Hacking attacks utilizing artificial intelligence (AI) have spread beyond the five major banks to savings banks, capital companies, and mutual finance institutions across the financial sector. Attackers extensively scanned external systems of multiple financial institutions, penetrating those with relatively weak security.

According to financial authorities on the 4th, approximately 40,000 people’s personal information, including names, birthdates, and contact details, was leaked in a hacking incident at Yegaram Savings Bank on September 30. Hyundai Capital also suffered a data breach on September 27, with information of 146 loan recruiters compromised. Welcome Savings Bank confirmed the leakage of data from around 2,200 corporate clients. The Korean Federation of Community Credit Cooperatives and NH Nonghyup Mutual Finance detected access attempts via internet protocol (IP) addresses identical or similar to those used in prior attacks on banks.

Earlier, from the 1st to the 2nd, hacking attempts were reported at the five major banks—KB Kookmin, Shinhan, Hana, Woori, and NH Nonghyup—as well as BNK Busan Bank. At Shinhan Bank, data of 25,729 customers was leaked, while KB Kookmin and Hana Bank each lost information of 119 and 89 customers, respectively. As AI-driven hacking attacks surged simultaneously, financial authorities urgently convened representatives from the entire financial sector to assess damage and review security responses. A high-ranking official from the financial authorities stated, “Given that some attacks involved the same IP address, we cannot rule out the possibility of a single perpetrator.”

This attack targeted peripheral business systems used by loan recruiters and external sales staff, rather than core financial transaction networks like internet or mobile banking. Professor Lyu Jae-cheol of Chungnam National University noted, “AI can identify vulnerabilities humans might overlook,” adding, “As similar attacks could become more frequent, financial institutions must establish a system to proactively detect and address weaknesses using AI.”

Financial authorities are considering a plan to require immediate reporting of hacking incidents. Currently, institutions have 24 hours after detecting an incident to report it, but concerns persist that delays in internal verification—due to fears of sanctions or reputational damage—could slow initial responses.

Leave a comment

Trending