Breaking
ARSaudi Arabia overcomes Qatar on penalties and reaches the 27th Gulf Cup final, and a historic victory for jiu-jitsu in the Asia’sTRMissing mentally disabled woman in Büyükorhan was found alive in the forestUSNatalia Silva vs. Wang Cong Set for UFC 332 Main Event in Salt Lake CityTRFerhat Gündoğdu resigned from his position as the President of the Central Referee BoardUSDraftKings Promo Code Offers $150 in Bonus Bets for New Users After $5 WagerRUCorporal Yuri Zelyaev destroyed several militants during a special operationBRVoters must take a tip to vote quickly in the 2026 electionsUSMiami Hurricanes Favored Over Clemson Tigers in Key ACC MatchupARAbdullah Nada wins the 85 kg gold medal in jiu-jitsu at the Asian Games in NagoyaKRHyundai Motor Company's sales are the worst in 16 years excluding 2020... Domestic sales lowest since the 2008 financial crisisARSaudi Arabia overcomes Qatar on penalties and reaches the 27th Gulf Cup final, and a historic victory for jiu-jitsu in the Asia’sTRMissing mentally disabled woman in Büyükorhan was found alive in the forestUSNatalia Silva vs. Wang Cong Set for UFC 332 Main Event in Salt Lake CityTRFerhat Gündoğdu resigned from his position as the President of the Central Referee BoardUSDraftKings Promo Code Offers $150 in Bonus Bets for New Users After $5 WagerRUCorporal Yuri Zelyaev destroyed several militants during a special operationBRVoters must take a tip to vote quickly in the 2026 electionsUSMiami Hurricanes Favored Over Clemson Tigers in Key ACC MatchupARAbdullah Nada wins the 85 kg gold medal in jiu-jitsu at the Asian Games in NagoyaKRHyundai Motor Company's sales are the worst in 16 years excluding 2020... Domestic sales lowest since the 2008 financial crisis
BackAI hacking attacks spread to Saemaeul Geumgo following savings banks and capital... Representatives of financial authorities convened
AI hacking attacks spread to Saemaeul Geumgo following savings banks and capital... Representatives of financial authorities convened
BREAKING
연합뉴스48 minutes agoTech3 min readSouth KoreaView original

AI hacking attacks spread to Saemaeul Geumgo following savings banks and capital... Representatives of financial authorities convened

Quick Look

  • Hackers using AI attacked the financial sector in all directions, including commercial banks, savings banks, capital companies, and Saemaeul Geumgo, and customer information leaks were confirmed in some institutions.
  • Financial authorities acknowledge the limitations of existing security capabilities and are pushing for a complete overhaul of the financial sector's security system, and plan to convene representatives of financial companies today to discuss response plans.

AI-generated summary

Why It Matters

Hacking attacks using AI are spreading targeting the financial sector, and it has been repeatedly mentioned that existing security systems have limitations in preventing these new attacks.

Font size

Banks suspend operation of 'satellite sites' due to security vulnerabilities... “There are limits to individual company responses.”

(Seoul = Yonhap News) Reporters Bae Young-kyung, Han Ji-hoon, Chae Sae-rom, Kang Soo-ryun, and Lee Do-heun = Circumstances are emerging that hackers using artificial intelligence (AI) agents have targeted not only major commercial banks, but also savings banks, capital companies (installment finance companies), and mutual finance companies.

Financial authorities believe that existing security capabilities have limitations in preventing new attacks using AI, and are expected to push for a complete overhaul of the financial security system.

◇ Attack regardless of first and second financial institutions… Securities, insurance, and cards are ‘unconfirmed’

According to financial authorities and the financial sector on the 4th, the Saemaul Geumgo Federation reportedly confirmed an attempt to access the same attacker's Internet address (IP) that stole customer personal information from Shinhan Bank.

The Saemaul Geumgo Federation blocked abnormal access from these overseas IPs with its own security equipment, so it did not suffer any damage from information leaks.

It is known that a similar intrusion attempt was made at Nonghyup Mutual Finance, which shares a network with NH Nonghyup Bank, but the defense was successful.

Yegaram Savings Bank announced on the 2nd that the names, dates of birth, and contact information of approximately 40,000 customers were leaked due to a hacking attack on the 30th of last month.

Hyundai Capital also recognized that the names, contact information, email addresses, and resident registration numbers of 146 loan originators were leaked.

In the past few days, a wide range of hacking attacks were carried out simultaneously, regardless of first and second financial institutions.

A key official in the financial sector pointed out, “Even if there was no information leak, if you suffer a hacking attack, you must report the breach to the financial authorities.” He added, “There may be far more financial companies that have been attacked this time than are known to the outside world.”

However, it has been reported that no traces of the same attack have been confirmed to date in the securities, insurance, and credit card industries and in government-run banks such as IBK Industrial Bank of Korea and the Export-Import Bank of Korea.

◇ IP usage in 8 countries… Targeting ‘gaps’ such as internal apps

Authorities note that this attack was not aimed at a specific company, but that vulnerable financial companies were exposed during the random attack using AI.

Since the attack time and methods are similar, it is highly likely that they are the same group. However, there are differences, such as AI not being used in some attacks, so it is expected that it will take time to identify the subject.

In particular, hackers have one thing in common: they steal information by intelligently digging into 'gaps' in employee or non-critical business support systems rather than customer financial business systems.

Unlike customer service counters, we targeted internal homepage menus and apps that did not require strict authentication procedures.

For example, at Shinhan Bank, the 'Loan Counselor Application Loan Progress Inquiry' service used by loan recruiters was used as a route for information leakage.

According to data submitted by Shinhan Bank to the National Assembly, the attacker IP is believed to have been first introduced at 6:04 pm on the 28th of last month. The attack continued for approximately 30 hours until midnight on the 30th, and 25,727 pieces of personal information were leaked.

