in the recent hacking incident at seven financial companies, including Shinhan, KB Kookmin, and Hana Bank, and ordered an emergency inspection across the entire financial sector.
AI-generated summary
Recently, hacking and information leakage incidents by the same attacker occurred at several financial companies, including banks.
(Seoul = Yonhap News) Reporter Kang Soo-ryun and Kang Ryu-na = In recent hacking incidents at banks, it was discovered that the same attacker used artificial intelligence (AI) tools to attack.
According to the financial authorities on the 4th, the same attacker's Internet address (IP) was found in several places in the breaches of seven companies, including Shinhan, KB Kookmin, Hana, BNK Busan Bank, Yegaram, Welcome Savings Bank, and Hyundai Capital.
It was discovered that the attacker continued to attack by changing the IP.
It is believed that the attacker used AI tools to carry out mass automated attacks targeting multiple financial companies.
According to data reported by Shinhan Bank to the National Assembly, in the case of the Shinhan Bank hacking incident, the attacker used IPs from several countries, including Korea, the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, and the United Kingdom.
Information was leaked from an additional system for employee and loan recruitment, and it was found that there was no impact on customer services such as internet or mobile banking or any financial damage.
Financial authorities categorized hacking incidents into three types and responded to them.
In the case of the information inquiry service, it was confirmed that the development was incorrect so that loan application details or company representative information could be searched without identity verification. Accordingly, all services missing the authentication process were investigated and the errors corrected or the service blocked.
In the case of employee work support services such as PB and RM, information was believed to have been stolen because mobile terminal access control was omitted or web vulnerabilities that could be accessed without permission were not addressed. Financial companies must strengthen controls to ensure access only through pre-registered terminals, and immediately improve vulnerable web services.
It was discovered that a hacker had dug into a known security vulnerability in the homepage service, installed malware, and stolen log files containing customer information. As a result, security controls are strengthened, such as taking action on known vulnerabilities or blocking services.
The Financial Supervisory Service disseminated attack IPs and security precautions to about 500 companies across the financial sector. Banks and credit cards must complete emergency inspections by the 6th, and securities, insurance, savings banks, and electronic finance companies must complete emergency inspections by the 8th.
They must be checked according to a checklist that includes 12 items, including โฒblocking the attacking IP and investigating damage, โฒidentifying externally exposed IT assets and services, and โฒwhether security has been strengthened. If any insufficiencies are found, they must be immediately supplemented.
Financial authorities plan to inspect the company where the accident occurred and inform the entire financial sector of vulnerability factors and improvement cases based on the inspection results to prevent similar accidents from recurring.
Meanwhile, financial authorities have held a total of three emergency response meetings since the hacking incident occurred until today. On this day, chairmen of all financial sectors and executives of financial companies that experienced breaches were convened to discuss response plans.
Financial Services Commission Chairman Lee Eok-won said, โIt is time for the entire financial sector to be seriously aware of the current situation and have the highest level of alertness,โ and called for thorough security checks and consumer protection measures.
AI outlook โ possibilities, not facts
Completed emergency security inspection of all financial institutions
Very likely ยท Within days

From January to August of this year, there were approximately 240,000 hacking attempts targeting the court computer network, significantly exceeding the number of hacking attempts for the entire year last year. In addition, cases of personal information leakage due to mistakes by internal employees or AI-related factors were found to have increased significantly compared to previous years.

Customer information leaks due to hacking attacks have been confirmed one after another in the financial and on2 industries, including Welcome Savings Bank, PF Technologies, and Mouda. Authorities are determining the exact extent and circumstances of the damage.

In the hacking incidents of seven financial companies, including Shinhan, Kookmin, and Hana Bank, circumstances were discovered in which the same attacker carried out mass automated attacks using AI tools. Financial authorities began an emergency security inspection targeting the entire financial sector.

Korea Electric Power Corporation (KEPCO) announced on the 4th that it is operating an emergency response situation room after an incident occurred in which personal information such as the names, affiliations, and phone numbers of about 24,000 employees were exposed through an external web page. No resident registration number or customer information was included.

South Korean President Lee Jae Myung ordered a thorough investigation into recent hacking attacks that leaked personal customer data at major financial institutions including Hana Bank, KB Kookmin Bank, and Shinhan Bank.

Naver announced that the number of simultaneous users of the Asian Games men's soccer finals, which was broadcast live through streaming platform Chizijik, reached 1.23 million. Additionally, the number of AI clip plays that automatically extract key scenes exceeded 53.2 million.