Local Chorus
Local news from local sources, read in your language.
Developing

Korea financial regulator orders AI-based defense after hacking wave

🇰🇷 South Korea, Seoul 10:37 IT & software Business4 Tech updated 2 h ago first reported by 서울경제

In short

South Korea’s Financial Services Commission held an emergency meeting on 4 October after hacking and data leaks were confirmed at seven financial companies, including Shinhan, KB Kookmin, Hana and BNK Busan banks, savings banks Yegaram and Welcom and Hyundai Capital. Chairman Lee Eok-won told the industry to block external access by default and build a system in which “AI fights AI”, warning of strict accountability for any repeat. The Financial Supervisory Service sent attack IPs and a 12-point checklist to about 500 financial companies, with banks and card firms to finish inspections by 6 October.

Read the full story 2 min read

South Korea’s Financial Services Commission held an emergency meeting on 4 October with the Financial Supervisory Service, industry associations and major financial companies to coordinate a response to a series of cyber intrusions. The meeting was chaired by FSC Chairman Lee Eok-won and attended by FSS Governor Lee Chan-jin and Financial Security Institute President Park Sang-won, along with the Ministry of Science and ICT, the Personal Information Protection Commission, police and the Korea Internet and Security Agency, Newsis and Seoul Economic Daily reported. Seoul Economic Daily said the meeting had originally been planned for 7 October and was moved forward after damage spread to smaller financial firms. [ 2 , 3 ]

Breach incidents were confirmed at seven companies: Shinhan, KB Kookmin, Hana and BNK Busan banks, savings banks Yegaram and Welcom, and Hyundai Capital. Authorities said the same attacker IP address was found at several companies, raising the possibility of large-scale automated attacks using AI tools, according to Newsis and ZDNet Korea. [ 4 , 6 ]

Lee said external web pages and servers used for convenience by loan brokers and employees had been used as attack targets, and cited weak authentication and excess stored data as blind spots. He ordered financial companies to block all external access by default except where essential for services or operations. [ 2 ]

The chairman warned that companies found negligent could face strict accountability under relevant laws, and called for a system in which “AI fights AI”, saying new attack patterns exploiting unexpected vulnerabilities were spreading. He said no information usable for fraudulent payments had leaked yet, and ordered measures against secondary voice phishing and smishing damage. [ 2 , 3 , 4 ]

The FSS sent the attack IP, security guidance and a 12-point checklist to about 500 financial companies, ZDNet Korea reported. Banks and card companies must complete inspections by 6 October, while securities, insurance, savings bank and electronic finance firms have until 8 October. Newsis reported the FSC is pushing to expand exceptions to network separation rules so high-performance external AI can be used for security testing. [ 4 , 6 ]

The National Assembly’s science and ICT committee is due to question the Ministry of Science and ICT on 6 October about the response, with a committee official telling Newsis that a cybersecurity control tower spanning the National Intelligence Service, MSIT and KISA is seen as necessary. The committee also plans to question Tving CEO Choi Ju-hee over a separate breach in which a public-private investigation team said 39.54 million user accounts, including duplicates, were exposed. [ 5 ]

Kim Seung-joo, a Korea University professor, proposed eight measures in a Facebook post cited by ZDNet Korea, including identifying assets, cutting unnecessary attack surfaces, building an “AI responds to AI” system, applying zero trust and organising the measures under a Korean-style cybersecurity framework led by the National Security Office. [ 6 ]

Why it matters

The incidents put the security of customer data held by banks and smaller financial firms at the centre of public scrutiny, and the regulator’s response points to tighter inspections and possible changes to network separation rules. Authorities cite a shared attacker IP at several companies as raising the possibility of AI-driven automated attacks, making the response a test of AI-based defences. A parliamentary audit on 6 October may add pressure for a central cybersecurity control tower.

