Video
[Anchor]
It has been confirmed that the internet protocol (IP) address used in recent successive hacking attacks on the financial sector also attempted to access Toss Bank earlier this year. Fortunately, it did not lead to a leak of personal information, but it suggests that widespread attacks had been taking place long before the recent incidents.
Reporter Lee Tae-gwon has more.
[Reporter]
During the hacking of Shinhan Bank on September 29, which resulted in the leakage of 25,000 pieces of personal information, IP addresses from at least eight countries, including Japan, the United States, and Hong Kong, were used.
However, it has been verified that two of these U.S. IPs are identical to those that already attempted to access Toss Bank's servers as early as January.
According to data submitted by Toss Bank to the National Assembly, these IPs attempted to access Toss Bank's internal servers three times on January 24, and 11 times in July and August.
However, no personal information leakage damage occurred as the access attempts were blocked.
Previously, financial authorities shared the attacker IPs with the financial sector and ordered inspections after hacking damage occurred at seven financial institutions, including major commercial banks like Shinhan, KB Kookmin, and Hana, as well as secondary financial institutions such as savings banks. This is the first time it has been confirmed that internet-only banks were also targeted by attack attempts.
[Choi Kyung-jin / Professor of Law at Gachon University & President of the Personal Information Professionals Association: If continuous attacks from the same IP have taken place over a considerable period, the probability of it being the same hacker naturally increases. It is necessary to quickly identify and share that information.]
In addition, it was found that the IPs related to the recent hacking incidents also attempted to access servers at two life insurance companies, including Kyobo Life Insurance.
As there is a possibility that these hacking attempts were carried out on a widespread scale long before they became known, experts point out that the scope and period of inspections need to be expanded.
[Kim Hyung-yeon / National Assembly Political Affairs Committee Member (Rebuilding Korea Party): Financial companies across the board should check their access logs for at least a year and utilize AI to catch newly evolving hacking methods...]
The Financial Supervisory Service has shared the attacking IPs and security precautions with the entire financial sector, and has instructed banks and credit card companies to complete emergency inspections by today (October 6), while securities firms, insurance companies, and savings banks must finish by October 8.
(Reported by Kim Hak-mo | Video by Kim Jin-won | Graphics by Choi Ha-neul)