Authorities inspect banks hit by data breaches
IPs used in Shinhan Bank and KB Kookmin Bank attacks found to partially match
Hana Bank also reports leak of 89 customers' data
Experts say same perpetrator cannot be ruled out
Some of the IP addresses used in a series of hacking attacks on South Korea's major banks — including five of the country's largest lenders and Busan Bank — have been found to match, raising the possibility that the attacks were carried out by the same perpetrator or a coordinated group, according to sources familiar with the matter. Authorities are analyzing the methods and routes of the attacks.
Some of the IP addresses used to attack Shinhan Bank match those used in the attack on KB Kookmin Bank, authorities have determined, according to sources.
Earlier, Shinhan Bank disclosed that the personal and credit information of about 25,000 customers who had applied for loans was leaked. The compromised data included names, phone numbers, annual income and calculated credit limits collected during the loan application process. The breach also included 66 resident registration numbers and 97 connected information (CI) records belonging to some of those customers.
Following the Shinhan Bank incident, KB Kookmin Bank also reported a breach involving the personal and credit information of 119 customers. The leaked data included names, phone numbers, addresses and encrypted resident registration numbers.
Authorities from the financial and cybersecurity sectors confirmed the partial IP match while comparing the addresses used in the two attacks and analyzing similarities between the incidents.
Hana Bank disclosed Friday afternoon that the data of 89 customers had been leaked, adding to the growing list of affected lenders. Woori Bank and NH NongHyup Bank also disclosed Friday that they had been targeted by external hacking attempts, underscoring the wave of cyberattacks hitting the banking sector.
IT security experts said that matching IP addresses alone are not sufficient to conclude the attacks were carried out by the same actor, but that the overlap could serve as one indicator of a possible link between the incidents.
"The fact that the same IP addresses were identified is not enough on its own to conclude that the same attacker is responsible," said Kim Seung-joo, a professor at Korea University's Graduate School of Information Security. "But it is one of several circumstances that emerged during the attacks, so it is reasonable to suspect the possibility that they were carried out by the same perpetrator or a connected group."
The Financial Services Commission held an emergency response meeting Friday at Government Complex Seoul, chaired by Secretary General Shin Jin-chang, with the Financial Supervisory Service, the Korea Financial Security Institute, major banks and card companies, and related industry associations in attendance.
The FSC, the Financial Supervisory Service and the Korea Financial Security Institute are conducting on-site inspections of financial institutions that have filed breach reports. To prevent further damage, they plan to share threat intelligence — including attacker IP addresses and attack types — with the Korea Internet & Security Agency and other relevant agencies, while also reviewing consumer protection and compensation measures at the affected institutions.
hyuk@heraldcorp.com
rim@heraldcorp.com