18 overseas hacking incidents hit financial sector over nearly 3 years
Attackers identified in only 2 cases
Financial authorities push to ease network-separation rules for AI-based defenses
Only 2 of 18 overseas hacking incidents targeting South Korea's financial sector over the past two years and nine months were traced to an identified attacker, data submitted to the National Assembly showed. As AI-powered cyberattacks grow more sophisticated, financial regulators are expected to accelerate the easing of network-separation rules to allow AI-based security tools to be deployed in defense.
According to data that People Power Party lawmaker Song Eon-seog, a member of the National Assembly's Political Affairs Committee, obtained from the Financial Supervisory Service, 18 incidents presumed to involve overseas hacking were recorded at financial companies from 2024 through Thursday. Attackers were identified in just 2 of those cases.
The breach at Seoul Guarantee Insurance last July was attributed to the international ransomware group GUNRA. The attack infected servers and disrupted services for roughly 64 hours; Seoul Guarantee Insurance paid customers 11.91 million won ($8,890) in compensation.
A separate intrusion at Baro Savings Bank in April was also attributed to a specific group — the ransomware gang INC Ransom — because the attackers directly demanded payment.
Of the remaining 16 cases, 13 were presumed to originate overseas based on domain lookups, detections by in-house security equipment, or breach investigations, while 3 could not be attributed at all and were classified as originating from an "unknown foreign country."
The FSS recently shared 28 unique attack IP addresses with the financial industry along with limited country-of-origin information, cautioning that the data should be interpreted carefully given the possibility of rerouted connections.
In materials submitted to Song's office, the FSS said that "in most cases, attackers disguise or reroute their connections using IP spoofing or virtual private networks, making it effectively impossible to identify the attacker based solely on the country associated with an IP address."
Separately, overseas cyberattacks on electronic financial service providers and online peer-to-peer lending platforms during the same period also proved difficult to trace. Of 12 incidents recorded in those sectors, attackers were identified in only one case.
Calls are growing for financial firms to build systems capable of identifying attackers, particularly as hacking operations using AI agents become more common. "Building an AI-based defense system to counter hacking is urgent," Song said. "Because attackers can reroute or disguise their IP addresses, identifying the real source from an overseas IP alone is difficult — developing technology to trace attack pathways and pinpoint the actual perpetrator is becoming increasingly important."
At the Financial Services Commission's national audit Thursday, FSC Chairman Lee Eok-won addressed how the financial sector should respond to AI-powered hacking, saying "to stop AI, you ultimately have no choice but to use AI," and signaling his intent to ease network-separation regulations.
At the same audit, Democratic Party of Korea lawmaker Park Min-gyu said payments and cloud services were already granted exceptions but AI used for security purposes was not, adding that "the weapons hackers use are upgraded every day, yet the security AI that banks could deploy remains blocked by network-separation rules."
In response, Lee said the FSC was "considering various phased and effective approaches to how the network-separation rules should be reformed" and pledged to "look into it carefully."
In his opening remarks at the audit, Lee said the FSC was "pursuing the lifting of network-separation regulations, premised on security, in order to support innovation and strengthen security capabilities in the financial sector."
Financial authorities have been discussing with the industry since June how to ease network-separation rules specifically for security-oriented AI, and the recent surge in AI-powered hacking has added urgency to those talks. The aim is to allow financial companies to use high-performance external AI and security software-as-a-service tools to detect vulnerabilities more quickly and broadly than existing methods permit.
Regulators are also working with the ruling party to amend the Electronic Financial Transactions Act to impose fines for security breaches and strengthen the authority of chief information security officers.
Lee also said of the recent wave of AI-powered attacks on the financial sector that "the threats keep growing, yet our response falls far short even in the most basic areas."
killpass@heraldcorp.com