▲ Busan Bank headquarters
As banks and credit card companies wrap up their emergency security inspections by today (October 6) at the request of the Financial Supervisory Service, it has been confirmed through SBS reporting that BNK Busan Bank reported some deficient results in its self-inspection checklist.
According to data submitted by BNK Busan Bank to the office of lawmaker Sohn Myung-su of the Democratic Party of Korea, who sits on the National Assembly's Political Affairs Committee, Busan Bank rated one out of 12 checklist items as "deficient."
The "deficient" rating was given to the item concerning the "verification of missing authentication and authorization verification functions for external systems, as well as the identification of access control vulnerabilities."
Regarding external systems, Busan Bank explained, "We monitor them daily using the Attack Surface Management (ASM) feature of the Google Threat Intelligence (GTI) service," but added, "The security tool is unable to determine whether a page is accessible to general users without a separate login."
The bank further explained, "We plan to fully reinvestigate web pages among our external systems that are accessible to general users without a separate login, block them within October, and promptly implement measures such as secure coding."
It also announced plans to develop an AI (artificial intelligence) agent dedicated to scanning security vulnerabilities in order to counter indiscriminate electronic intrusions utilizing AI.
The bank acknowledged limitations in its management, noting that currently, all security management tasks—such as human inspectors directly using vulnerability tools to individually check and address vulnerabilities—are performed manually.
Busan Bank added, "We applied to financial authorities for regulatory relaxation on network separation to utilize AI for enhanced security, but even before being selected as a target financial institution, we will urgently develop and apply a related AI agent within the permissible scope of current laws by December."
In addition, while it currently utilizes 24/7 security monitoring services from SK Shieldus and the Financial Security Institute for cyber threats and breaches, the bank emphasized that because resident personnel do not monitor around the clock, real-time security monitoring utilizing all internal security equipment is difficult during off-hours such as nights and holidays. It noted that it will review the implementation of real-time security monitoring operated by resident personnel 24 hours a day, 365 days a year.
Lawmaker Sohn Myung-su emphasized, "Financial authorities must closely examine the checklists of all financial companies, not just Busan Bank, and take action to swiftly improve security vulnerabilities."
Previously, around 9:00 p.m. on October 1, Busan Bank experienced an incident where the personal information of 11 outsourced development workers was exposed due to an external web server attack leveraging an AI agent.
(Photo provided by BNK Busan Bank, Yonhap News)
※ Please note: This article was translated by AI and may contain errors.
Video News
Video News
Video News