After becoming aware of the attack at 9:30 a.m. on the 29th, the bank blocked IPs and suspended some services, but attacks targeting six services, including loan application results inquiries on the mobile website, continued.

The hacker obtained valid customer numbers through random input and stole information, and used IPs from several countries, including Korea, the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, and the United Kingdom.

KB Kookmin Bank suffered damage through ‘RM Agent’ and ‘PB Agent’, mobile work support systems for employees.

According to data obtained by the office of Democratic Party of Korea lawmaker Park Min-gyu, the attack continued for 42 hours and 41 minutes from 11:19 p.m. on the 27th of last month to 6:00 p.m. on the 29th. A total of 153 pieces of information, including information on 20 executives and employees, customer names, and mobile phone numbers, were leaked, including the encrypted resident registration numbers of some customers.

◇ Authorities “The possibility of additional damage cannot be ruled out”

Some banks where customer information was leaked are known to have temporarily suspended the operation of 'satellite sites' with exposed security vulnerabilities and are keeping an eye on the possibility of secondary damage.

These banks kept customer reporting channels open and promised to provide full compensation in case of damage.

There is also the possibility that, in addition to financial companies where accidents are already known, there may be other companies that have not yet identified damage.

A high-ranking financial authority official said, “We cannot rule out the possibility that additional damage will occur beyond what has been reported to the authorities so far.”

In particular, it is pointed out that non-financial companies with relatively poor information security capabilities may experience delays in detection and response even if they encounter a similar attack.

An official from the financial sector expressed concern, saying, “Private companies may be breached by AI hacking and not be aware of the fact,” and added, “If secondary damage occurs through such a route, it could become a much bigger problem.”

◇ A complete overhaul of the financial security system is expected to be promoted.

There are growing voices calling for a joint response led by financial authorities or across the entire industry.

Another official pointed out, “Advanced AI hacking seems to have gone beyond the level of entrusting response to individual companies,” and added, “There are clear technical limitations in telling companies to stop it on their own and hold them accountable if they fail.”

Even within the authorities, it is judged that it is difficult to block new methods that use AI to find and attack vulnerabilities with existing security capabilities. Accordingly, there is an atmosphere of consideration to the extent to which the plutocracy security system should be reformed.

In fact, at the emergency response meeting chaired by the Financial Services Commission on the 2nd, it was reported that there was an opinion that a new system was needed as the current response system was disabled. The authorities are expected to convene financial company representatives this afternoon to continue related discussions.

The easing of network separation regulations being promoted by the Financial Services Commission is expected to accelerate.

Currently, domestic financial companies are subject to network separation regulations that require business systems to be separated and blocked from external communication networks for security reasons.

The authorities are in the position that network separation regulations should be completely lifted for financial companies with response capabilities so that they can defend against rapidly evolving AI attacks with AI.

We have been conducting a deregulation test since last June by selecting companies that wish to participate, and companies participating in the second test will be selected on the 7th.

What to Watch

AI outlook — possibilities, not facts

  • Financial authorities will convene representatives of financial companies to present directions for a complete overhaul of the security system.

    Likely · Within days

  • Relaxation of network separation regulations will be partially applied after pilot testing to increase AI attack defense capabilities

    Possible · Within weeks

Open Questions

  • What are the identity and background of the hackers?
  • Which financial institutions were additionally affected?
  • What are the chances of misuse of leaked personal information?
  • What is the specific direction of the security system reform promoted by the financial authorities?

Related Topics

This article was originally published by 연합뉴스.

Related Stories

Successive infringements by Shinhan, Kookmin, Hana, and Busan banks... We and Nonghyup were also attacked
Developing·

Successive infringements by Shinhan, Kookmin, Hana, and Busan banks... We and Nonghyup were also attacked

Hacking incidents occurred one after another at Shinhan Bank, KB Kookmin Bank, Hana Bank, and BNK Busan Bank, and Woori Bank and NH Nonghyup Bank were also attacked, but no information leaks were confirmed. Experts warned that a security paradigm shift is needed as AI agents evolve into attack tools, emphasizing zero trust and AI-based defense systems.

연합뉴스
3 min read
AI slop spreads to the gaming industry... 36.8% of games released on Steam disclose the use of AI
Developing·

AI slop spreads to the gaming industry... 36.8% of games released on Steam disclose the use of AI

The AI ​​slop that has taken over YouTube and social media is spreading to the gaming industry, with 36.8% of games released on Steam announcing the use of AI. The domestic gaming industry is still focusing on existing MMORPGs and webtoon-based games, but the burden on review agencies is increasing as low-quality AI games are pouring into the app market.

연합뉴스
3 min read
President Trump signs executive order to use ‘SI’ instead of ‘AI’… sparking a terminology war
Developing·

President Trump signs executive order to use ‘SI’ instead of ‘AI’… sparking a terminology war

A terminology debate is erupting in the United States after U.S. President Donald Trump signed an executive order requiring the use of 'super intelligence (SI)' instead of 'artificial intelligence (AI)' in federal government documents and external communications. This is interpreted as an intention to alleviate negative public opinion about AI and maintain an edge in technological competition with China.

연합뉴스
3 min read
Be careful about rewriting your password... Email accounts are particularly at risk
Developing·

Be careful about rewriting your password... Email accounts are particularly at risk

As account takeover attacks using AI increase, the risk of password reuse is increasing. Experts recommend separating passwords for each site and setting up multi-factor authentication (MFA), and emphasize that passwords for all related accounts must be changed to prevent chain damage in the event of an email account being leaked. He also pointed out that companies must be careful about phishing and smishing attacks and strengthen corporate security responsibilities.

연합뉴스
3 min read
More on this topicai hacking