Will legislation to strengthen financial sector accountability gain momentum?
Firms face fines of up to 3% of sales for data breaches
Financial authorities warned of AI risks in July guidelines
As AI-assisted hacking attacks continue to hit South Korea's financial sector, a bill aimed at strengthening cybersecurity investment has been stalled in the National Assembly for more than 10 months. With the threat of AI-powered hacking now a reality, observers expect legislative discussions to accelerate as pressure mounts to hold financial executives more accountable and drive greater security spending.
According to financial industry sources and regulators, Democratic Party of Korea lawmaker Yoo Dong-su introduced an amendment to the Electronic Financial Transactions Act in late November last year after a series of large-scale hacking incidents struck Lotte Card and other firms. The bill was referred to a subcommittee of the National Assembly's Political Affairs Committee in March but has not been discussed once since then.
The amendment would clarify the responsibilities of chief executive officers and strengthen the authority of chief information security officers.
Under the bill, financial firms that suffer a breach resulting in the leak of transaction data or personal credit information would face fines of up to 3 percent of total sales. It would also introduce mandatory cybersecurity disclosure requirements. Firms that fail to follow through on remediation plans drawn from vulnerability assessments would face enforcement fines of up to 50 million won ($36,800).
While discussions have been repeatedly delayed by other legislative priorities, analysts say momentum could build as hacking incidents spread across the financial sector and the risk of indiscriminate AI-powered attacks grows.
Analysts say the string of hacking incidents that began in late September was worsened less by increasingly sophisticated AI tools than by inadequate security management at financial firms.
Core internal systems were relatively well protected, but peripheral systems exposed externally — such as loan agent inquiry services and employee work platforms — were loosely managed and became prime targets for attackers.
The Financial Services Commission and the Korea Financial Security Institute had already urged firms to prepare for exactly this kind of threat in July guidelines titled "How to Respond to AI Security Threats in the Financial Sector," but the warnings had not taken hold on the ground.
At the time, regulators stressed that "because AI can rapidly scan a financial firm's attack surface, it is critical that financial firms accurately identify and manage their IT assets and supply chains."
Specifically, the guidelines called on firms to categorize and comprehensively manage their IT assets based on internet exposure, operational importance, data sensitivity and patch status.
The guidelines also offered liability protections for minor IT incidents arising from vulnerability discovery or security patching conducted for security purposes. They further recommended that boards of directors and CEOs take an active role in response efforts, and that chief information security officers be granted authority over budget allocation and staffing.
Meanwhile, financial regulators are set to receive emergency inspection reports from banks and credit card companies by Tuesday. Securities firms, insurers, card companies and electronic financial service providers must complete their inspections by Thursday.
As of Monday afternoon, no additional breach reports had been filed beyond the seven firms already confirmed — Shinhan, KB Kookmin, Hana and BNK Busan Bank, along with Yegareum and Welcome savings banks and Hyundai Capital Services — as well as two online peer-to-peer lending platforms.
Hacking attempts were also detected at banks, internet banks, securities firms, insurers and savings banks, but most successfully repelled the attacks.
Credit card companies, insurers and savings banks continued emergency inspections through the holiday period to maintain their guard. Online peer-to-peer lending platforms that suffered breaches plan to report their checklist inspection status, follow-up measures and response plans to financial regulators Tuesday.
Regulators plan to identify and address vulnerabilities based on the inspection results, and will take strict action if the same type of incident recurs.
forest@heraldcorp.com