Local Chorus
Local news from local sources, read in your language.
Developing

Korea financial regulator orders full security review after bank data leaks

🇰🇷 South Korea, Seoul 06:46 IT & software Business11 Tech2 Official updated 2 h ago first reported by 국민일보

Version 2: New coverage identifies the AI agent suspected in the attacks as ARTEX, with a tech outlet detailing 359 related IP addresses observed worldwide, while officials still have not confirmed that the tool was used.

In short

Financial Services Commission Chairman Lee Eok-won chaired an emergency meeting of the entire financial sector in Seoul on Oct. 4 after customer data leaks spread from major banks to non-bank lenders, saying the possibility of AI-enabled hacking cannot be ruled out and ordering a full security review. He said no sensitive information usable for fraudulent payments has been confirmed leaked, but warned of secondary damage such as voice phishing, and said firms would face strict accountability if similar incidents recur. Two outlets reported that Oasis Security found 359 IP addresses linked to the AI penetration-testing tool ARTEX, while saying it is not confirmed that the tool was used.

Read the full story 3 min read

Lee Eok-won, chairman of South Korea’s Financial Services Commission, chaired an emergency meeting of the entire financial sector with the Financial Supervisory Service at the Government Seoul Complex in Seoul on Oct. 4, the commission said, after hacking and customer data leaks spread from major commercial banks to non-bank lenders. Lee said the possibility of hacking attacks using artificial intelligence cannot be ruled out, and that the whole financial sector should recognize the situation as grave and hold the highest level of alertness. Korea Economic Daily, Yonhap and other outlets carried his remarks in rolling bulletins through the afternoon. [ 1 , 2 , 3 , 4 , 5 , 6 , 10 , 12 , 14 , 15 , 17 , 18 , 20 , 21 ]

According to Lee, the attacks used relatively lightly managed areas: external web pages and servers that loan recruiters, employees and contractors use for work convenience. He said that however solid a security system is, one unmanaged gap can become a weakness for the whole system, and that some pointed to weak basic measures such as authentication or to information being stored beyond business needs. He asked for checks covering external contact points and access routes used by employees, loan recruiters and outsourcing companies as well as customer-facing services. [ 14 , 16 , 18 , 20 , 21 ]

Maeil Business and CBS NoCut News reported that confirmed leaks involve Shinhan Bank, KB Kookmin Bank, Hana Bank and BNK Busan Bank, and extended to Hyundai Capital, Yegaram Savings Bank and Welcome Savings Bank among non-bank lenders. Newsis reported that about 25,000 Shinhan Bank customers’ personal data leaked through external access that bypassed identity verification of a loan recruiter-only service. Lee said no sensitive information that could be used directly for fraudulent payments has been confirmed as leaked, but that secondary damage such as voice phishing and smishing cannot be ruled out, and asked for stronger detection of abnormal transactions, victim relief and timely consumer guidance. [ 11 , 14 , 18 , 19 , 20 ]

Lee ordered financial companies to inspect externally exposed IT assets and services, authentication and access controls and intrusion detection systems without gaps, and said external access not essential to business should in principle be blocked entirely. He said firms would face strict accountability under relevant laws if similar incidents occur after threat information and cases had already been shared, and called for building a system of defending against AI attacks with AI, referring to tasks that include easing network separation rules. [ 8 , 10 , 13 , 17 , 18 , 21 ]

Separately, Newsis and ZDNet Korea reported that Oasis Security, using its threat-intelligence platform, identified 359 unique IP addresses linked to ARTEX, an open-source AI penetration-testing tool, across 14 countries between Sept. 23 and Oct. 3, and that Chinese-language ARTEX wording was found in a web page title of a server suspected in the Shinhan Bank attack. Both reported that the traces alone do not establish that ARTEX was used and that no official investigation has confirmed it. Korea Economic Daily later reported in a headline that the AI agent abused in the hacking was ARTEX. [ 19 , 22 , 23 ]

Newsis reported the meeting was attended by FSS Governor Lee Chan-jin, FSC secretary-general Shin Jin-chang, Financial Security Institute head Park Sang-won, the heads of financial industry associations and executives of the affected companies; Electronic Times reported the Financial Security Institute, industry associations and seven major financial companies took part. The commission said it had distributed security checklists across the sector and asked for self-inspections and reports, and Maeil Business reported the emergency meeting was brought forward from a plan to receive inspection results on Oct. 7 after incidents spread to non-bank lenders over the weekend. [ 10 , 14 , 21 ]

Why it matters

The FSC has put the whole financial sector under a security inspection regime and warned of legal accountability for repeat incidents, raising pressure on banks and non-bank lenders to close external-access gaps. Confirmed leaks expose customers to voice phishing and smishing risks, and the chairman’s references to AI-based attacks and to easing network separation rules point to possible changes in how financial firms run their security systems.

