South Korea activates 24-hour cyber emergency system over financial hacks
In short
South Korea’s science ministry said on Oct. 4 that it activated a 24-hour emergency cyber response system with KISA after a series of hacking incidents at financial companies, and sent security inspection advisories to about 28,000 companies. Financial authorities are leading the investigation. Kyunghyang Shinmun and Asia Economy reported breaches at seven financial firms, and authorities estimate an attacker changed IP addresses and used AI tools to run automated attacks. No figures on leaked customer data or the attacker’s identity have been given.
Read the full story 2 min read
South Korea’s Ministry of Science and ICT said on Oct. 4 that it has activated an emergency response system with the Korea Internet & Security Agency (KISA) after a series of hacking incidents at financial companies. The ministry said the incidents are being investigated and handled by the Financial Services Commission, the Financial Supervisory Service and the Financial Security Institute, while it and KISA work to keep the attacks from spreading to the private sector and causing further damage. [ 3 , 4 , 6 , 8 , 9 ]
Under the measures, KISA strengthened its Internet Incident Response Center, increased monitoring of major companies’ websites, added incident-response staff and placed an emergency dispatch team on standby around the clock, the ministry said. [ 3 , 4 , 6 , 8 , 9 ]
The ministry said threat information is being shared with institutions and companies through the Boho Nara portal and the Cyber Threat Analysis and Sharing system, or C-TAS, which Newsis and ZDNet Korea reported has about 5,900 member companies. Security inspection recommendation emails were sent to about 28,000 companies registered as reporting chief information security officers. Threat information on overseas attacker IP addresses identified by the Financial Security Institute was passed to the relevant cloud operators with a request to block the malicious activity, the ministry said. [ 3 , 4 , 6 , 8 , 9 ]
Kyunghyang Shinmun and Asia Economy reported that breaches were confirmed at seven financial firms — Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. Citing financial authorities, Kyunghyang Shinmun said the same attacker’s IP address was found in multiple incidents and that the attacker is suspected of changing IP addresses and using AI tools to run automated attacks against multiple financial firms. Asia Economy reported that the financial sector views the incidents as mass automated attacks using AI tools and said data was leaked at the seven firms. [ 6 , 9 ]
Earlier, Seoul Shinmun reported on Oct. 2 that authorities had called for checks of all externally exposed IT systems after the hacking incidents, and Newsis reported on Oct. 4 that KISA recommended prioritizing checks of web and API vulnerabilities. The ministry said it is prepared to send KISA personnel to the scene immediately if the Financial Services Commission or the Financial Supervisory Service requests expert support. [ 1 , 2 , 3 , 8 ]
Why it matters
The response shows authorities treating the financial-sector incidents as a risk that could spread to other private-sector services, with about 28,000 companies told to check their security. If the authorities’ assessment that AI tools were used for automated attacks holds, the same method could be applied more widely. The documents give no estimate of damage or of how many customers were affected.
Key facts
- The Ministry of Science and ICT said on Oct. 4 that it activated a 24-hour emergency response system with KISA over the financial-sector hacking incidents. [ 3 , 4 , 6 , 8 , 9 ]
- KISA strengthened its Internet Incident Response Center, increased monitoring of major companies’ websites, added incident-response staff and put an emergency dispatch team on standby. [ 3 , 4 , 6 , 8 , 9 ]
- About 28,000 companies registered as reporting chief information security officers received emails recommending security checks. [ 3 , 4 , 5 , 6 , 8 , 9 ]
- Threat information is shared through the Boho Nara portal and the Cyber Threat Analysis and Sharing system (C-TAS), which Newsis and ZDNet Korea reported has about 5,900 member companies. [ 4 , 8 ]
- The Financial Services Commission, the Financial Supervisory Service and the Financial Security Institute are leading the investigation and response. [ 3 , 4 , 6 , 8 , 9 ]
- Threat information on overseas attacker IP addresses identified by the Financial Security Institute was provided to the relevant cloud operators with a request to block the malicious activity. [ 3 , 4 , 6 , 8 , 9 ]
- Kyunghyang Shinmun and Asia Economy reported breaches at seven financial firms: Shinhan, KB Kookmin, Hana and BNK Busan banks, Yegaram and Welcome savings banks, and Hyundai Capital. [ 6 , 9 ]
- Financial authorities estimate the attacker changed IP addresses and used AI tools to run automated attacks against multiple financial firms. [ 6 , 9 ]
Confirmed by several sources
- The science ministry and KISA activated a 24-hour emergency cyber response system in connection with the financial-sector hacking incidents. [ 3 , 4 , 6 , 8 , 9 ]
- Security inspection recommendation emails were sent to about 28,000 CISO-reporting companies. [ 3 , 4 , 5 , 6 , 8 , 9 ]
- Financial authorities — the Financial Services Commission, the Financial Supervisory Service and the Financial Security Institute — are leading the investigation and response. [ 3 , 4 , 6 , 8 , 9 ]
- Threat information on overseas attacker IP addresses was passed to cloud operators with a request to block malicious activity. [ 3 , 4 , 6 , 8 , 9 ]
- Breaches were confirmed at seven financial firms, including Shinhan, KB Kookmin, Hana and BNK Busan banks, Yegaram and Welcome savings banks, and Hyundai Capital. [ 6 , 9 ]
- Authorities estimate the attacker used AI tools and changed IP addresses to run automated attacks against multiple financial firms. [ 6 , 9 ]
Still unclear
- How many customers were affected and what personal or financial data was exposed. Kyunghyang Shinmun and Asia Economy report breaches and data leakage at seven firms, but no document gives figures on affected customers or the data involved.
- Who carried out the attacks. Documents refer only to overseas attacker IP addresses confirmed by the Financial Security Institute; no attribution or location beyond that is given.
- When the individual hacking incidents occurred and which systems were breached at each company. The documents describe the response and the affected companies but give no dates or system details for the incidents themselves.
- Whether attacks have spread beyond the financial sector. The ministry says it is acting to prevent spread to private-sector services; the documents do not say whether any non-financial company has been affected.
- KISA’s recommendation to prioritize web and API vulnerability checks. This appears only in a single Newsis headline and is not detailed by any other document.
What local media are saying
Timeline, local time
- Seoul Shinmun reports that authorities, after successive hacking incidents, called for checks of all externally exposed IT systems. [ 1 ]
- Newsis reports that KISA recommended prioritizing checks of web and API vulnerabilities as financial-sector breaches continued. [ 2 ]
- KISA shares cyber threat information through the Boho Nara portal and C-TAS so that institutions and companies can strengthen their own security measures, according to ZDNet Korea; no time of day is given. [ 8 ]
- The Ministry of Science and ICT announces it has activated a 24-hour emergency response system with KISA and sent security inspection advisory emails to about 28,000 companies. [ 3 , 4 ]
- Kyunghyang Shinmun reports breaches confirmed at seven financial firms and authorities’ assessment that an attacker changed IPs and used AI tools for automated attacks. [ 6 ]
- Asia Economy reports that the seven firms suffered data leakage damage and that the financial sector views the incidents as mass automated attacks using AI tools. [ 9 ]