News

Toss Bank Targeted Since January, Prompting Industry Emergency Response

[Anchor]

It has been confirmed that the internet protocol (IP) addresses used in recent simultaneous cyberattacks on the financial sector had also attempted to access Toss Bank earlier this year. Fortunately, it did not lead to a personal information leak, but it suggests that widespread attacks have been underway long before the recent incidents.

Reporter Lee Tae-gwon has this exclusive report.

[Reporter]

During the hacking of Shinhan Bank on September 29, which resulted in the leakage of 25,000 pieces of personal data, IP addresses from at least eight countries including Japan, the United States, and Hong Kong were used.

It has been confirmed, however, that two of these U.S. IPs are identical to those that had already attempted to access Toss Bank servers as early as January.

According to data submitted by Toss Bank to the National Assembly, these IPs attempted to access Toss Bank's internal servers three times on January 24, and 11 times in July and August.

However, no personal data leakage occurred as the access attempts were blocked.

Previously, financial authorities shared the attackers' IPs with the financial sector and ordered inspections after hacking damage occurred at seven institutions, including primary financial firms like Shinhan, KB Kookmin, and Hana, as well as secondary financial institutions such as savings banks. This is the first time it has been confirmed that there were also attack attempts on an internet-only bank.

[Choi Kyung-jin / Professor of Law at Gachon University & Head of the Personal Information Experts Association: If continuous attacks from the same IP have taken place over a considerable period, the probability that it is the same hacker naturally increases. It is necessary to quickly identify and share that information.]

It was also found that servers at two life insurance companies, including Kyobo Life Insurance, had been targeted for access attempts by IPs related to the recent hacking incidents.

As these hacking attempts may have been carried out on a widespread scale long before they became known, experts point out that the scope and period of inspections must be expanded.

[Kim Hyung-yeon / Member of the National Assembly's Political Affairs Committee (Rebuilding Korea Party): Financial companies in general should review access logs for at least a year, and utilize AI to catch newly evolving hacking attempts….]

The Financial Supervisory Service has shared the attacking IPs and security precautions across the entire financial sector, and has ordered banks and credit card companies to complete emergency inspections by tomorrow (October 6), and securities firms, insurers, and savings banks by October 8.

(Photo: Yonhap News / Video reporting: Kim Hak-mo, Video editing: Kim Jin-won, Design: Choi Ha-neul)

---

[Anchor]

Let us learn more with economic news reporter Lee Tae-gwon, who covered this story.

Q. Server access attempts at Toss Bank since early this year… How was this revealed?

[Reporter Lee Tae-gwon: The Financial Supervisory Service shared the IP addresses that actually attacked Shinhan Bank with the financial sector and ordered inspections. It was then found that those IPs had accessed services allowing remote access to internal servers at Toss Bank. While we cannot conclude they are the exact same attackers, it means the same IPs have been knocking on financial companies' servers since the beginning of this year. Under the Act on Promotion of Information and Communications Network Utilization and Information Protection, service providers are only obligated to report to the Korea Internet & Security Agency when an actual infringement accident occurs. According to financial authorities, tens of thousands of such attack attempts or access trials occur per company on average every day. Therefore, unless a major breach occurs, attempts that are blocked after being launched are not all shared with authorities. Experts emphasize that authorities need to continuously monitor and rapidly share information regarding such risky IPs.]

Q. The industry is also on 'emergency response'?

[Reporter Lee Tae-gwon: The government has recommended security inspections not only for the financial sector but also for 28,000 general corporations. Although it was the last day of the holiday, companies hastily conducted inspections. Given that damage primarily occurred in external systems with weak security, companies dealing directly with general consumers are particularly nervous. The home appliance industry stated it is strengthening identification and protection measures for external access points, while the automobile and construction industries report no confirmed damage but are blocking risky IPs and operating a 24-hour monitoring system. As the method of widely scanning for vulnerabilities to launch attacks has been newly identified, AI hacking and security are expected to become major issues during the parliamentary audit starting tomorrow.]
※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.

Most Read