KISA bolsters response staff, keeps emergency teams on standby
Overseas attacker IPs blocked; security-check advisories sent to firms
Development of security-focused 'K-Mitos' AI model accelerates; cooperation with foreign IT firms to deepen
The government has launched an all-out effort to contain a widening wave of cyberattacks on the financial sector. The Ministry of Science and ICT has activated an emergency response framework in coordination with the Korea Internet & Security Agency.
With reports indicating that the attacks exploited AI, the ministry is expected to accelerate development of the homegrown security-focused AI model known as K-Mitos. Cooperation with global AI companies is also set to intensify as South Korea's access to the US government's Mitos model remains restricted.
The Financial Services Commission, the Financial Supervisory Service and the Korea Financial Security Institute are leading the investigation and response to the financial sector hacking incidents, the government said Tuesday. The Ministry of Science and ICT and the Korea Internet & Security Agency are also stepping up their cyber-threat response efforts to prevent further damage.
The mobilization follows confirmed hacking incidents at seven financial institutions: Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital Services.
To guard against additional fallout, the Korea Internet & Security Agency has strengthened the response framework at its Internet Infringement Response Center. Measures include enhanced monitoring of major corporate websites, reinforced incident-response staffing and round-the-clock emergency deployment teams on standby.
The agency also used C-TAS — a platform for sharing malware data, attacker IP addresses and the latest cyber-threat intelligence — to distribute threat information and advise institutions and companies to tighten their own security measures.
Security-check advisory emails containing links to relevant notices were sent to about 28,000 companies that have registered a chief information security officer. For overseas attacker IP addresses identified by the Korea Financial Security Institute, the agency requested that the relevant cloud service providers block the malicious activity and take other necessary steps.
Reports that AI was used in the broad-based attacks on the financial sector are expected to accelerate the government's countermeasures on that front as well.
Development of K-Mitos through the Naver Cloud consortium — selected last month as the operator for a cybersecurity-focused AI foundation model development project — is expected to pick up pace.
The Naver Cloud consortium includes key ICT affiliates of LG Group: LG CNS, LG AI Research and LG Uplus. Starting last month, the consortium is set to receive support covering 200 GPUs — 256 units in total over five months — with an additional five months of support to follow depending on a midterm evaluation.
As AI-driven hacking attacks grow more serious, development of the cybersecurity-focused AI foundation model is expected to accelerate in parallel with the push to build frontier-level AI capabilities ahead of the March deadline next year.
Beyond K-Mitos, cooperation with US AI companies is also expected to move into full gear. The Ministry of Science and ICT is currently working with OpenAI's GTAC (since late May this year), Google's Gemini Flash Cyber (since late July this year) and Microsoft's Mdash (application pending).
The ministry is also expected to mount an all-out push to secure access to Mitos, the US model it has yet to obtain clearance for.
"The threat level of AI hacking is crossing a critical threshold, with AI autonomously identifying vulnerabilities and automating attacks," an industry official said. "We cannot protect core national infrastructure and corporate data by relying solely on foreign technology."
"Building Korea-specific security-focused AI models, including K-Mitos, is not an option but an essential survival strategy," the official added. "This incident is expected to prompt a significant increase in government support and a rapid expansion of proof-of-concept collaboration projects between technically capable private companies and government agencies."
ko@heraldcorp.com