Suspected AI hacking attempts hit five major banks
Financial authorities launch emergency security review
South Korea's major commercial banks, including KB Kookmin Bank and Hana Bank, have been exposed to suspected AI-assisted hacking attacks following a similar incident at Shinhan Bank, putting the financial sector on high alert.
Hacking attempts were recently detected at Shinhan Bank, KB Kookmin Bank, Hana Bank, Woori Bank and NH NongHyup Bank, according to financial industry sources Saturday. Of those, Shinhan Bank, KB Kookmin Bank and Hana Bank confirmed actual customer data leaks, while Woori Bank and NH NongHyup Bank said they blocked external access attempts and have not confirmed any data exposure. Financial authorities directed banks and credit card companies to conduct their own security reviews.
Shinhan Bank suffered the largest breach. An external attacker bypassed the identity verification process in a loan solicitor service, exposing the personal information of 25,729 customers. The leaked data included names, phone numbers, annual income, loan limits, resident registration numbers and linked identification information.
The bank's internet and mobile banking systems — which rely on login authentication — were not compromised. The breach occurred in a simplified inquiry service used by loan solicitors, sources said.
At KB Kookmin Bank, an external intrusion into an employee mobile work-support system exposed the personal and credit information of 119 customers, including names, phone numbers, addresses and encrypted resident registration numbers.
Hana Bank also confirmed that an external attacker gained unauthorized access to its sales support system, known as ODS, and extracted seven categories of data on 89 customers — including names, resident registration numbers, addresses, email addresses, phone numbers, mobile phone numbers and employer names.
In both the KB Kookmin Bank and Hana Bank cases, the data was taken from internal work-support systems rather than customer-facing financial transaction platforms.
At Busan Bank, the names, phone numbers, dates of birth and email addresses of 11 outsourced development staff members were exposed.
The Korean National Police Agency's cyber terror investigation unit has launched a pre-indictment probe into the institutions that have officially reported hacking damage.
In response to the string of incidents, the Financial Services Commission convened an emergency response meeting Friday that brought together the Financial Supervisory Service, the Korea Financial Security Institute, major banks and credit card companies, the Korea Federation of Banks and the Credit Finance Association.
Financial authorities plan to have financial firms conduct self-assessments based on a security vulnerability checklist and report the results promptly.
Shin Jin-chang, secretary general of the Financial Services Commission, said the authorities would "closely monitor intrusion attempts in the financial sector and work in close cooperation to swiftly share threat information." He added that they would "thoroughly analyze the causes and methods of the attacks and quickly develop measures to improve the regulatory regime."
kido@heraldcorp.com