Key facts

  • FSC Chairman Lee Eok-won chaired an emergency meeting of the entire financial sector with the Financial Supervisory Service at the Government Seoul Complex on Oct. 4 over hacking and customer data leaks. [ 10 , 14 , 18 , 21 ]
  • Lee said the possibility of hacking attacks using artificial intelligence cannot be ruled out. [ 1 , 2 , 7 , 12 , 15 , 18 ]
  • Lee said no sensitive information that could be used directly for fraudulent payments has been confirmed as leaked, but that secondary damage such as voice phishing and smishing cannot be ruled out. [ 14 , 18 , 20 ]
  • Confirmed leaks involve Shinhan Bank, KB Kookmin Bank, Hana Bank and BNK Busan Bank, and extended to Hyundai Capital, Yegaram Savings Bank and Welcome Savings Bank among non-bank lenders. [ 14 , 20 ]
  • Lee ordered financial companies to block external access not essential to business in principle and to inspect externally exposed IT assets, authentication and access controls and intrusion detection systems. [ 8 , 10 , 13 , 17 , 18 , 21 ]
  • Lee warned that firms would face strict accountability under relevant laws if similar incidents occur after attack information and cases had already been shared. [ 2 , 4 , 10 , 14 , 17 , 21 ]
  • Newsis and ZDNet Korea reported that Oasis Security identified 359 unique IP addresses linked to the AI penetration-testing tool ARTEX across 14 countries between Sept. 23 and Oct. 3, while saying the traces alone do not establish that the tool was used. [ 19 , 22 ]
  • Newsis reported that about 25,000 Shinhan Bank customers’ personal data leaked through external access that bypassed identity verification of a loan recruiter-only service. [ 19 ]

Confirmed by several sources

  • Lee Eok-won, chairman of the Financial Services Commission, chaired an emergency meeting of the entire financial sector with the Financial Supervisory Service at the Government Seoul Complex on Oct. 4. [ 10 , 14 , 18 , 21 ]
  • Lee said the possibility of hacking attacks using artificial intelligence cannot be ruled out. [ 1 , 2 , 7 , 12 , 15 , 18 ]
  • Lee said no sensitive information usable for fraudulent payments has been confirmed as leaked so far, while secondary damage such as voice phishing and smishing remains possible. [ 14 , 18 , 20 ]
  • Lee warned of strict legal accountability for firms if similar incidents occur after shared threat information. [ 2 , 4 , 10 , 14 , 17 , 21 ]
  • The leaks confirmed so far involve Shinhan, KB Kookmin, Hana and BNK Busan banks, plus Hyundai Capital, Yegaram Savings Bank and Welcome Savings Bank. [ 14 , 20 ]
  • Oasis Security reported 359 unique IP addresses linked to the AI penetration-testing tool ARTEX across 14 countries, according to Newsis and ZDNet Korea. [ 19 , 22 ]

Still unclear

  • Whether the AI penetration-testing tool ARTEX was actually used in the attacks. Newsis and ZDNet Korea both reported that traces alone do not establish use and that no official investigation has confirmed it.
  • Whether AI was used in the attacks at all. Lee only said the possibility cannot be ruled out; no document states that AI use has been confirmed.
  • The full scope of leaked data and the total number of affected customers across the sector. Only a single-source figure for Shinhan Bank is given, with no sector-wide totals in the documents.
  • Who carried out the attacks. No document identifies the attackers, and Newsis noted that server IP locations do not indicate an attacker’s nationality or location.
  • Whether network separation rules will be eased for AI-based security. Only Hankook Ilbo mentioned Lee referring to easing network separation regulations and to identifying institutional improvement tasks.

What local media are saying

Business mediaBusiness outlets ran rolling breaking-news bulletins quoting the FSC chairman’s lines, then added detail on the affected banks and non-bank lenders, the external-access route used in the attacks, consumer-protection measures, the accountability warning and the ARTEX tool analysis, emphasising the spread of leaks beyond the major banks. [ 1 , 2 , 4 , 5 , 6 , 8 , 9 , 11 , 12 , 13 , 14 , 16 , 17 , 18 , 19 , 20 , 21 , 23 ]
Official sourcesYonhap’s bulletins relayed the chairman’s key remarks in short form: the need for top-level alertness across the financial sector, the unconfirmed AI-hacking possibility and the statement that a sensitive-information leak had not been confirmed. [ 3 , 7 , 15 ]
Technology mediaTech outlets focused on the FSC convening the whole financial sector, the composition of the meeting and the plan to block non-essential external access, and on the ARTEX AI penetration-testing tool, including observations of related infrastructure while noting that official confirmation of its use is absent. [ 10 , 22 ]

Timeline, local time

  1. Kukmin Ilbo reports Lee Eok-won’s remarks on a financial-sector information leak and the possibility of AI-enabled hacking attacks. [ 1 ]
  2. Korea Economic Daily reports Lee saying the possibility of AI-enabled hacking cannot be ruled out and calling for the financial sector’s security system to be checked for gaps. [ 2 ]
  3. Yonhap and Korea Economic Daily report Lee calling for the highest level of alertness across the financial sector and strict accountability if similar incidents occur. [ 3 , 4 ]
  4. Yonhap reports Lee saying the AI-hacking possibility exists while a sensitive-information leak is unconfirmed. [ 7 ]
  5. Newsis reports the financial authorities entered an emergency response posture and that Lee stressed defending against AI attacks with AI. [ 8 ]
  6. Electronic Times reports the FSC and FSS held an emergency meeting of the entire financial sector at the Government Seoul Complex, chaired by Lee. [ 10 ]
  7. Maeil Business reports the list of financial companies with confirmed information leaks and that the meeting was brought forward from a plan to receive inspection results on Oct. 7. [ 14 ]
  8. Hankook Ilbo reports Lee ordering the sector to re-inspect its information security system from scratch and to defend against AI attacks with AI. [ 18 ]
  9. Newsis reports Oasis Security findings on ARTEX-related IP addresses and the Shinhan Bank leak of about 25,000 customers’ data. [ 19 ]
  10. Newsis publishes a comprehensive report on the emergency meeting, including its attendees and the distribution of security checklists. [ 21 ]
  11. ZDNet Korea reports ARTEX-related infrastructure observations, including 359 unique IP addresses. [ 22 ]
  12. Korea Economic Daily reports that the AI agent abused in the hacking was ARTEX. [ 23 ]