Seoul:Recent cyberattacks on financial institutions in South Korea have exposed significant vulnerabilities in the country's security infrastructure. Seven companies, including major banks such as Shinhan Bank, KB Kookmin Bank, and Hana Bank, reported personal data leaks, while others managed to fend off similar threats.
According to Yonhap News Agency, the attacks primarily targeted systems connected to the external network rather than the core networks that handle deposits and transfers. This focus on peripheral systems, often used by loan agents or employees, allowed attackers to access valuable personal information. Shinhan Bank alone reported a breach affecting approximately 25,000 customers, while Hana Bank disclosed a leak involving 89 customers. The incidents are currently under investigation by the police, and financial authorities are exploring the potential use of AI in these attacks.
The use of artificial intelligence has shifted the dynamics of cyber threats, enabling attackers to quickly identify and exploit vulnerabilities. Financial regulators have traced the attacks to 19 IP addresses across 12 countries, although the ultimate perpetrators remain unidentified. This highlights a challenge for defenses based on known threats, which struggle against rapidly evolving tactics.
Woori Bank and NH Nonghyup Bank successfully blocked similar intrusions, employing measures such as biometric verification and restricted IP access. This contrast in outcomes underscores the need for regulators to reassess their approach to security, moving beyond static certifications and inspections towards dynamic and frequent testing of systems, including those managed by partners and contractors.
Regulators are urged to facilitate better information sharing among financial institutions to enhance collective defense, protecting against both successful breaches and attempted attacks. Such collaboration is crucial for understanding attack methods and identifying potential vulnerabilities across the industry.
Beyond the financial sector, the urgency of robust cybersecurity is underscored by an unrelated leak at Korea Electric Power Corp., which compromised the data of about 24,000 employees. These incidents collectively point to the critical need for comprehensive protection of peripheral systems, treating financial cybersecurity as a matter of national infrastructure security.