Translating into Русский. The English version is shown until it is ready.
Welcome Savings Bank intrusion ran nearly 120 hours, detected five days later
Коротко
Welcome Savings Bank was breached for about five days before it detected the intrusion, according to data the Financial Supervisory Service submitted to lawmaker Han Chang-min's office. The bank reported that the attack began on Sept. 27 and that leaked data included corporate internet banking IDs and contact details; it estimated 2,299 of 2,370 data items contained personal information. Hyundai Capital also took five days to detect a 24-minute attack on the same day, and one report says 28 attack IP addresses have been shared with financial firms.
Читать полностью 2 мин чтения
Welcome Savings Bank was hit by an intrusion that ran for about five days before the company detected it, according to data the Financial Supervisory Service submitted to the office of Rep. Han Chang-min of the Social Democratic Party. The bank reported to authorities that the intrusion began on Sept. 27 at about 5:09 p.m. It recognised the incident on Oct. 2 at about 4:04 p.m., about 116 hours 55 minutes later, after receiving an email from the Financial Security Institute that shared related IP addresses following the Shinhan Bank hacking incident, the reports said. [ 1 , 2 ]
Eight minutes after detecting the incident, at 4:12 p.m., the bank blocked the IP as an initial response, and one minute later relayed the situation to the operations manager, according to the reports. The attack was reported to have ended the same day at about 4:25 p.m. Maeil Business reported the welcome Savings Bank attack lasted a total of 119 hours 16 minutes, while Yonhap's headline described it as lasting nearly 120 minutes. [ 1 , 2 ]
The leaked data included corporate internet banking IDs, corporate names, representatives' names, company work contacts, mobile phone numbers and email addresses. Welcome Savings Bank estimated that 2,299 of 2,370 leaked data items contained personal information. The reports said this count did not remove duplicates and that the company plans to re-report the scale of the damage by data subject later. [ 1 , 2 ]
Hyundai Capital also detected its own attack late. The company was attacked for about 24 minutes from Sept. 27 at 6:37 a.m., with the attack ending at about 7:01 a.m., but it recognised the incident only on Oct. 2 at about 5:08 p.m. Hyundai Capital reported that its investigation into the circumstances and possibility of customer data leakage found no actual damage, while some personal information of 146 housing loan recruiters was leaked, the reports said. [ 1 , 2 ]
Han said it was a major problem that financial companies still failed to respond properly despite repeated personal data leaks, and said he would thoroughly examine whether financial firms and supervisors bore responsibility at the upcoming parliamentary audit. Separately, Newsis reported, citing the Financial Supervisory Service, that 28 confirmed attack IP addresses had been shared with financial companies amid a series of intrusions. The security industry said the priority was to block access from those addresses and check past access records, while continuing to monitor threat information because attackers can change addresses, according to Newsis, which reported that fear of what it called AI hacking was spreading in the financial sector. [ 1 , 2 , 3 ]
Почему это важно
The reports show two financial firms failing to detect intrusions for roughly five days, which puts both the companies and their supervisors under scrutiny ahead of a parliamentary audit. Newsis reported that the financial sector is on alert over what it called AI hacking, with the security industry saying shared attack addresses must be blocked and past access logs checked because attackers can change addresses.
Ключевые факты
- Welcome Savings Bank reported to authorities that an intrusion began on Sept. 27 at about 5:09 p.m. [ 1 , 2 ]
- The bank detected the intrusion on Oct. 2 at about 4:04 p.m., about 116 hours 55 minutes after it began, and blocked the related IP at 4:12 p.m. [ 1 , 2 ]
- Maeil Business reported the attack lasted a total of 119 hours 16 minutes, ending Oct. 2 at about 4:25 p.m. [ 1 , 2 ]
- Leaked Welcome Savings Bank data included corporate internet banking IDs, corporate names, representatives' names, work contacts, mobile phone numbers and email addresses. [ 1 , 2 ]
- Welcom Savings Bank estimated that 2,299 of 2,370 leaked data items contained personal information, without removing duplicates, and said it would re-report by data subject. [ 1 , 2 ]
- Hyundai Capital was attacked for about 24 minutes from Sept. 27 at 6:37 a.m. and detected it on Oct. 2 at about 5:08 p.m. [ 1 , 2 ]
- Hyundai Capital reported no actual damage from the incident, while some personal information of 146 housing loan recruiters was leaked. [ 1 , 2 ]
- Newsis reported that the Financial Supervisory Service and the Financial Security Institute shared 28 confirmed attack IP addresses with financial companies. [ 3 ]
Подтверждено несколькими источниками
- Welcome Savings Bank reported a Sept. 27 intrusion and detected it on Oct. 2, about five days later. [ 1 , 2 ]
- Hyundai Capital also detected its Sept. 27 attack on Oct. 2, about five days later. [ 1 , 2 ]
- Rep. Han Chang-min of the Social Democratic Party said it was a major problem that financial firms still failed to respond properly and said he would examine responsibility at the upcoming parliamentary audit. [ 1 , 2 ]
Пока неясно
- The length of the Welcome Savings Bank attack The Yonhap headline says the intrusion lasted nearly 120 minutes, while its article and Maeil Business describe an attack running from Sept. 27 to Oct. 2, with Maeil Business putting the total at 119 hours 16 minutes; the documents do not reconcile this.
- Whether the 146 Hyundai Capital housing loan recruiters whose data leaked count as damage The reports say Hyundai Capital found no actual damage in its investigation into the circumstances and possibility of customer data leakage, while also stating that some personal information of 146 housing loan recruiters was leaked.
- The number of people affected by the Welcome Savings Bank leak The reports say the 2,370 figure is a count that did not remove duplicates and that the company will re-report by data subject.
- The identity of the attackers and whether the 28 shared IP addresses are linked to both companies' incidents No document names a perpetrator, and the Newsis article on the 28 addresses is partially truncated and does not connect them to specific firms.
- The Financial Supervisory Service and the Financial Security Institute shared 28 confirmed attack IP addresses with financial companies, according to Newsis, citing the Financial Supervisory Service. Reported by a single source so far
Что пишут местные СМИ
Хронология, местное время
- Sept. 27: Welcome Savings Bank's reported intrusion begins. [ 1 , 2 ]
- Sept. 27: Hyundai Capital's attack begins. [ 1 , 2 ]
- Sept. 27: Hyundai Capital's attack ends. [ 1 , 2 ]
- Oct. 2: Welcome Savings Bank recognises the intrusion, about 116 hours 55 minutes after it began, after an email from the Financial Security Institute sharing related IP addresses. [ 1 , 2 ]
- Oct. 2: Welcome Savings Bank blocks the IP as an initial response. [ 1 , 2 ]
- Oct. 2: The situation is relayed to the operations manager. [ 1 , 2 ]
- Oct. 2: The attack on Welcome Savings Bank is reported to have ended. [ 1 , 2 ]
- Oct. 2: Hyundai Capital recognises its attack. [ 1 , 2 ]
- Oct. 6: Yonhap publishes its report based on data received by Rep. Han Chang-min's office from the Financial Supervisory Service. [ 1 ]
- Oct. 7: Newsis publishes its report on the shared attack IP addresses. [ 3 ]