Video
[Anchor]
Following Shinhan Bank, personal information of employees and customers has been additionally confirmed to have leaked at three other commercial banks. Amid an unprecedented situation where the operational systems of three major banks were breached by hacking attacks, a state of emergency has been declared for banking sector security.
This is a report by reporter Lee Tae-gwon.
[Reporter]
At KB Kookmin Bank, personal information of a total of 119 individuals, including 20 employees and 99 customers, was leaked due to an external intrusion.
The leaked data includes names, phone numbers, addresses, and encrypted resident registration numbers.
It was determined that a mobile work support system for employees was used as the hacking pathway.
The attack, which first began on the night of September 27, continued for over 40 hours, and the bank confirmed the actual leak at 7:00 PM on the night of September 30, exactly one full day after the attack ended.
Hana Bank announced that the information of 89 customers—including resident registration numbers, names, addresses, email addresses, phone numbers, mobile phone numbers, and workplace names—was leaked.
Hana Bank stated that there was abnormal access to its sales support system.
At BNK Busan Bank, it was found that personal information of 11 outsourced development employees was leaked yesterday morning (October 2) through the mobile sales support system for employees.
Previously, information on 25,000 customers was leaked when webpages used by loan recruiters at Shinhan Bank were hacked, and similar incidents consecutively erupted at other banks around the same time.
Personal information was leaked as the operational systems of all four banks were breached.
While it has not been clearly verified whether it was the work of the same group, circumstances indicating the utilization of AI have emerged in terms of the timing and methods of the attacks.
[Professor Hwang Seok-jin / Dongguk University Graduate School of Information Security : They keep breaching and pushing through until they find a way. Therefore, the timeframes and other aspects were such that manual work would have been completely impossible.]
Woori Bank and Nonghyup also suffered attacks using the same method, but it is reported that no information leakage occurred.
Yegaram Savings Bank, a secondary financial sector institution, also stated that an unidentified hacker accessed a server containing customer personal information on September 30, leaking personal details such as names, dates of birth, and contact information, though specific hacking methods have not yet been disclosed.
Financial authorities held an emergency response meeting to order a comprehensive inspection of all systems exposed externally, and the police have also launched an internal probe.
(Video Editing: Ahn Ye-jin, Design: Sohn Seung-phil)