South Korea's financial cyber security is being put to the test. The Seoul presidential office has directed a comprehensive probe into the recent personal data breaches of banks, finance companies and public agencies.
What Happened in the Financial Data Breach
Shinhan Bank, KB Kookmin Bank and others have reported attacks on their systems by a cyber intruder, according to the Financial Services Commission (FSC). Hana Bank and Woori Bank also were breached, according to Yonhap news agency. Shinhan Bank disclosed the leak on September 30 and regulators started on-site investigations which were later extended to include all the reported incidents.
It was not immediately possible to contact the banks for comment outside their working hours. The extent of the breach and the kind of personal information that was leaked is not known as institutions have yet confirmed the full extent of the impact.
FSC Emergency Meeting on Cybersecurity
Lee Eog-weon, FSC chairman, held an emergency meeting on Sunday with financial industry associations, regulators and executives from institutions affected. The meeting had been set for October 7, but was moved up due to further violations at second-tier financial institutions, according to Korean media reports.
The chairman cautioned that the industry needs to be vigilant as much as they can be. It was a follow-up to similar talks held on Friday.
AI Cyberattacks: A Possible Factor
The officials indicated that there was no way to exclude the possibility of using artificial intelligence in the attacks. As a response, the FSC's chairman has proposed the ‘AI attacks defended by AI' principle and has indicated a general upgrade of the cybersecurity architecture of the financial sector.
It is a simple concept: Automation in the attacker's probing and exploitation efforts must be matched by automation in the defender's detection and response efforts. No confirmation has been made on whether AI was used or not.
Attack Pattern and IP Addresses
The attacks could have penetrated several financial firms, not just a single one, according to the regulators, who added that they suspect the hackers were "scanning for vulnerabilities" in order to get to the most vulnerable targets. It said data collected from banks showed attack traffic was from IP addresses from various countries, including the United States, Japan, Singapore, Vietnam and Britain.
The IP address does not indicate the responsibility. Traffic may go through servers in other countries, which in turn does not mean much when looking at the geographic range.
Security Measures Ordered for Financial Institutions
The following security measures are ordered for financial institutions:
- - Carry out comprehensive security inspections
- - Tighten access controls
- - Minimise external system access
- Improve consumer protection –
Information about attacks, IP addresses and other threat data will be exchanged quickly throughout the industry as well. Time to share information makes a difference since an attack method that works in one bank can be countered in others within hours.
Political Reaction and North Korea Question
The main opposition People Power Party urged authorities to also investigate into whether North Korean troops were responsible for the attacks, citing similar hacking incidents on South Korean financial institutions in the past that have been blamed on Pyongyang. In this instance the cause is not attributed to any official and investigators have not declared any such connection.
What Customers Can Do to Protect Personal Data
While customers have no control over the internal systems of their bank, some steps minimize the risk in the event of a data leak:
- Be aware of any suspicious calls, texts or emails that appear to be from your bank as leaked information is a key driver of phishing
- Update online banking passwords, and set up 2-step verification
- Check account statements regularly and notify of any unfamiliar transactions promptly
- - Trust only official bank applications and sites for updates
What Comes Next
The investigation is ongoing. The issue is the number of customers impacted, what type of data got leaked and whether the banks' defenses are compliant with regulations. Meanwhile, regulators are pressing for better security checks, threat intelligence and AI-based defenses, and citizens await clarity.
