
신한·KB국민·하나은행 등 7개사 침해 사고에서 동일 공격자 IP 발견… 금융당국, 긴급 점검 지시
금융당국이 최근 신한·KB국민·하나은행 등 7개 금융사의 해킹 사고에서 동일한 공격자가 인공지능(AI) 도구를 활용해 자동화된 공격을 감행한 정황을 포착하고, 전 금융권에 긴급 점검을 지시했다.
AI-generated summary
최근 은행 등 여러 금융사에서 동일 공격자의 해킹 및 정보 유출 사고가 발생함.
(서울=연합뉴스) 강수련 강류나 기자 = 최근 은행 등 해킹사고에서 동일 공격자가 인공지능(AI) 도구를 활용해 공격한 정황이 발견됐다.
4일 금융당국에 따르면, 신한·KB국민·하나·BNK부산은행과 예가람·웰컴저축은행, 현대캐피탈 등 7개사의 침해 사고에서 동일한 공격자의 인터넷주소(IP)가 여러 곳에서 발견됐다.
공격자는 IP를 변경해 지속적으로 공격한 것으로 파악됐다.
공격자는 AI 도구를 활용해 다수 금융사를 대상으로 대량으로 자동화된 공격을 한 것으로 추정된다.
실제 신한은행이 국회에 보고한 자료에 따르면, 신한은행 해킹사고의 경우 공격자가 한국과 미국·일본·홍콩·싱가포르·베트남·태국·영국 등 여러 국가의 IP를 이용했다.
직원·대출모집인용 부가시스템에서 정보가 유출됐으며, 인터넷·모바일뱅킹 등 대고객 서비스 영향이나 금전 피해는 없는 것으로 파악됐다
금융당국은 해킹 사고를 3개 유형으로 분류해 대응하도록 했다.
정보조회 서비스의 경우 본인 확인을 거치지 않고 대출신청 내역이나 기업대표정보를 조회할 수 있도록 개발이 잘못된 것으로 확인됐다. 이에 따라 인증 절차가 누락된 서비스는 전수조사해 오류를 수정하거나 서비스를 차단하도록 했다.
PB, RM 등 직원 업무지원 서비스의 경우에는 모바일 단말기 접근통제가 누락됐거나 권한 없이 접근할 수 있는 웹 취약점에 조치하지 않아 정보가 탈취된 것으로 봤다. 금융사는 사전 등록된 단말기로만 접속할 수 있도록 통제를 강화하고, 취약한 웹서비스는 즉시 개선해야 한다.
홈페이지 서비스는 해커가 이미 알려진 보안 취약점을 파고들어 악성코드를 설치하고, 고객정보가 포함된 로그파일을 탈취한 것으로 파악됐다. 이에 알려진 취약점은 조치하거나 서비스를 차단하는 등 보안 통제를 강화한다.
금감원은 전 금융권 약 500개사에 공격 IP와 보안 유의사항을 전파했다. 은행·카드는 오는 6일까지, 증권·보험·저축은행·전자금융업자 등은 오는 8일까지 긴급 점검을 마쳐야 한다.
이들은 ▲공격 IP 차단 및 피해조사여부 ▲외부노출 IT자산·서비스 식별 ▲보안 강화 여부 등 12개 항목이 포함된 체크리스트에 따라 점검해야 하며, 미흡 사항이 발견되면 즉시 보완해야 한다.
금융당국은 사고발생 회사 현장 점검, 검사 결과에 따라 취약 요인과 개선사례를 전 금융권에 알려 유사 사고가 재발되지 않도록 할 계획이다.
한편, 금융당국은 해킹 사고 발생 이후 이날까지 총 3차례 긴급상황 대응회의를 진행했다. 이날은 전체 금융권 회장과 침해사고 발생 금융사 임원들을 소집해 대응 방안을 논의했다.
이억원 금융위원장은 "금융권 전체가 지금의 상황을 엄중하게 인식하고 최고 수준의 경각심을 가져야 할 시점"이라며 철저한 보안 점검과 소비자 보호 조치를 당부했다.
AI outlook — possibilities, not facts
전 금융권 긴급 보안 점검 완료
Very likely · Within days

State-run Korea Electric Power Corp. announced that personal data of roughly 24,000 employees was leaked on an external website. The exposed data includes names, titles, and phone numbers, though sensitive information remained safe.

The Ministry of Science and ICT has launched a 24-hour emergency response system with the Korea Internet & Security Agency (KISA) in relation to the recent financial hacking incident and has begun to prevent the spread of the virus to the private sector and further damage.

From January to August of this year, there were approximately 240,000 hacking attempts targeting the court computer network, significantly exceeding the number of hacking attempts for the entire year last year. In addition, cases of personal information leakage due to mistakes by internal employees or AI-related factors were found to have increased significantly compared to previous years.

Customer information leaks due to hacking attacks have been confirmed one after another in the financial and on2 industries, including Welcome Savings Bank, PF Technologies, and Mouda. Authorities are determining the exact extent and circumstances of the damage.

In the hacking incidents of seven financial companies, including Shinhan, Kookmin, and Hana Bank, circumstances were discovered in which the same attacker carried out mass automated attacks using AI tools. Financial authorities began an emergency security inspection targeting the entire financial sector.

Korea Electric Power Corporation (KEPCO) announced on the 4th that it is operating an emergency response situation room after an incident occurred in which personal information such as the names, affiliations, and phone numbers of about 24,000 employees were exposed through an external web page. No resident registration number or customer information was included.