News

Attacks Also Attempted on KakaoBank and K Bank: 28 'Attacker IPs' Identified

[Anchor]

It has been confirmed that some of the internet addresses used in financial sector hacking attempts accessed not only Toss Bank's servers, but also those of KakaoBank and K Bank. Financial authorities have identified 28 internet addresses used in the attacks and issued a consumer alert in preparation for potential secondary damage.

Reporting by Lee Tae-gwon.

[Reporter]

Some of the internet addresses, or IPs, used in attacks against seven financial institutions—including Shinhan Bank, where personal information leakage occurred—were found to have attempted access to all three of South Korea's internet-only banks.

Following confirmed access attempts to Toss Bank starting in January, K Bank experienced a total of four server access attempts by IPs from the United States and South Korea between July and last month.

KakaoBank's servers were accessed six times between January and March by IPs from China, the United States, and Malaysia, and it was confirmed that an actual attack attempt aimed at identifying server vulnerabilities took place once on September 29.

However, these access attempts were blocked by security systems, preventing any leakage of personal information or other damage.

The Financial Supervisory Service has identified 28 attacker IPs and distributed them to the financial sector along with information on their countries of origin.

[Interview / Kwon Heon-young, Professor, Graduate School of Information Security, Korea University: Since there may be attacks in a circumvented form, additional analysis will likely be needed to determine the actual original source of the attack. Additional checks must also be conducted to see if the risk is spreading to other areas....]

Banks and card companies conducted emergency security system inspections through yesterday (October 6) at the request of financial authorities.

BNK Busan Bank, where personal information of 11 outsourced workers was exposed on October 1, reportedly submitted a report rating its evaluation as "insufficient" in one out of 12 checklist items—specifically regarding the omission of external system authorization verification functions.

This means that while it was not the main system, there was an external page that could be accessed without a separate login.

Financial authorities warned that secondary damage could occur, issuing a "Caution" consumer alert and designating a month-long special response period starting yesterday. They instructed financial institutions to operate dedicated customer support desks for affected clients and to strengthen the monitoring of abnormal transactions.

Video by Shin Seeun | VJ: Lee Ji-hwan | Graphics: Park Cheon-woong
※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.

Most Read