
The same IP and similar techniques were discovered in breaches of 7 companies, including Shinhan, Kookmin, and Hana Bank, and financial authorities ordered an emergency inspection of all financial sectors.
AI-generated summary
Recently, a number of financial companies, including Shinhan Bank, suffered a breach through the IP of the same attacker.
(Seoul = Yonhap News) Reporter Kang Soo-ryun and Kang Ryu-na = In recent hacking incidents at banks, it was discovered that the same attacker used artificial intelligence (AI) tools to attack.
According to the financial authorities on the 4th, the same attacker's Internet address (IP) was found in several places in the breaches of seven companies, including Shinhan, KB Kookmin, Hana, BNK Busan Bank, Yegaram, Welcome Savings Bank, and Hyundai Capital.
The IP that attacked commercial banks and the IP that attacked savings banks and capital companies were different, but the methods themselves were similar.
It was discovered that the attacker continued to attack by changing the IP.
It appears that the attacker used AI tools to carry out mass automated attacks targeting multiple financial companies.
According to data reported by Shinhan Bank to the National Assembly, in the case of the Shinhan Bank hacking incident, the attacker used IPs from several countries, including Korea, the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, and the United Kingdom.
According to a financial security official, traces of ARTEX AI were confirmed in the IP that attacked the bank, and the Cyber Investigation Bureau of the National Police Agency is currently investigating.
ARTEX AI is a large-scale language model (LLM)-based autonomous penetration testing system released as open source on GitHub, focusing on Chinese.
However, due to the nature of the open source model, it is used globally and IPs are widely distributed, so some say that it is difficult to determine a specific country as the background.
In this attack, information was leaked from financial company employees and loan collection citation supplementary systems, and it was determined that there was no impact on customer services such as internet or mobile banking or financial damage.
Financial authorities categorized hacking incidents into three types and responded to them.
In the case of the information inquiry service, it was confirmed that the development was incorrect so that loan application details or company representative information could be searched without identity verification. Accordingly, all services missing the authentication process were investigated and the errors corrected or the service blocked.
In the case of employee work support services such as PB and RM, information was believed to have been stolen because mobile terminal access control was omitted or web vulnerabilities that could be accessed without permission were not addressed. Financial companies must strengthen controls to ensure access only through pre-registered terminals, and immediately improve vulnerable web services. It was discovered that a hacker had dug into a known security vulnerability in the homepage service, installed malware, and stolen log files containing customer information. As a result, security controls are strengthened, such as taking action on known vulnerabilities or blocking services.
In addition to the seven companies, other financial companies were also confirmed to have attempted infringements, but whether or not they were breached varied depending on whether a multi-factor authentication system was introduced and preemptive measures against vulnerabilities were taken.
The Financial Supervisory Service disseminated attack IPs and security precautions to about 500 companies across the financial sector. Banks and credit cards must complete emergency inspections by the 6th, and securities, insurance, savings banks, and electronic finance companies must complete emergency inspections by the 8th.
They must be inspected according to a checklist that includes 12 items, including ▲blocking the attacking IP and investigating damage, ▲identifying externally exposed IT assets and services, and strengthening security. If any insufficiencies are found, they must be immediately supplemented.
Financial authorities plan to inspect the company where the accident occurred and inform the entire financial sector of vulnerability factors and improvement cases based on the inspection results to prevent similar accidents from recurring.
In addition, the financial authorities are carrying out 'autonomous correction' of basic IT control for the entire financial sector by November, and are taking strict action if large-scale IT/infringement incidents occur due to insufficient inspection.
Since the hacking incident occurred, financial authorities have held a total of three emergency response meetings to this day. On this day, chairmen of all financial sectors and executives of financial companies that experienced breaches were convened to discuss response plans.
Financial Services Commission Chairman Lee Eok-won said, “It is time for the entire financial sector to be seriously aware of the current situation and have the highest level of alertness,” and called for thorough security checks and consumer protection measures.
AI outlook — possibilities, not facts
Emergency inspections were completed by the 6th for banks and cards, and by the 8th for securities, insurance, and savings banks.
Very likely · Within days

Customer information leaks due to hacking attacks have been confirmed one after another in the financial and on2 industries, including Welcome Savings Bank, PF Technologies, and Mouda. Authorities are determining the exact extent and circumstances of the damage.

Korea Electric Power Corporation (KEPCO) announced on the 4th that it is operating an emergency response situation room after an incident occurred in which personal information such as the names, affiliations, and phone numbers of about 24,000 employees were exposed through an external web page. No resident registration number or customer information was included.

South Korean President Lee Jae Myung ordered a thorough investigation into recent hacking attacks that leaked personal customer data at major financial institutions including Hana Bank, KB Kookmin Bank, and Shinhan Bank.

Naver announced that the number of simultaneous users of the Asian Games men's soccer finals, which was broadcast live through streaming platform Chizijik, reached 1.23 million. Additionally, the number of AI clip plays that automatically extract key scenes exceeded 53.2 million.

Financial authorities detected circumstances in which the same attacker carried out an automated attack using artificial intelligence (AI) tools in the recent hacking incident at seven financial companies, including Shinhan, KB Kookmin, and Hana Bank, and ordered an emergency inspection across the entire financial sector.

President Lee Jae Myung called for a thorough investigation into hacking attacks that leaked personal information from major South Korean banks including Shinhan, Hana, KB Kookmin, Woori, and NH Nonghyup Bank, with Shinhan Bank reporting 25,000 customers affected.