SBS NEWS

News > Economy

KakaoBank, K Bank Servers Also Targeted... 28 Attacker IPs Identified

Lee Tae-gwon

Published : Oct 6, 2026 9:35 PM

Video

[Anchor]

It has been confirmed that some of the IP addresses used in the widespread financial sector hacking incident also attempted to access the servers of KakaoBank and K Bank. Financial authorities have identified 28 IPs used in the attacks.

Reporter Lee Tae-gwon has the details.

[Reporter]

Some of the internet addresses, or IPs, used to attack seven financial institutions including Shinhan Bank, where personal information leakage damage occurred, were found to have also attempted access to all three of South Korea's internet-only banks.

Following confirmed access attempts on Toss Bank since January, K Bank was found to have been accessed a total of four times by IPs from the United States and South Korea from July to last month.

It was confirmed that IPs from China, the United States, and Malaysia accessed KakaoBank's servers six times between January and March, and there was even one actual attack attempt on September 29 aimed at identifying server vulnerabilities.

However, these access attempts were blocked by security systems and did not lead to personal information leakage or other damage.

The Financial Supervisory Service has identified 28 attacker IPs and distributed them to the financial sector along with information on the countries of origin.

[Kwon Heon-young, Professor at Korea University Graduate School of Information Security: Since there may be attacks in the form of routing, additional analysis will likely be needed to find out where the actual original attack came from. Additional checks must also be made to see if the risk is spreading to other areas....]

Banks and card companies conducted emergency inspections of their security systems by today (October 6) at the request of financial authorities.

BNK Busan Bank, where the personal information of 11 outsourced workers was exposed on October 1, was confirmed to have reported a "deficient" rating in one out of 12 checklist items, namely the omission of external system authorization verification functions.

This means that although it was not the main system, there was an external page that could be accessed without a separate login.

Financial authorities issued a consumer alert warning stage, citing the possibility of secondary damage, and designated one month starting today as a special response period, instructing financial institutions to operate dedicated customer service desks for affected clients and to strengthen the detection of anomalous transactions.

(Video Editing: Park Ji-in | VJ: Lee Ji-hwan | Design: Park Cheon-woong)