News

KakaoBank and K-Bank Servers Also Targeted... 28 Attacker IPs Confirmed

[Anchor]

It has been confirmed that some of the Internet Protocol (IP) addresses used in the widespread financial sector hacking incident also attempted to access the servers of KakaoBank and K-Bank. Financial authorities have identified 28 IPs used in the attacks.

Reporter Lee Tae-gwon has the details.

[Reporter]

Some of the IP addresses used in the attacks against seven financial institutions, including Shinhan Bank where personal information was leaked, were found to have also attempted to access all three of South Korea's internet-only banks.

Following the confirmed access attempts on Toss Bank starting in January, it was found that US and domestic IPs accessed K-Bank's server a total of four times from July to last month.

IPs from China, the US, and Malaysia accessed KakaoBank's server six times between January and March, and it was confirmed that there was actually one attack attempt made on September 29 to identify server vulnerabilities.

However, these access attempts were blocked by security systems, preventing any leaks of personal information or other damages.

The Financial Supervisory Service (FSS) has identified 28 attacker IPs and distributed them to the financial sector along with information on their countries of origin.

[Kwon Heon-young, Professor at Korea University Graduate School of Information Security: Since there may be attacks in the form of circumvention, additional analysis will likely be needed to find out where the actual original attack came from. Additional inspections must be conducted to see if the risk is spreading elsewhere....]

At the request of financial authorities, banks and credit card companies conducted emergency inspections of their security systems through yesterday (October 6).

BNK Busan Bank, where the personal information of 11 outsourced workers was exposed on October 1, reportedly submitted a report judging one of the 12 checklist items—specifically regarding the omission of access verification functions for external systems—as inadequate.

This means that although it was not the main system, there was an external page that could be accessed without a separate login.

Expressing concerns that secondary damages could occur, financial authorities issued a Caution-level consumer alert, designated a one-month special response period starting today, and instructed financial institutions to operate dedicated customer support desks for affected customers and to strengthen the detection of abnormal transactions.

(Video Editing: Park Ji-in, VJ: Lee Ji-hwan, Design: Park Cheon-woong)
※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.

Most Read