Police have launched a formal investigation into a series of AI-assisted hacking attacks on financial institutions.
The Korean National Police Agency's National Investigation Headquarters said Tuesday it had booked the case as a violation of the Act on Promotion of Information and Communications Network Utilization and Information Protection after verifying the facts surrounding the attacks. Citing the gravity of the case, police designated the agency's Cyber Terror Investigation Unit as the dedicated investigative team, appointing a senior superintendent as team leader and deploying 28 officers.
Police are still reviewing whether the case qualifies as a cybercrime subject to referral to the Serious Crimes Investigation Agency. Cybercrimes under that agency's jurisdiction include violations of the information and communications network law stemming from hacking of national critical infrastructure, and violations of the Electronic Financial Transactions Act stemming from hacking of electronic financial infrastructure.
"In this case, the affected financial institutions do not constitute national critical infrastructure, so the case does not fall under the referral requirement," the Korean National Police Agency said. "However, if the compromised systems qualify as electronic financial infrastructure, a referral would be required — and we have asked the Financial Services Commission for an authoritative interpretation."
The agency added that it would "work closely with relevant authorities to conduct a swift and rigorous investigation to put the public's concerns to rest."
Experts say the attacks should not be viewed in isolation but examined alongside China-based hacking campaigns that have continued over recent years. Kwon Heon-young, a professor at Korea University's Graduate School of Information Security, said "most large-scale cyberattacks over the past several years have been traced to China," adding that "this financial sector hacking should not be treated as a standalone incident — we need to look at whether it is part of a continuous pattern of attacks by Chinese hacker groups."
The government has taken steps to prevent further damage. The Ministry of Science and ICT activated an emergency response system with the Korea Internet & Security Agency, expanding monitoring of major corporate websites. It also sent security-check advisory emails to more than 28,000 companies that have registered a chief information security officer, urging them to strengthen their own security measures. For internet addresses of overseas attackers identified by the Financial Security Institute, authorities provided threat intelligence to relevant companies and issued guidance on blocking malicious activity.
arin@heraldcorp.com