BackShinhan attack IP, also on Toss Bank... Circumstances of widespread attacks in the financial sector
Shinhan attack IP, also on Toss Bank... Circumstances of widespread attacks in the financial sector
Developing
연합뉴스4 hours agoTech3 min readSouth KoreaView original

Shinhan attack IP, also on Toss Bank... Circumstances of widespread attacks in the financial sector

Security inspection recommended for 28,000 companies... Even schools and public institutions need to prepare

Quick Look

It was revealed that the IP used to hack Shinhan Bank also attempted to access the Toss Bank server, and as personal information leakage incidents have occurred one after another at KEPCO and universities, the need to strengthen security across society is growing.

AI-generated summary

Why It Matters

Recently, hacking and personal information leakage incidents have been occurring one after another at various financial companies, public institutions, and universities, including Shinhan Bank.

Font size

Shinhan attack IP, also in Toss Bank... Circumstances of widespread attacks in the financial sector

Security inspection recommended for 28,000 companies... Even schools and public institutions need to prepare

(Seoul = Yonhap News) Reporter Shin Seon-mi = Following the financial sector, Korea Electric Power Corporation [015760] and universities are also experiencing personal information leaks, increasing public anxiety about cyber threats.

Regarding security incidents in the financial sector, it was revealed that some of the Internet addresses (IPs) used in the Shinhan Bank hacking attempted to access the Toss Bank server several times.

Accordingly, voices are calling for preparations for attacks targeting not only one financial company but also multiple institutions simultaneously or sequentially.

In fact, recent security incidents are occurring across all industries, not only in the financial sector such as banks, savings banks, and capital, but also in public energy companies and universities.

In this situation, there is a growing demand to reexamine the defense system of society as a whole, from security checks at individual corporate level to institutions with large amounts of citizens' personal information, such as schools and public institutions.

◇ Shinhan attack IP attempted to access Toss Bank server 14 times

According to data received from Toss Bank by Kim Hyeong-yeon, a member of the National Assembly's Political Affairs Committee, on the 5th, some of the IPs of the attackers who hacked Shinhan Bank have also attempted to access Toss Bank's servers since early this year.

The two American IPs used in the Shinhan Bank attack tapped the Toss Bank server 14 times in total, including 3 times in January and 11 times between July and August. Toss Bank blocked access, so there was no actual damage such as customer information leakage.

Previously, hacking damage was confirmed at seven financial companies, including Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank, and Hyundai Capital.

The customers whose personal information was leaked include approximately 25,000 from Shinhan Bank, about 40,000 from Yegaram Savings Bank, 119 from KB Kookmin Bank, 89 from Hana Bank, and 11 from BNK Busan Bank.

Financial authorities reportedly discovered the same attacker's IP in several places in these incidents. Authorities believe that the attacker continued the attack by changing IP addresses and used AI tools to carry out automated attacks targeting several financial companies.

However, the fact that the same IP was used alone does not allow us to conclude that the series of attacks were the work of the same person or organization, so additional investigation by financial authorities and related organizations is needed.

◇ Information on 24,000 KEPCO employees and cyber university students was also leaked.

Security concerns are also spreading outside the financial sector.

KEPCO announced on the 4th that it was aware that the names, affiliations, and phone numbers of about 24,000 employees were exposed on an external web page at 3:59 p.m. on the 1st.

KEPCO immediately blocked access to the related internal system and requested the webpage operator to delete it. The information was deleted around midnight on the 2nd. It took about 32 hours from recognizing the incident to deleting it.

According to KEPCO, unique identification numbers such as resident registration numbers, sensitive information, and customer information were not exposed.

It is known that the webpage in question is not a site open to the public. KEPCO believes this incident is unrelated to AI-based hacking targeting the financial sector.

At Seoul Cyber ​​University, personal information of current students, graduates, faculty, staff, and job applicants was leaked. On the 4th, the school received notification from the Korea Internet & Security Agency (KISA) that data presumed to be member personal information had been posted on an external site.

Information that has been leaked or may have been leaked includes the student/graduate's name, student number, date of birth, contact information, email address, address, department/student status, and admission/academic information. The school said that resident registration numbers, passwords, and account numbers were encrypted, and there is no sign that they have been decrypted so far.

Seoul Cyber ​​University formed an emergency response task force (TF) and reported to the Ministry of Education's Cyber ​​Safety Center and the Personal Information Protection Committee. The exact circumstances and scale of the leak are being investigated together with relevant agencies.

◇ Government recommends inspections at 28,000 locations… “The scope of inspection must be expanded”

The recent series of accidents is shocking in that the boundaries of the attack target have virtually disappeared.

Financial institutions store asset and credit information, schools store personal and academic background information of students and faculty, and public institutions store various types of information about employees and citizens. If a security hole is opened in one location, it will not only result in a large-scale leak, but the stolen information may also be used in secondary attacks targeting other organizations or services.

The government, feeling more urgent, also raised the level of its security response.

The Ministry of Science and ICT and the Korea Internet & Security Agency (KISA) are operating the KISA Internet Infringement Response Center (KISC) on a 24-hour emergency basis.

Monitoring of major companies' websites has been increased, and personnel to respond to infringement incidents have been strengthened.

An email was sent on the 4th recommending a security check to approximately 28,000 companies that reported the Chief Information Security Officer (CISO).

The IP of the foreign attacker identified by the Financial Security Institute was forwarded to the relevant cloud service provider and requested to block the malicious activity.

However, as leaks occur not only in financial companies and private companies but also in public energy companies and universities, some are pointing out that the scope of inspection needs to be expanded further.

Because not only schools and public institutions with large amounts of personal information but also major infrastructure operators directly connected to people's lives can be attacked, account and access rights management, external exposure systems, and security of cooperation and consignment companies must be reexamined.

Now, in a situation where one or a small number of attack groups can find vulnerabilities in multiple organizations at once using automated tools such as AI, there are growing voices calling for a response system to be established by viewing cyber attacks as a risk to society as a whole rather than an incident of an individual company.

What to Watch

AI outlook — possibilities, not facts

  • Identification of hacking subject through additional investigation by relevant agencies

    Likely · Within weeks

Open Questions

  • Whether the person who attacked Shinhan Bank and Toss Bank is the same person
  • Whether the government will expand the scope of additional security checks

Related Topics

This article was originally published by 연합뉴스.

Related Stories

Government reorganizes independent AI foundation model business... Frontier AI development parallel two-track strategy announced
Developing·

Government reorganizes independent AI foundation model business... Frontier AI development parallel two-track strategy announced

The Ministry of Science and ICT announced that it will not stop its independent AI foundation model (Dokpamo) project but will redesign it into two tracks: developing a frontier AI model and expanding the industrial ecosystem. Starting next year, an investment project worth 4.7 trillion won for frontier AI development will be reflected in the budget, and two of the three Dokpamo companies will be selected and assigned to the frontier model development track or industrial expansion track after evaluation by the end of January next year.

연합뉴스
3 min read
More on this topichacking