Authorities to audit external-access systems, authentication protocols
Attack IP addresses, methods to be shared across financial sector
Financial regulators launched a sweeping security review of the banking sector Friday after data breaches were confirmed at both Shinhan Bank and KB Kookmin Bank. Authorities said they would examine vulnerabilities in IT systems and services accessible from outside the institutions and quickly share information — including attacker IP addresses and methods — with financial firms across the industry.
The Financial Services Commission convened an emergency response meeting at Government Complex Seoul on Friday, chaired by FSC Secretary General Shin Ji-chang and attended by representatives from the Financial Supervisory Service, the Korea Financial Security Institute, major banks and card companies, and related industry associations.
The meeting was called after cyber attacks caused confirmed damage at KB Kookmin Bank and other major financial institutions, following the Shinhan Bank data breach on Wednesday. Regulators said they would analyze the causes and methods behind the recent attacks to prepare for similar incidents and assess the sector's overall readiness.
The FSC directed financial firms to take stock of all IT assets and services exposed to the internet and review their security vulnerabilities and access controls. Institutions were told to examine every externally accessible system — regardless of whether it serves customers — and check whether any pathways allow access to internal data without authentication. Regulators also ordered firms to identify cases where identity verification steps were skipped or improperly applied during personal data lookups.
Attack intelligence gathered by individual financial firms will be shared across the entire sector. IP addresses used in the attacks, intrusion methods and records of attempted breaches will be distributed to relevant agencies and financial companies to enable a coordinated response to similar attacks. Authorities said they would provide a security vulnerability checklist and collect self-assessment results from financial firms as soon as possible.
The FSC, the Financial Supervisory Service and the Korea Financial Security Institute are currently conducting on-site investigations at financial firms that have filed breach reports. To prevent further damage, threat intelligence — including attacker IP addresses and attack types — will be shared with the Korea Internet & Security Agency and other relevant bodies. Regulators also plan to review consumer protection and compensation measures at affected institutions.
"Above all else, it is critical to be thoroughly prepared so that incidents such as data breaches do not occur in the first place," FSC Secretary General Shin said. "When an incident does occur despite those efforts, we must be fully ready to respond swiftly and minimize harm to consumers." He added that authorities would "closely monitor intrusion attempts against the financial sector, share threat intelligence promptly and cooperate closely, while thoroughly analyzing the causes and methods of breaches to quickly develop any necessary regulatory improvements."
Data breaches have been occurring in rapid succession across the banking sector. A novel hacking attack at Shinhan Bank exposed the personal information of about 25,000 customers, while KB Kookmin Bank confirmed that an external intrusion into its employee mobile work-support system resulted in the leak of roughly 100 customer records.
rim@heraldcorp.com