Key facts

  • The Financial Services Commission held an emergency meeting on 4 October chaired by Chairman Lee Eok-won, with FSS Governor Lee Chan-jin and financial company executives attending. [ 2 , 3 ]
  • Breach incidents were confirmed at seven companies: Shinhan, KB Kookmin, Hana and BNK Busan banks, savings banks Yegaram and Welcom, and Hyundai Capital. [ 4 , 6 ]
  • Authorities said the same attacker IP address was found at multiple companies, raising the possibility of large-scale automated attacks using AI tools. [ 4 , 6 ]
  • Lee ordered that external access be blocked as a basic principle except where essential, and called for a security system in which AI defends against AI attacks. [ 2 , 4 ]
  • The FSS sent the attack IP, security guidance and a checklist to about 500 financial companies; banks and card companies must complete inspections by 6 October and other financial sectors by 8 October. [ 6 ]
  • Authorities said no information usable for fraudulent payments had leaked yet, while warning of secondary voice phishing and smishing risks. [ 2 , 3 ]
  • The National Assembly’s science and ICT committee is due to question the Ministry of Science and ICT on 6 October over the response. [ 5 ]

Confirmed by several sources

  • The Financial Services Commission held an emergency meeting on 4 October chaired by Chairman Lee Eok-won to respond to the hacking incidents. [ 2 , 3 , 4 ]
  • Breach incidents affected Shinhan, KB Kookmin, Hana and BNK Busan banks, savings banks Yegaram and Welcom and Hyundai Capital. [ 4 , 6 ]
  • Lee warned that companies found negligent could face strict accountability under relevant laws. [ 2 , 3 , 4 ]
  • Lee called for a security system in which AI is used to defend against AI attacks. [ 2 , 3 , 4 , 6 ]
  • The same attacker IP was found at several of the affected companies. [ 4 , 6 ]

Still unclear

  • Who carried out the attacks No document names an attacker, their location or an affiliation; outlets describe the incidents only as external cyberattacks.
  • Whether AI was actually used in the attacks Documents 4 and 6 say the shared IP raised the possibility of AI-based mass automated attacks, not that this was confirmed.
  • The scale of leaked data at each affected company Only Shinhan Bank’s figure of 25,000 affected people appears, in a single outlet, document 5; other outlets give no figures.
  • The role of the open-source AI agent ARTEX Only one tech outlet, document 6, names ARTEX as linked to the wave; no other document mentions it.
  • The outcome of the inspections and whether deadlines will be met Documents state the deadlines and checklist items but not the results of the inspections.

What local media are saying

Business mediaBusiness outlets focused on the regulator’s emergency response: the meeting and its attendees, Chairman Lee Eok-won’s warnings of strict accountability, the list of affected institutions, plans to ease network separation rules for security use, and the coming parliamentary audit. They relayed official statements at length and gave few technical details of the attacks. [ 1 , 2 , 3 , 4 , 5 ]
Technology mediaThe tech outlet focused on how the attacks were carried out, reporting a shared attacker IP, suspected AI-driven automated attacks, the open-source AI agent ARTEX, inspection deadlines for roughly 500 financial firms and a security professor’s proposed countermeasures, including a Korean-style cybersecurity framework. [ 6 ]

Timeline, local time

  1. The FSC and FSS hold an emergency meeting on cyber intrusion threats at the Government Complex in Seoul, chaired by Chairman Lee Eok-won; the meeting had been moved forward from 7 October. [ 3 ]
  2. Newsis reports the FSC chairman’s call for AI-based security to be prepared quickly. [ 1 ]
  3. Newsis reports the meeting, the attendees and Lee’s warning of strict accountability. [ 2 ]
  4. Seoul Economic Daily reports the meeting, the five directives to the financial sector and the absence so far of data usable for fraudulent payments. [ 3 ]
  5. Newsis reports the FSC’s plan to expand exceptions to network separation rules for security AI and the shared attacker IP. [ 4 ]
  6. Newsis reports that the National Assembly science and ICT committee will take up the AI hacking response. [ 5 ]
  7. ZDNet Korea reports FSS guidance to about 500 financial companies and inspection deadlines. [ 6 ]
  8. Banks and card companies are to complete emergency inspections by 6 October, the day the science and ICT committee questions the Ministry of Science and ICT. [ 5 , 6 ]
  9. Securities, insurance, savings bank and electronic finance firms are to complete inspections by 8 October. [ 6 ]