At an emergency inspection meeting across the financial sector on responses to recent intrusion threats at the Government Complex Seoul on Oct. 4, (from right) Shinhan Bank CEO Jeong Sang-hyeok, KB Kookmin Bank CEO Lee Hwan-ju and Hana Bank CEO Lee Ho-seong listen to remarks by Financial Services Commission Chairman Kim Byoung-hwan. [Photo: Yonhap News Agency]

Traces of hacking attacks targeting the financial sector are spreading broadly beyond banks and secondary financial firms to internet banks and the insurance and securities industries. Following a string of data leak damage at commercial banks, savings banks and capital firms, access attempts from internet protocol (IP) addresses used in attacks on existing financial companies were also confirmed at internet-only banks. Additional data leak incidents were also found at online investment-linked finance companies, and intrusion traces were detected at insurers and brokerages. As the number of attack IPs identified by financial authorities rose to 28 excluding duplicates, police also formed a dedicated team and opened a formal investigation.

As of Oct. 6, the Financial Supervisory Service identified 33 IP addresses used in hacking attempts related to recent intrusions in the financial sector, according to the financial industry. Excluding duplicates, the figure is 28. That is an increase in targets compared with 19 as of 6 p.m. the previous day.

The FSS shared information with the financial sector on the attack IPs and their countries of origin, and asked firms to block them and conduct self-checks. The IPs confirmed through the previous day spanned 12 countries, including the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, Sweden and Germany, and included 1 domestic IP. The United States had the most, with 5.

The reach of the attackers appears to have extended beyond financial companies where actual data leak damage was confirmed to internet banks.

Access attempts from IPs used in existing hacks on the financial sector were also confirmed on the servers of KakaoBank and K Bank. In KakaoBank's case, multiple attempts have been made since January this year, but they were detected and blocked through its security system and did not lead to damage. K Bank also confirmed connection attempts from the related IPs, but no damage such as data leaks occurred.

Toss Bank also confirmed abnormal access attempts via attack IPs identified by financial authorities, including in January and in July to August this year. Toss Bank blocked the access, and no intrusion damage such as customer personal data leaks has been confirmed so far.

Similar movements were detected in the insurance and securities industries. Access logs believed to be linked to this incident were confirmed on the systems of some insurers and brokerages during self-checks in the financial sector, it was reported. The number of companies involved is about 1 to 2 in each industry. No cases leading to actual data leaks have been confirmed so far.

With similar access traces confirmed at internet banks and the insurance and securities industries after banks, savings banks and capital firms, the possibility has been raised that attacks were attempted across the financial sector.

The FSS told financial companies to re-identify externally exposed IT assets and services and check vulnerabilities. It also distributed a 12-item checklist that includes authentication, authorisation and verification functions of external systems, whether shared attacker IPs were blocked, whether actual intrusion attempts and damage occurred, and the status of real-time security monitoring systems. Financial companies plan to carry out self-checks and take measures on any shortcomings through Oct. 8.

Personal data leak incidents were also additionally found in online investment finance companies in the fintech industry.

PFC Technologies (PFCT) said it confirmed on Sept. 27 that some users' personal data and other information had been leaked through an external electronic intrusion, and posted a notice on its website on Sept. 29. Personal information of about 300 customers was reported to have been leaked.

Mouda also posted a notice on Sept. 29 that some personal data and personal credit information could have been leaked externally. The company said it believed a third party illegally accessed its website on Sept. 27, and after confirming abnormal signs it blocked the relevant IP and detour routes.

It has not yet been confirmed whether the incidents at PFCT and Mouda were carried out by the same attackers as the recent string of hacking across banks, savings banks and capital firms.

Police switched the string of hacking incidents in the financial sector to a formal investigation.

The National Office of Investigation at the National Police Agency said it confirmed the facts of the hacking cases at financial institutions, booked the case on suspicion of violating the Information and Communications Network Act and designated the NPA's Cyber Terror Investigation Unit as the dedicated investigation team.

Police are expected to look into intrusion routes and attack methods by financial company, the scale of personal data leaks and links among attackers.

Police are also reviewing whether the case falls under the notification requirement for the Major Crime Investigation Office. Under the law on the office, hacking of electronic financial infrastructure facilities that violates the Electronic Financial Transactions Act can be subject to notification.

Police requested an authoritative interpretation from the Financial Services Commission to determine whether the systems breached at the financial companies qualify as electronic financial infrastructure facilities.

With the financial authorities' emergency inspection and the police investigation proceeding at the same time, the government also ordered a response, viewing the incident as a national cyber security issue.

President Lee Jae-myung (이재명) said at a cabinet meeting at Cheong Wa Dae that public concern and anxiety were very high after signs emerged that some hacks involved the use of artificial intelligence. He called for swift and clear identification of the circumstances and for concentrated input of personnel and resources to minimise damage.

Keyword

#Financial Supervisory Service #KakaoBank #K Bank #Toss Bank #PFCT
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.