Multiple IPs used to hide origin of recent cyberattacks against financial firms
Quick Look
South Korean financial institutions including Hana Bank, KB Kookmin Bank and Shinhan Bank suffered customer data leaks in recent cyberattacks, with investigators finding that many IP addresses linked to the attacks were used to mask hackers' locations, prompting a police investigation and international tracing efforts.
AI-generated summary
Why It Matters
South Korean financial institutions have been targeted in recent cyberattacks resulting in customer data leaks, prompting investigations by financial and police authorities.
SEOUL, Oct. 7 (Yonhap) -- A considerable number of internet protocol (IP) addresses were found to have been used to mask those responsible for recent cyberattacks against South Korean financial institutions, sources said Wednesday.
Several financial companies, including Hana Bank, KB Kookmin Bank and Shinhan Bank, suffered back-to-back leaks of customer information in recent hacking attacks, prompting a major police investigation.
While the Financial Supervisory Service identified 28 IP addresses in connection with the attacks, police have determined a significant number of them were used to hide the hackers' whereabouts, according to the sources.
Investigators are said to be tracing the attack path through international cooperation.
The financial watchdog earlier shared the IP addresses with financial companies, along with country information, while noting the possibility of the attackers using indirect connections.
In response to the cyberattacks, the National Police Agency formed a 28-member team to investigate the case.
What to Watch
AI outlook — possibilities, not facts
Investigators will trace the attack path through international cooperation to identify the hackers' origins
Likely · Within weeks
The National Police Agency's 28-member investigation team will continue to pursue leads in the case
Very likely · Within weeks
Open Questions
- Who is responsible for the cyberattacks?
- What specific customer information was leaked?
- Are the masked IP addresses linked to any specific country or group?
- What actions are financial institutions taking to prevent future attacks?







