AI Automated Translation.

Font Size

Share

Shinhan, then Kookmin: Banks on high alert as AI infiltration leaves them defenseless

Shinhan, then Kookmin: Banks on high alert as AI infiltration leaves them defenseless

Personal data of 25,000 Shinhan and 119 KB customers leaked in succession
Industry suspects indiscriminate brute-force attempts leveraging AI… Need to strengthen security monitoring systems

Overview of banking sector data breach incidents / Graphic by Kim Ji-young
Overview of banking sector data breach incidents / Graphic by Kim Ji-young

As customer information was also leaked from KB Kookmin Bank following Shinhan Bank, the banking industry’s security system has been placed on high alert. Given that traces of an AI agent were detected in the Shinhan Bank case and recent attack attempts by AI agents have been identified, there is speculation that an AI agent may have been utilized in this incident. The use of such technology can accelerate hacking speeds from vulnerability discovery to actual attack execution compared to conventional methods, heightening vigilance within the financial sector.

According to the financial industry on the 2nd, Shinhan Bank and KB Kookmin Bank reported personal data breach incidents to the Financial Supervisory Service on the 30th of last month. Both banks recognized abnormal access attempts on September 29, the previous day, and took emergency follow-up measures, such as IP blocking, after confirming signs of information leakage the next day.

In the case of Shinhan Bank, a dedicated mobile homepage called "M-Shinhan," used by loan solicitors to check customers' loan statuses, was attacked, and it was confirmed that personal data of 25,000 individuals had been leaked. The leaked information includes 66 cases of resident registration numbers, 97 cases of CI-linked information, customer names, phone numbers, annual income, calculated limits, and other loan-related details.

Kookmin Bank’s employee mobile business support system became the target of the attack. Information including the names, phone numbers, addresses, and encrypted resident registration numbers of 119 customers was leaked.

The Financial Supervisory Service has begun investigating the incidents at both banks in collaboration with the Financial Security Institute. The scale of the damage may increase as the investigation progresses.

With hacking incidents occurring consecutively at major banks, the banking sector has initiated internal inspections. Woori Bank activated an emergency response system under the supervision of its Chief Information Security Officer (CISO) immediately after recognizing personal data leakage incidents at other banks and conducted a comprehensive inspection of suspected attack IPs. Hana Bank verified intrusion indicators such as IPs disclosed by the Financial Supervisory Service and proceeded with measures including blocking suspicious IPs and strengthening monitoring.

The series of hacking attacks that occurred this time is estimated to be credential stuffing, a method of indiscriminately inputting personal information such as IDs and passwords obtained from other sources to gain access. In particular, in the case of M-Shinhan, it is assessed that this method was facilitated because loan status could be checked using only mobile phone authentication.

Credential stuffing is an attack method well-known in the security industry. Last year, a hacking attack targeting the GS Retail website was carried out using this method, resulting in personal data leakage for a total of 1.58 million customers.

There is mention that an AI agent may have led the infiltration in this incident. According to Moon Jong-hyun, head of the Genians Security Center, the string "ARTEX — Autonomous Penetration Testing Console" was identified on a server that recently attacked domestic institutional investors. Director Moon noted, "This indicates circumstances suggesting that ARTEX AI was operated in the infrastructure or that related environments were utilized." ARTEX AI is an autonomous penetration testing system based on large language models (LLMs) that can autonomously execute everything from planning to vulnerability detection and actual attacks once goals and scope are set.

Previously, automated programs allowed for millions of inputs per hour. However, utilizing AI agents can significantly reduce the time required from information aggregation to vulnerability discovery and hacking attempts. There is a time lag between when security vulnerabilities arise in software and when they are improved through updates; it is pointed out that if an AI agent infiltrates, there is essentially no time to develop countermeasures, leaving targets defenseless.

As attacks utilizing AI agents are expected to increase, criticism is emerging that banks must strengthen their continuous security monitoring and rapid response systems. Hwang Seok-jin, a professor at the Graduate School of International Information Security at Dongguk University, stated, "The major issue is that abnormal access requests led all the way to customer information inquiries," adding, "Despite operating 24-hour security monitoring, there were deficiencies in continuously detecting login attempts and information inquiries."

"This article was translated using AI and may differ slightly from the original."