AI hacking attacks spread to Saemaeul Geumgo following savings banks and capital... Representatives of financial authorities convened
Quick Look
- Hackers using AI attacked the financial sector in all directions, including commercial banks, savings banks, capital companies, and Saemaeul Geumgo, and customer information leaks were confirmed in some institutions.
- Financial authorities acknowledge the limitations of existing security capabilities and are pushing for a complete overhaul of the financial sector's security system, and plan to convene representatives of financial companies today to discuss response plans.
AI-generated summary
Why It Matters
Hacking attacks using AI are spreading targeting the financial sector, and it has been repeatedly mentioned that existing security systems have limitations in preventing these new attacks.
Banks suspend operation of 'satellite sites' due to security vulnerabilities... “There are limits to individual company responses.”
(Seoul = Yonhap News) Reporters Bae Young-kyung, Han Ji-hoon, Chae Sae-rom, Kang Soo-ryun, and Lee Do-heun = Circumstances are emerging that hackers using artificial intelligence (AI) agents have targeted not only major commercial banks, but also savings banks, capital companies (installment finance companies), and mutual finance companies.
Financial authorities believe that existing security capabilities have limitations in preventing new attacks using AI, and are expected to push for a complete overhaul of the financial security system.
◇ Attack regardless of first and second financial institutions… Securities, insurance, and cards are ‘unconfirmed’
According to financial authorities and the financial sector on the 4th, the Saemaul Geumgo Federation reportedly confirmed an attempt to access the same attacker's Internet address (IP) that stole customer personal information from Shinhan Bank.
The Saemaul Geumgo Federation blocked abnormal access from these overseas IPs with its own security equipment, so it did not suffer any damage from information leaks.
It is known that a similar intrusion attempt was made at Nonghyup Mutual Finance, which shares a network with NH Nonghyup Bank, but the defense was successful.
Yegaram Savings Bank announced on the 2nd that the names, dates of birth, and contact information of approximately 40,000 customers were leaked due to a hacking attack on the 30th of last month.
Hyundai Capital also recognized that the names, contact information, email addresses, and resident registration numbers of 146 loan originators were leaked.
In the past few days, a wide range of hacking attacks were carried out simultaneously, regardless of first and second financial institutions.
A key official in the financial sector pointed out, “Even if there was no information leak, if you suffer a hacking attack, you must report the breach to the financial authorities.” He added, “There may be far more financial companies that have been attacked this time than are known to the outside world.”
However, it has been reported that no traces of the same attack have been confirmed to date in the securities, insurance, and credit card industries and in government-run banks such as IBK Industrial Bank of Korea and the Export-Import Bank of Korea.
◇ IP usage in 8 countries… Targeting ‘gaps’ such as internal apps
Authorities note that this attack was not aimed at a specific company, but that vulnerable financial companies were exposed during the random attack using AI.
Since the attack time and methods are similar, it is highly likely that they are the same group. However, there are differences, such as AI not being used in some attacks, so it is expected that it will take time to identify the subject.
In particular, hackers have one thing in common: they steal information by intelligently digging into 'gaps' in employee or non-critical business support systems rather than customer financial business systems.
Unlike customer service counters, we targeted internal homepage menus and apps that did not require strict authentication procedures.
For example, at Shinhan Bank, the 'Loan Counselor Application Loan Progress Inquiry' service used by loan recruiters was used as a route for information leakage.
According to data submitted by Shinhan Bank to the National Assembly, the attacker IP is believed to have been first introduced at 6:04 pm on the 28th of last month. The attack continued for approximately 30 hours until midnight on the 30th, and 25,727 pieces of personal information were leaked.
After becoming aware of the attack at 9:30 a.m. on the 29th, the bank blocked IPs and suspended some services, but attacks targeting six services, including loan application results inquiries on the mobile website, continued.
The hacker obtained valid customer numbers through random input and stole information, and used IPs from several countries, including Korea, the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, and the United Kingdom.
KB Kookmin Bank suffered damage through ‘RM Agent’ and ‘PB Agent’, mobile work support systems for employees.
According to data obtained by the office of Democratic Party of Korea lawmaker Park Min-gyu, the attack continued for 42 hours and 41 minutes from 11:19 p.m. on the 27th of last month to 6:00 p.m. on the 29th. A total of 153 pieces of information, including information on 20 executives and employees, customer names, and mobile phone numbers, were leaked, including the encrypted resident registration numbers of some customers.
◇ Authorities “The possibility of additional damage cannot be ruled out”
Some banks where customer information was leaked are known to have temporarily suspended the operation of 'satellite sites' with exposed security vulnerabilities and are keeping an eye on the possibility of secondary damage.
These banks kept customer reporting channels open and promised to provide full compensation in case of damage.
There is also the possibility that, in addition to financial companies where accidents are already known, there may be other companies that have not yet identified damage.
A high-ranking financial authority official said, “We cannot rule out the possibility that additional damage will occur beyond what has been reported to the authorities so far.”
In particular, it is pointed out that non-financial companies with relatively poor information security capabilities may experience delays in detection and response even if they encounter a similar attack.
An official from the financial sector expressed concern, saying, “Private companies may be breached by AI hacking and not be aware of the fact,” and added, “If secondary damage occurs through such a route, it could become a much bigger problem.”
◇ A complete overhaul of the financial security system is expected to be promoted.
There are growing voices calling for a joint response led by financial authorities or across the entire industry.
Another official pointed out, “Advanced AI hacking seems to have gone beyond the level of entrusting response to individual companies,” and added, “There are clear technical limitations in telling companies to stop it on their own and hold them accountable if they fail.”
Even within the authorities, it is judged that it is difficult to block new methods that use AI to find and attack vulnerabilities with existing security capabilities. Accordingly, there is an atmosphere of consideration to the extent to which the plutocracy security system should be reformed.
In fact, at the emergency response meeting chaired by the Financial Services Commission on the 2nd, it was reported that there was an opinion that a new system was needed as the current response system was disabled. The authorities are expected to convene financial company representatives this afternoon to continue related discussions.
The easing of network separation regulations being promoted by the Financial Services Commission is expected to accelerate.
Currently, domestic financial companies are subject to network separation regulations that require business systems to be separated and blocked from external communication networks for security reasons.
The authorities are in the position that network separation regulations should be completely lifted for financial companies with response capabilities so that they can defend against rapidly evolving AI attacks with AI.
We have been conducting a deregulation test since last June by selecting companies that wish to participate, and companies participating in the second test will be selected on the 7th.
What to Watch
AI outlook — possibilities, not facts
Financial authorities will convene representatives of financial companies to present directions for a complete overhaul of the security system.
Likely · Within days
Relaxation of network separation regulations will be partially applied after pilot testing to increase AI attack defense capabilities
Possible · Within weeks
Open Questions
- What are the identity and background of the hackers?
- Which financial institutions were additionally affected?
- What are the chances of misuse of leaked personal information?
- What is the specific direction of the security system reform promoted by the financial authorities?







