Hack attacks targeting the financial sector are spreading beyond commercial banks to secondary lenders such as savings banks and capital firms, and signs linked to the same attacker have been identified at multiple financial companies. After President Lee Jae-myung ordered a thorough investigation and countermeasures, financial authorities urgently convened the entire financial sector and began responding while leaving open the possibility of automated attacks using artificial intelligence (AI).
The financial sector said on Oct. 4 that as information leaks continue from hack attacks targeting the sector, additional damage has been confirmed at Welcome Savings Bank. Welcome Savings Bank said it found a hack attack targeting a corporate customer-related system during an internal inspection the previous day and reported it to financial authorities.
So far, up to 2,200 cases of corporate customer-related information are estimated to have been leaked, including company names, names of corporate account managers, email addresses and phone numbers. Welcome Savings Bank is determining the exact circumstances of the leak and the scale of the damage.
Recent information leak incidents in the financial sector appear to be spreading beyond banks to secondary lenders. Information leaks have been confirmed so far at Shinhan Bank, KB Kookmin Bank, Hana Bank and BNK Busan Bank, and damage has been identified at Hyundai Capital, Yegaram Savings Bank and Welcome Savings Bank among secondary lenders.
As the situation spread, President Lee Jae-myung also ordered countermeasures directly.
Kang Yu-jung (강유정), senior presidential spokesperson, said Lee received a report on recent personal data leak incidents and the response status at financial institutions and public institutions, and, recognising the matter as serious, instructed officials to make every effort to conduct a thorough investigation and prepare countermeasures.
Signs of same attacker at seven firms; suspected AI use
Financial authorities also held an emergency inspection meeting on responses to recent breach threats for the entire financial sector at the Government Complex Seoul on the afternoon of Oct. 4 to review the response situation.
Lee Eok-won (이억원), chairman of the Financial Services Commission, said at the meeting that multiple breach incidents were being found in a short period across several sectors, including savings banks and capital firms as well as major commercial banks. He stressed that the entire financial sector must maintain the highest level of vigilance.
In particular, the possibility that AI was used in the attack was also raised. Financial authorities said IP addresses linked to the same attacker were found in multiple places in breach incidents at seven firms: Shinhan, KB Kookmin, Hana and BNK Busan Bank, as well as Yegaram and Welcome Savings Bank and Hyundai Capital.
Authorities estimate the attacker changed IP addresses and used AI tools to carry out automated attacks against multiple financial companies.
Lee said that because a new type of high-frequency cyberattack could continue in the future, efforts should be accelerated to establish a security system in which AI attacks are defended with AI.
He added that the government is pursuing fundamental institutional improvements, including urgently easing network separation regulations and reviewing a full lifting, to shift to an AI security system. He urged the financial sector to actively participate in related policies and speed up the transition to an AI-based security system.
He also pointed to the areas targeted by the attacks. He said cases have been confirmed in which external web pages and servers used for work convenience by loan solicitors or employees, areas that had drawn relatively less attention in security management, were used as attack channels.
Lee said that even if a robust security system is built, a single unmanaged gap can act as a vulnerability for the entire system. He called on financial companies to expand inspection scope beyond core computer networks to include external linked systems and business support systems.
Financial authorities said no signs have been confirmed so far that sensitive information that could be directly used for fraudulent payments was leaked. They said they are not ruling out the possibility that leaked personal information could be abused for secondary harm such as voice phishing or smishing.
Financial authorities: Strict accountability for similar incidents
Financial authorities instructed financial companies to immediately recheck their security systems based on already shared attack information and incident cases.
Lee also set out a policy of holding firms strictly accountable under relevant laws and regulations if similar incidents occur again because financial companies neglected necessary inspections and responses despite already shared attack information and incident cases.
The meeting was attended by officials from all parts of the financial sector, including banking, financial investment, insurance, specialised credit finance, savings banks, mutual finance, virtual assets and fintech, as well as officials from financial companies where breach incidents occurred.
As information leak incidents that began in the banking sector spread across sectors, an overall inspection of the financial sector's security system has become unavoidable.
With repeated cases in which the attack targeted external and business support systems that were relatively weak in management compared with core financial transaction systems, follow-up measures are expected depending on the results of the financial authorities' investigation to strengthen financial companies' security management scope and responsibility system.