Regulators order emergency security checks after breaches at seven financial firms, investigate possible AI involvement

Automated teller machines of major banks are seen in central Seoul, Sunday. (Yonhap)
Automated teller machines of major banks are seen in central Seoul, Sunday. (Yonhap)

A wave of cyberattacks has exposed personal data at seven South Korean financial firms, prompting emergency security measures as regulators investigate whether a single attacker used artificial intelligence to breach their defenses.

Shinhan Bank and Yegaram Savings Bank reported the largest breaches, affecting about 25,000 and 40,000 people, respectively. Authorities found the same attacker’s internet protocol address across all seven affected firms, raising suspicions of a coordinated campaign.

The Financial Services Commission convened an emergency meeting with financial industry leaders Sunday and ordered firms to block external access to systems unless essential for business operations.

“We cannot rule out the possibility of attacks using AI,” FSC Chair Lee Eok-won said, urging the sector to maintain the highest level of vigilance.

Lee said there were no signs that information directly usable for payments or other crimes had been leaked, but warned that the exposed data could facilitate voice phishing and fraudulent text messages.

The breaches first came to light Wednesday at Shinhan Bank, where leaked loan application data included names, phone numbers, annual income and calculated borrowing limits.

KB Kookmin Bank suffered similar breaches affecting 153 individuals, while Hana Bank reported 89 cases.

Woori Bank and NH NongHyup Bank detected attempted intrusions but successfully blocked them, with no data breaches reported.

Regional banks and nonbank financial institutions were also affected, including BNK Busan Bank, where 11 outsourced workers were impacted, Yegaram Savings Bank, which reported 40,000 cases, Welcome Savings Bank, with 2,200 cases, and Hyundai Capital, where 146 individuals were affected.

With the same attacker's IP address found across all seven affected financial companies, authorities suspect that a single attacker used an AI-powered tool to launch simultaneous intrusion attempts.

Other traces indicate Artex, a Chinese-developed AI-based penetration-testing platform, was used. The tool is designed to identify security vulnerabilities and select its next intrusion method based on the results of previous attacks.

To circumvent banks' tightly secured core systems, the hacker instead targeted less-protected noncore systems, such as sales support platforms.

Financial regulators plan to overhaul the sector's security framework in response to the incident, seeking to strengthen defenses against evolving cyber threats.

Authorities have ordered financial institutions to block external access unless it is essential for business operations.

President Lee Jae Myung on Sunday called for a thorough investigation into a series of hacking attacks.

"Lee instructed authorities to take the matter seriously, conduct a thorough investigation and spare no effort in coming up with measures to address the issue," presidential spokesperson Kang Yu-jung said in a press release.

Damage varies by cybersecurity spending

The string of security breaches has raised questions over whether commercial banks, which are reporting record profits, are spending enough on cybersecurity.

While Shinhan Bank suffered the most significant breach among the top four commercial banks in the recent cyberattacks, its relatively low level of cybersecurity spending has come under scrutiny.

Shinhan Bank's information security budget stood at 40.59 billion won ($30.2 million) this year, the lowest among the top four commercial banks here. KB Kookmin Bank had the largest budget at 86.07 billion won, followed by Hana Bank at 63.63 billion won and Woori Bank at 61.56 billion won.

Last year, Shinhan ranked second-lowest among the four top commercial banks in information security spending, with 36.9 billion won, ahead of only Woori Bank's 36.4 billion won. Given the difference in scale between the banks, however, Shinhan's spending could be considered relatively lower.

Regulators, however, say differences in the damage cannot be explained simply by how much each bank spends on cybersecurity. Instead, they are focusing on how effectively each bank’s overall security framework addressed vulnerabilities in individual business systems.

"We need to check the entire security framework to ensure there are no gaps," FSC Chair Lee said, pointing to externally exposed IT assets and services, authentication and access controls, and intrusion detection systems.

The Financial Supervisory Service has ordered financial companies to complete an emergency security inspection by Thursday.


silverstar@heraldcorp.com