Regulator identifies 19 attacker IPs in 12 countries in Korean bank hacking case
Version 2: New reporting adds the reported number of customers whose data leaked — about 25,000 at Shinhan Bank, 119 at KB Kookmin Bank and 89 at Hana Bank — and says savings banks and capital firms have also been hit, beyond the previously reported identification of 19 attacker IPs in 12 countries.
In short
South Korea's Financial Supervisory Service has identified 19 IP addresses suspected of being used in hacking attacks on financial companies, spread across 12 countries including the United States, Japan and Hong Kong (China). The regulator shared the list with the whole financial sector, along with a 12-item checklist, and asked firms to finish self-inspection and fix shortcomings by October 8. Newsis reported that client data was leaked at Shinhan Bank (about 25,000 customers), KB Kookmin Bank (119) and Hana Bank (89).
Read the full story 2 min read
South Korea's Financial Supervisory Service has identified 19 IP addresses suspected of being used in hacking attacks on financial companies, according to Yonhap and Asia Economy, which cited financial authorities and industry officials. The addresses are spread across 12 countries — the United States, Japan, Hong Kong (China), Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, Sweden and Germany — along with one domestic Korean IP. Yonhap reported that US-based addresses were the most numerous at five, with Japan, Sweden and Germany at two each. [ 2 , 4 , 5 ]
The list was compiled by the regulator's Digital Risk Analysis Team, Yonhap and Chosun Ilbo reported. Yonhap said the regulator narrowed the range using IPs that accessed Shinhan Bank and some other banks through abnormal routes and took customer personal information, with the attackers described as routing through addresses in multiple countries to search services, find vulnerabilities and then concentrate their attack. [ 2 , 4 , 5 ]
The Financial Supervisory Service distributed the list to the whole financial sector and asked firms to complete self-inspection and fix shortcomings by October 8, along with a 12-item checklist, Yonhap and Asia Economy reported. Yonhap quoted the regulator's notice asking firms to “closely identify externally exposed IT assets and services and inspect and address vulnerabilities” and to check authentication, authorization and verification functions on external systems that could be abused as intrusion paths. The checklist asked whether the shared attacker IPs had been blocked, whether there had been intrusion attempts or damage tied to them, and whether real-time security monitoring was in operation. [ 2 , 5 ]
Financial companies have widened the period and scope of their own checks, Yonhap and Asia Economy reported. Yonhap said Toss Bank found abnormal access attempts through some of the identified IPs not only in July and August but also in January. [ 2 , 5 ]
Some security industry officials suspect a China-origin attack because traces of a Chinese-language AI penetration testing tool made public in July were found, Yonhap and Asia Economy reported, while the authorities have shared only the nationalities of the IPs and have not specified a suspected country. Yonhap quoted a financial-sector official saying it will take considerable time for investigations by the financial authorities and the Financial Security Institute and the police probe to produce results, and that it is difficult to conclude hastily before then which country's hackers are responsible. [ 2 , 5 ]
On the scale of data exposure, Newsis reported that about 25,000 Shinhan Bank customers' personal and credit information leaked, 119 KB Kookmin Bank customers' personal credit information leaked in an external security breach, and 89 Hana Bank customers' personal information leaked when an external hacking group accessed the bank's operations support system. Newsis also reported that hacking cases have continued beyond commercial banks to savings banks and capital companies in the second-tier financial sector. These figures come from a single outlet and have not been confirmed by the regulator in the documents. [ 6 ]
Why it matters
The addresses point to infrastructure in a dozen countries, which Yonhap and Asia Economy present as an attempt to obscure the attacker's origin and complicate attribution. The regulator's October 8 deadline puts the whole financial sector on a short remediation timetable, with a checklist covering exposed systems and real-time monitoring. The documents give no regulator-confirmed total for customers or systems affected, so the scale of the breach remains unknown.
