[Anchor]
It has been confirmed that the internet addresses used in recent sequential hacking attacks on the financial sector had also attempted to access Toss Bank earlier this year. Fortunately, it did not lead to a data breach, but it appears that widespread attacks had been taking place long before the current incident.
Reporter Lee Tae-gwon has the story.
[Reporter]
During the Shinhan Bank hacking incident on September 29, which resulted in the leakage of 25,000 pieces of personal information, internet protocol (IP) addresses from at least eight countries, including Japan, the United States, and Hong Kong, were used.
However, it has been confirmed that two of these U.S. IPs are identical to those that had already attempted to access Toss Bank's servers back in January.
According to data submitted by Toss Bank to the National Assembly, the IPs in question attempted to connect to Toss Bank's internal servers three times on January 24, and 11 times in July and August.
However, because the connection attempts were blocked, no personal information leaks occurred.
Previously, after hacking damages occurred at seven financial institutions—including major commercial banks like Shinhan, KB Kookmin, and Hana, as well as secondary financial sectors such as savings banks—financial authorities shared the attacker IPs with the financial sector and ordered inspections. This marks the first time it has been confirmed that internet-only banks were also targeted by attack attempts.
[Choi Kyung-jin / Professor of Law at Gachon University & President of the Korea Privacy Professionals Association: If continued attacks from the same IP have taken place over a considerable period, the likelihood that it is the same hacker naturally increases. It is necessary to identify this quickly and share that information promptly.]
In addition, it was found that the IPs related to the recent hacking incidents also attempted to access servers at two life insurance companies, including Kyobo Life Insurance.
As there is a possibility that these hacking attempts took place on a much wider scale and from much earlier than known, critics point out that the scope and period of inspections must be expanded.
[Kim Hyung-yeon / Member of the National Assembly's Political Affairs Committee (Rebuilding Korea Party): Financial institutions overall should check access logs for at least a year, and new, evolving hacking attempts must be caught through AI...]
The Financial Supervisory Service has shared the attacking IPs and security precautions with the entire financial sector, and has instructed banks and credit card companies to complete emergency inspections by today (October 6), and securities firms, insurers, and savings banks by October 8.
(Video Reported by Kim Hak-mo | Video Edited by Kim Jin-won | Design by Choi Ha-neul)
※ Please note: This article was translated by AI and may contain errors.
Exclusive: Hacker IP Involved in Recent Attacks Attempted Breach on Toss Bank Since January, Targeted Kyobo Life Too
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.
Trending Now
-
Video News
'North Korea Directly Planted Landmine South of MDL About a Year Ago'
-
Video News
Yoo Hae-jin's Agency Vows Strict Action Against Protests in Front of Actor's Home
-
Video News
"This Is Going Too Far": Surge in Marathons Sparks Outcry Over Road Closures in Seoul
-
Video News
"Double Salary" Lures to China... The Bitter Reality of Semiconductor Talent Drain
-
Video News
Toss Bank Targeted Since January, Prompting Industry Emergency Response
Video News
Video News
Video News
Video News
Video News