News

Authorities Order Banks and Credit Card Companies to Conduct Self-Security Checks

Authorities Order Banks and Credit Card Companies to Conduct Self-Security Checks
▲ Financial Services Commission

Following a series of hacking incidents at Shinhan Bank and KB Kookmin Bank, financial authorities have instructed the banking and credit card sectors to conduct internal security checks.

The authorities plan to receive prompt reports on the self-inspection results from each sector and formulate institutional improvement measures.

The Financial Services Commission (FSC) held an "Emergency Response Meeting" for the financial sector chaired by Shin Jin-chang, Secretary General, today (October 2) to share information on recent financial company information leakage incidents, attack types, and methods, and discussed the direction for response.

Secretary General Shin ordered the banking and credit card sectors to conduct security inspections across all IT systems exposed externally.

This measure took into account that relatively vulnerable IT systems—such as Shinhan Bank's exclusive service for loan solicitors and Kookmin Bank's mobile work support system for employees—became targets of attacks utilizing artificial intelligence (AI) agents.

Financial institutions must comprehensively identify all IT assets and services exposed to the outside, and intensively inspect security vulnerabilities and access control status.

In particular, all systems accessible from the outside will be subject to inspection, regardless of whether they provide customer-facing services or what type of service they offer.

In addition, they must minimize information exposed to the outside and check whether there are any pathways allowing access to internal information without authentication.

The FSC urged that thorough checks be conducted to ensure authentication procedures are not omitted or inadequately applied during the retrieval of internal information.

At the same time, threat information such as IP addresses used in the attacks, attack methods, and breach attempt histories will be promptly shared with relevant organizations and financial companies to enable a joint response.

The financial authorities plan to provide a security vulnerability checklist to support financial companies in conducting their own security inspections and to receive prompt reports on the results.

Meanwhile, the FSC, the Financial Supervisory Service (FSS), and the Korea Financial Security Institute (FSI) have launched on-site investigations regarding recent hacking incidents, and promptly shared information such as attacker IPs and attack types with the Korea Internet & Security Agency (KISA) and other entities.

Furthermore, they plan to manage and supervise financial companies affected by security breaches to ensure they implement consumer protection and damage compensation without disruption.

Secretary General Shin stated, "We plan to closely monitor breach attempts in the financial sector, promptly share threat information, and maintain close cooperation," adding, "We will thoroughly analyze the causes and attack methods of the breaches to swiftly prepare institutional improvement measures."

Previously, Shinhan Bank announced the previous day that approximately 25,000 customer records were leaked due to an unauthorized hacking incident targeting its communication message structure (code).

KB Kookmin Bank also confirmed during its own inspection process that around 100 customer records were leaked due to external intrusion.

(Photo: Yonhap News)
※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.

Most Read