[Anchor]
It has been confirmed that the attacker's internet addresses used in recent financial sector hacking attacks also attempted to access Toss Bank earlier this year. While this did not lead to personal data leaks, experts point out that more thorough inspections are necessary, as widespread attack attempts appear to have taken place long before the recent incidents.
Reporting by Lee Tae-gwon.
[Reporter]
During the hacking incident at Shinhan Bank on September 29, where 25,000 pieces of personal data were leaked, internet protocol (IP) addresses from at least eight countries, including Japan, the United States, and Hong Kong, were utilized.
However, it has been confirmed that two of these U.S. IPs are identical to those that had already attempted to access Toss Bank's servers back in January.
According to data submitted by Toss Bank to the National Assembly, the IPs in question attempted to access Toss Bank's internal servers three times on January 24, and 11 times across July and August.
However, no personal data leakage occurred as the access attempts were blocked.
Previously, financial authorities shared the attacker IPs with the financial sector and ordered security checks after hacking damage occurred at seven institutions, including major commercial banks like Shinhan, KB Kookmin, and Hana, as well as secondary financial sectors such as savings banks. This marks the first time it has been confirmed that internet-only banks were also targeted by attack attempts.
[Choi Kyung-jin / Professor of Law, Gachon University (Head of the Personal Information Professionals Association): If continuous attacks from the same IP have been taking place over a considerable period, the probability that it is the same hacker becomes somewhat higher. It is necessary to quickly identify and share that information.]
In addition, it was found that IPs related to the recent hacking incidents also attempted server access at two life insurers, including Kyobo Life Insurance.
As these hacking attempts may have been carried out on a widespread scale long before they became known, critics point out that the scope and period of security inspections must be expanded.
[Kim Hyung-yeon / Member of the National Assembly's Political Affairs Committee (Rebuilding Korea Party): Financial institutions overall should check access logs for at least a year, and utilize AI to detect newly evolving hacking methods....]
The Financial Supervisory Service has shared the attacking IPs and security precautions across the entire financial sector, and has ordered banks and credit card companies to complete emergency inspections by today (October 6), while securities firms, insurers, and savings banks must finish by the 8th.
(Video by Kim Hak-mo | Video editing by Kim Jin-won | Design by Choi Ha-neul)
※ Please note: This article was translated by AI and may contain errors.
Toss Bank Targeted Since January, Kyobo Life Also Targeted
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.
Trending Now
-
Video News
Barefoot Passenger Sparks Outrage After Putting Feet Between Front Seats on Flight
-
550-Year-Old Landmark Vanishes Overnight in Collapse
-
Video News
"Is This Right?" Outrage Everywhere... Smoking Openly Right Under "No Smoking" Signs
-
Video News
"Three Typhoons at Once" Causes Alarm: Will South Korea Be Affected?
-
Video News
"What Did the Person Next to Me Do Wrong? Please Stop"—Looking at the Photo
Video News
Video News
Video News
Video News