Key facts
- The Financial Supervisory Service's Digital Risk Analysis Team identified 19 suspected attacker IP addresses in the financial-sector hacking case. [ 1 , 2 , 3 , 4 , 5 ]
- The addresses were spread across 12 countries, including the United States, Japan, Hong Kong (China), Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, Sweden and Germany, plus one domestic Korean IP. [ 2 , 4 , 5 ]
- US-based IPs were the most numerous at five, while Japan, Sweden and Germany had two each, according to Yonhap. [ 2 , 5 ]
- The regulator distributed the list to the whole financial sector, asked firms to complete self-inspection and remedies by October 8, and issued a 12-item checklist covering IP blocking, signs of intrusion and real-time monitoring. [ 2 , 5 ]
- Toss Bank found abnormal access attempts through some of the identified IPs not only in July and August but also in January, Yonhap and Asia Economy reported. [ 2 , 5 ]
- Newsis reported that about 25,000 Shinhan Bank customers' personal and credit information leaked, 119 KB Kookmin Bank customers' personal credit information leaked, and 89 Hana Bank customers' personal information leaked after an external hacking group accessed its operations support system. [ 6 ]
- Some security industry officials suspect a China-origin attack because traces of a Chinese-language AI penetration testing tool made public in July were found, but the authorities have not named a country. [ 2 , 5 ]
Confirmed by several sources
- The Financial Supervisory Service identified 19 suspected attacker IP addresses in the hacking of financial companies. [ 1 , 2 , 3 , 4 , 5 ]
- The addresses were spread across 12 countries, including the United States, Japan, Hong Kong (China), Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, Sweden and Germany, with one domestic Korean IP. [ 2 , 4 , 5 ]
- The Financial Supervisory Service's Digital Risk Analysis Team produced the list of attacker addresses. [ 2 , 4 ]
- US-based IPs were the most numerous at five; Japan, Sweden and Germany had two each. [ 2 , 5 ]
- The regulator narrowed the range using IPs that accessed Shinhan Bank and some other banks through abnormal routes and took customer personal information. [ 2 , 5 ]
- The Financial Supervisory Service distributed the list to the whole financial sector and asked firms to complete self-inspection and remedy shortcomings by October 8, along with a 12-item checklist. [ 2 , 5 ]
- Toss Bank found abnormal access attempts through some of the identified IPs in both January and July-August. [ 2 , 5 ]
Still unclear
- Who or which country is behind the attack Yonhap and Asia Economy reported that some security industry officials suspect a China-origin attack, but the authorities shared only the IP nationalities and did not name a country, and a financial-sector official said it is too early to conclude.
- Whether AI agents were actually used in the attack The documents describe the attack as presumed or suspected to have used AI agents, without confirmation.
- The total number of customers or systems affected The customer figures reported by Newsis are single-source and have not been confirmed by the regulator; the documents give no overall total.
- Whether Toss Bank's January abnormal access attempts belong to the same campaign Only Yonhap and Asia Economy mention the January attempts, and the documents do not link them definitively to the wider case.
What local media are saying
Timeline, local time
- Kukmin Ilbo reports that the Financial Supervisory Service identified 19 suspected AI-hacking IPs across 12 countries. [ 1 ]
- Yonhap publishes the detailed account of the 19 attacker IPs, the 12 countries, the checklist and the October 8 self-inspection deadline. [ 2 ]
- Korea Economic Daily carries the report under a headline citing 12 countries and 19 identified attacker addresses. [ 3 ]
- Chosun Ilbo reports that the addresses are scattered across 12 countries, including the United States, Japan and Hong Kong, citing the regulator's Digital Risk Analysis Team. [ 4 ]
- Asia Economy reports the 19 IPs across 12 countries and notes that some in the financial sector suspect a China-origin attack. [ 5 ]
- Newsis reports continuing hacking cases across the financial sector and gives reported customer leak figures for Shinhan, KB Kookmin and Hana banks, alongside a photo dated October 4. [ 6 ]