
Hacking attacks, presumed to utilize AI, have occurred across all fronts targeting domestic financial companies. It has been revealed that attacks have extended beyond banks, savings banks, capital companies, and online investment-linked finance businesses (hereinafter referred to as online investment businesses), which have already shown damage, to the insurance and securities sectors.
As domestic financial companies have recently emerged as concentrated targets for international hackers, warnings are being issued that the financial sector's response capabilities and their effectiveness will influence additional attacks.
According to the government and the financial sector on the 5th, financial industry associations by sector confirmed with member companies regarding the recently revealed AI-utilizing hacking incidents, finding traces of attackers accessing systems at one or two insurance companies and one or two securities firms. Previously, attacks or information leaks were successively confirmed at banks including KB Kookmin, Shinhan, Hana, and BNK Busan; savings banks such as Yega Ram and Welcome; Hyundai Capital; and online investment businesses such as PFCT and Moudda.
Financial authorities have launched inspections to check for additional intrusion traces in the insurance and financial investment sectors. However, as of now, there is no evidence that personal information or other data has been leaked externally from the insurance companies and securities firms where intrusion traces were found, nor that their systems have been substantially compromised.
Financial authorities ordered banks and card industries to complete inspections by the 6th, and insurance companies, securities firms, savings banks, and electronic finance providers by the 8th. This attack utilized methods of penetrating relatively vulnerable external touchpoints, such as external webpages and servers used by employees or loan solicitors for business purposes, rather than directly targeting core computer networks. Consequently, it was assessed that additional hacking incidents that have not yet been confirmed cannot be ruled out.