SBS NEWS

News > Society

Financial Sector Targeted via IP Addresses from 12 Countries... FSS Identifies 19 'Attack Addresses'

Lee Jaewon

Published : Oct 6, 2026 11:52 AM


▲ Hacker (File Photo)

Financial authorities have reportedly identified 19 internet addresses in connection with hacking attacks on the financial sector suspected of utilizing AI agents. 

According to financial authorities and the financial sector, the Digital Risk Analysis Team of the Financial Supervisory Service (FSS) has pinned down 19 internet addresses used by the attackers in the recent financial hacking incident. 

The locations of these internet addresses span across 12 countries. 

They include the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, Sweden, and Germany. 

Addresses originating from the United States were the most frequent at five, followed by two each from Japan, Sweden, and Germany. 

There was also one domestic internet address. 

It appears that a hacker of unknown nationality bypassed and infiltrated systems using internet addresses from various countries to evade tracking, explored multiple services within financial institutions' systems, discovered vulnerabilities, and launched concentrated attacks. 

The FSS reportedly narrowed down the scope of the attacker's internet addresses based on the ones that accessed certain banks, including Shinhan Bank, through abnormal routes to steal customers' personal information. 

The FSS distributed this list of attacker internet addresses to the entire financial sector, requesting that they complete self-inspections and address any inadequacies by the 8th. 

Through official documents, the FSS urged institutions to closely identify externally exposed information technology assets and services, inspect and remediate vulnerabilities, and check the authentication, authorization, and verification functions of external systems that could be exploited as intrusion pathways. 

In addition, the authority distributed a 12-item checklist asking whether the shared attacker internet addresses have been blocked, whether there were any intrusion attempts or damages associated with them, and whether a real-time security monitoring system is in operation for the early detection and response to cyber threats and intrusion attempts. 

Financial institutions are continuing their self-inspections by expanding the period and scope. 

Internet-only bank Toss Bank, for instance, found that abnormal access attempts had been made through some of the attacker internet addresses identified by authorities not only from July to August of this year, but as early as January. 

Some security industry insiders are leaning toward presuming the hacking is an attack originating from China. 

This is because traces of a Chinese-language artificial intelligence penetration testing tool released last July were detected. 

However, at the authority level, only the nationalities of the attacker internet addresses have been shared, and specific circumstances pointing to hacking suspicions from a particular country have not been explicitly mentioned. 

An official from the financial sector stated that it will take a considerable amount of time for the investigations by financial authorities and the Financial Security Institute, as well as police investigations, to yield results, and that it would be premature to jump to conclusions about which country's hackers are behind the incident before then.