▲ Financial Sector Hacking
Circumstances indicate that hackers using AI agents have been targeting not only major commercial banks, but also savings banks, capital companies (installment financing companies), and mutual finance institutions in a broad-scale offensive.
Deeming that existing security capabilities have limitations in blocking these novel attacks leveraging AI, financial authorities are expected to push for a complete overhaul of the financial sector's security systems.
According to financial authorities and the financial sector, the National Federation of Credit Cooperatives has reportedly confirmed access attempts from the same hacker internet protocol (IP) address used to steal customer personal information from Shinhan Bank.
The National Federation of Credit Cooperatives successfully blocked abnormal access from these overseas IPs using its own security equipment, preventing data leakage damage.
Similar intrusion attempts were also reported at NongHyup Mutual Finance, which shares its network with NH NongHyup Bank, but defenses were successful.
Yegaram Savings Bank announced on October 2 that approximately 40,000 customers' names, dates of birth, and contact information were leaked in a hacking attack on September 30.
Hyundai Capital also detected that the names, contact information, email addresses, and resident registration numbers of 146 loan agents were leaked.
Welcome Savings Bank has also identified a corporate customer information leak caused by a hacking attack and is reportedly investigating the exact scale of the damage and the leakage route.
In short, wide-ranging hacking attacks have been carried out simultaneously across Tier 1 and Tier 2 financial sectors over the span of just a few days.
A key official in the financial sector pointed out, "Even if there is no data leakage, financial companies must report cyber intrusions to financial authorities if they are targeted by hacking attacks," adding, "The number of financial institutions that received attack attempts this time could be far greater than what has been made public."
However, the same attack traces have not been found so far in the securities, insurance, and card sectors, nor in state-run banks such as IBK and the Export-Import Bank of Korea.

Financial authorities' chiefs, Financial Services Commission Chairman Lee Eok-won and Financial Supervisory Service Governor Lee Chan-jin, will convene an emergency inspection meeting this afternoon at the Government Complex Seoul, gathering heads of all financial sector associations and chief executive officers (CEOs) of financial institutions that have experienced security incidents.
The meeting is scheduled to be attended by the heads of Shinhan, Kookmin, Hana, and Busan banks, Hyundai Capital, and Yegaram and Welcome savings banks, among others.
Authorities are paying close attention to the fact that these attacks did not target specific companies, but rather exposed vulnerable financial firms in the process of indiscriminate AI-driven attacks.
Because the attack timings and methods are similar, they are highly likely to be the work of the same group, but identifying the perpetrators is expected to take time due to inconsistencies, such as AI not being utilized in some of the attacks.
In particular, a common thread is that hackers intelligently zeroed in on "gaps" in employee-use or non-critical business support systems rather than customer-facing financial operation systems.
Unlike customer channels, they targeted internal-use homepage menus or apps that do not necessarily require strict authentication procedures.
For instance, at Shinhan Bank, the "Loan Consultant Application Loan Progress Status Inquiry" service used by loan agents served as the channel for data leakage.
According to materials submitted by Shinhan Bank to the National Assembly, the attacker's IP is estimated to have first flowed in at 6:04 PM on September 28.
The attacks continued for about 30 hours until 0:15 AM on September 30, resulting in the leakage of 25,727 pieces of personal information.
After detecting the attack at 9:30 AM on September 29, the bank blocked the IP and suspended certain services, but attacks targeting six services, including loan application result inquiries on the mobile homepage, continued.
The hackers secured valid customer numbers through random input to extract information, utilizing IPs from multiple countries including South Korea, the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, and the United Kingdom.
KB Kookmin Bank suffered damage through "RM Agent" and "PB Agent," which are mobile work support systems for employees.
According to data secured by the office of Democratic Party lawmaker Park Min-gyu, the attacks lasted for 42 hours and 41 minutes from 11:19 PM on September 27 to 6:00 PM on September 29.
A total of 153 items were leaked, including information on 20 executives and employees, customer names, and mobile phone numbers, along with the encrypted resident registration numbers of some customers.
Some banks where customer information was leaked have temporarily suspended the operation of "satellite sites" that exposed security vulnerabilities and are closely monitoring the possibility of secondary damage.
These banks have kept customer reporting channels open and promised full compensation if damages occur.
The possibility is also being raised that beyond financial companies with already public accidents, there may be others that have yet to figure out their damages.

A high-ranking financial authority official said, "We cannot rule out the possibility that additional damage cases may emerge beyond those reported to the authorities so far."
Particularly, concerns are being raised that non-financial companies with relatively insufficient information security capabilities might experience delayed detection and response even if they suffer similar attacks.
A financial sector official expressed worry, saying, "Private companies might not even recognize the fact that they were breached by AI hacking. If secondary damage occurs through such pathways, it could turn into a much bigger problem."
Voices calling for a joint response led by financial authorities or at the entire industry level are growing louder.
Another official pointed out, "Advanced AI hacking seems to have surpassed the level where individual companies can be left to handle it on their own. There are clear technical limitations to telling companies to fend for themselves and holding them accountable if they fail."
Even within the authorities, the judgment is that it is difficult to fend off new methods of finding and exploiting vulnerabilities using AI with existing security capabilities.
As a result, there is an atmosphere of deep deliberation over how far to overhaul the financial sector's security systems.
In fact, during an emergency situation response meeting presided over by the Financial Services Commission on October 2, opinions reportedly emerged that new institutional measures are necessary as the current response system has been neutralized.
Authorities are expected to continue related discussions by summoning financial company representatives this afternoon.
Momentum is also expected to pick up for the relaxation of network separation regulations currently being pursued by the FSC.
Currently, domestic financial companies are subject to network separation regulations requiring business systems and other networks to be physically separated and blocked from external communication networks for security reasons.
The authorities' stance is that network separation regulations should be completely lifted for financial companies equipped with response capabilities so that rapidly evolving AI attacks can be defended against using AI.
Since last June, companies wishing to participate have been selected to undergo regulatory easing tests, and the second batch of participating companies will be selected on October 7.