Move follows data breaches at Shinhan, KB Kookmin and two other banks
South Korea’s financial regulator on Friday ordered banks and credit card companies to conduct security checks following a series of cyberattacks involving Shinhan Bank and KB Kookmin Bank.
The Financial Services Commission said it would promptly collect the results and use them to develop measures to strengthen cybersecurity in the financial sector.
The FSC held an emergency meeting chaired by Secretary General Shin Jin-chang to share information on recent data breaches, including the types and methods of attacks, and discuss how to respond.
Shin called on banks and credit card companies to conduct comprehensive checks of all IT systems accessible from outside their networks.
The move came after relatively less-secure systems, including Shinhan Bank’s service for loan agents and KB Kookmin Bank’s mobile work-support system for employees, were targeted in attacks involving artificial intelligence agents.
Shin also stressed the need for financial companies to conduct thorough checks “so that the public does not feel anxious,” according to officials.
The comments reflected the need to quickly determine what information was leaked and how it was obtained to ease public concerns, officials said.
“People will only feel reassured once it is confirmed that the leaked information was not directly related to their financial transactions,” a financial industry official said. “That is why financial companies were urged to conduct thorough checks.”
The FSC instructed financial companies to identify all IT assets and services exposed to external access and closely examine security vulnerabilities and access controls. The checks should cover all systems accessible from outside, regardless of whether they provide customer-facing services or what type of service they offer.
Companies were also told to minimize the amount of information exposed externally and check for any routes that could allow access to internal information without authentication. They were urged to ensure that authentication procedures are properly applied whenever internal information is accessed.
Information on potential threats, including attackers’ IP addresses, attack methods and attempted intrusions, will be shared promptly with relevant authorities and financial companies to enable a coordinated response.
The financial authorities will provide a cybersecurity checklist to help financial companies conduct their own reviews and will collect the results.
The FSC, Financial Supervisory Service and Financial Security Institute have also launched on-site inspections into the recent cyberattacks. They have shared information such as attackers’ IP addresses and attack methods with the Korea Internet & Security Agency and other relevant authorities.
The authorities will oversee affected financial companies to ensure they take appropriate measures to protect customers and compensate them for any losses.
“We will closely monitor cyberthreats targeting the financial sector and work closely with relevant parties by sharing threat intelligence promptly,” Shin said. “We will thoroughly analyze the causes and methods of the attacks and swiftly develop measures to strengthen the system.”
Shinhan Bank said Thursday that information belonging to about 25,000 customers had been leaked after a code related to its communications infrastructure was hacked. KB Kookmin Bank also found during its own review that information on more than 100 customers had been leaked following an external intrusion.
Hana Bank and BNK Busan Bank were also found to have suffered information leaks Friday, according to financial industry sources.
The Financial Supervisory Service and Financial Security Institute have dispatched personnel to all four banks where data breaches have been reported to conduct on-site inspections.
ch0221@heraldcorp.com
