
고객정보 유출 없어…추가 해킹 공격 대비 모니터링 강화 중
신한·국민·하나은행에 이어 BNK부산은행에서도 AI 에이전트를 활용한 외부 해킹으로 외주 개발직원 11명의 개인정보가 유출됐다. 부산은행은 즉각 웹페이지를 차단하고 금융당국에 신고했으며, 고객 정보 유출은 없다고 밝혔다.
AI-generated summary
최근 신한은행, KB국민은행, 하나은행 등 주요 시중은행에서 해킹 사고가 잇따라 발생한 상황이다.
"고객정보 유출 없어…추가 해킹 공격 대비 모니터링 강화 중"
(부산=연합뉴스) 오수희 기자 = 신한은행과 KB국민은행, 하나은행에서 해킹으로 고객 정보가 유출되는 사고가 발생한 상황에서 BNK부산은행에서도 해킹으로 외주 직원의 신상정보 11건이 유출됐다.
2일 BNK부산은행에 따르면 지난 1일 오후 9시께 AI 에이전트를 활용한 외부의 웹서버 공격 시도가 있었다.
부산은행은 주요 공격은 차단했지만, 후속 점검 과정에서 세션 검증이 충분하지 않았던 일부 웹페이지를 통해 외주 개발직원 11명의 개인정보가 노출된 정황이 확인돼 해당 페이지를 즉각 차단했다고 전했다.
노출된 외주 개발직원 정보는 성명과 전화번호, 생년월일, 이메일 주소다.
해당 정보가 노출됐던 웹페이지는 차단돼 외부 접속이 제한된 상태다.
부산은행 측은 내부 직원용 모바일 영업 지원시스템 등을 대상으로 한 해킹 공격으로 이런 사고가 난 것으로 추정된다고 설명했다.
해킹 공격을 받아 일부 외주 직원의 신상 정보가 웹페이지에 유출됐지만, 고객 정보는 유출되지 않았다고 부산은행 측은 전했다.
부산은행은 관계자는 "해당 웹페이지는 차단 조치가 끝난 상황이며, 금융당국에 관련 내용을 신고했다"면서 "고성능 AI를 활용한 유사 추가 해킹 공격에 대비해 외부 공개용 웹페이지를 전수조사 하는 등 지속해 모니터링을 강화하고 있다"고 말했다.
AI outlook — possibilities, not facts
금융당국의 보안 점검 및 추가 조사 진행
Very likely · Within days

During a hacking attack targeting major domestic banks such as Shinhan Bank, traces of 'ARTEX AI', a Chinese-based open source tool in which an artificial intelligence (AI) agent automatically performs the hacking process, were discovered, putting the entire financial sector on a security alert.

Samcheok City in Gangwon-do was selected by the Ministry of Science and ICT for the '2027 Smart Village Supply and Expansion Project' and will invest 3 billion won by 2029 to build an AIoT-based maritime safety management system.

KB Kookmin Bank announced that about 100 pieces of customer information were leaked due to an external intrusion through the mobile work support system for employees. This is the second commercial bank hacking incident following Shinhan Bank, and financial authorities are discussing response measures considering the possibility of further spread of damage.

In relation to the personal information leakage of about 25,000 Shinhan Bank customers, traces of 'ARTEX AI', a Chinese-based AI autonomous penetration testing console, were found on the suspected attack server, but it was not confirmed whether it was actually used, the security industry said.

As accidents caused by AI increase, there is a growing consensus that AI development companies should be held legally responsible, but it is pointed out that it is difficult to apply the existing legal system. The New York Times introduced related public opinion and legal academic opinions, and reported on cases where AI models such as Open AI and Antropic caused security incidents and the process of discussing responsibility.

Following Japan, Naver announced that it will strengthen overseas travel information search results in 45 major Asian regions, including Vietnam, Thailand, Indonesia, the Philippines, Taiwan, Hong Kong, and Macau, and provide weather, exchange rates, visas, entry guidance, safety notices, and AI-based popular restaurant and attraction recommendation services.