Video
[Anchor]
It has been confirmed that some of the internet addresses used in the financial sector hacking attempts tried to access not only Toss Bank, but also the servers of KakaoBank and K Bank. Financial authorities have identified 28 internet addresses used in the attacks and issued a consumer alert in preparation for potential secondary damage.
Reporter Lee Tae-gwon has the details.
[Reporter]
Some of the internet addresses, or IPs, used in the attacks against seven financial institutions that suffered personal information leaks, including Shinhan Bank, were found to have also attempted access to all three of South Korea's internet-only banks.
Following the confirmed access attempts to Toss Bank starting last January, K Bank was found to have had its servers accessed a total of four times by U.S. and domestic IPs from last July to last month.
KakaoBank experienced server access attempts from Chinese, U.S., and Malaysian IPs six times between January and March, and it was confirmed that there was actually one attack attempt on September 29 aimed at identifying server vulnerabilities.
However, these access attempts were blocked by security systems and did not lead to personal information leaks or other damage.
The Financial Supervisory Service has identified 28 attacker IPs and distributed them to the financial sector along with information on the countries of origin.
[Kwon Heon-young, Professor at Korea University Graduate School of Information Security: Since there may be attacks in a bypassed form, additional analysis will likely be needed to find out where the actual original attack came from. Additional checks must be conducted to see whether the risk is spreading elsewhere....]
Banks and card companies carried out emergency security system inspections by yesterday (October 6) at the request of financial authorities.
BNK Busan Bank, where personal information of 11 outsourced workers was exposed on October 1, was confirmed to have reported a rating of "insufficient" in one out of 12 checklist items—specifically concerning the omission of access verification functions for external systems.
This means that while it was not the main system, there was an external page that could be accessed without a separate login.
Stating that secondary damage could occur, financial authorities issued a "Caution" level consumer alert and designated a one-month special response period starting yesterday, instructing financial companies to operate dedicated support desks for affected customers and strengthen the detection of abnormal transactions.
(Video Editing: Shin Seeun, VJ: Lee Jihwan, Design: Park Cheon-woong)