Hundreds of thousands of attack attempts daily; core banking systems held firm

Back-office support systems left relatively exposed

Financial authorities vow strict action if lax management confirmed

Fraudulent loans using leaked data seen as unlikely

ATM machines of major commercial banks in Seoul. (Yun Chang-bin/The Korea Herald)
ATM machines of major commercial banks in Seoul. (Yun Chang-bin/The Korea Herald)

A string of hacking attacks on South Korean banks has zeroed in on back-office support systems — such as loan solicitor inquiry services — exposing security vulnerabilities that industry insiders say had been building for years. Banks poured substantial resources into securing customer-facing channels, while the less visible back-end support infrastructure was left comparatively underprotected. Although the leaked data is not expected to translate into direct financial losses for customers, financial regulators say they will separately scrutinize whether the banks managed and secured those systems adequately.

According to financial industry and government sources Saturday, the wave of cyberattacks that began in late September focused on back-office support systems. At Shinhan Bank, personal information on about 25,000 customers was leaked through a simplified inquiry service used by loan solicitors. KB Kookmin Bank and Hana Bank also reported breaches of support systems, with data on 119 and 89 customers respectively compromised. Authorities are investigating whether the attacks were carried out using ARTEX, an AI-based intrusion platform, and say the probe is ongoing.

Within the financial industry, the targeting of back-office systems has drawn a reaction of grim inevitability. Banks have invested heavily in securing their core banking systems — the primary interface with customers — but comparatively little attention and funding went to back-office support areas that are less visible to the outside world.

"It's true that we paid more attention to the services customers use most," a bank official said. "Those back-office areas were also considered relatively lower priority."

Aside from the use of AI tools, the attacks are not believed to differ significantly from conventional hacking attempts seen in the past.

Hacking attacks targeting banks typically follow a sequence of system scanning, spoofing and brute-force credential stuffing. Attackers first scan the bank's systems to identify weak points, then spoof IP addresses to penetrate internal networks, before extracting data by cycling through random values. In the latest attacks, AI tools are believed to have automated this process — enabling tens of thousands of values to be tested at once, far more efficiently than a human operator could manage.

"Hundreds of thousands of attack attempts following this pattern occur every single day," a financial industry official said. "The core banking systems that customers use directly have a relatively high level of security and blocked the intrusions, but areas that did not meet that standard appear to have been breached."

The data leaked in the attacks includes customer names, phone numbers, annual income figures, loan limits and resident registration numbers. Financial authorities and the banks believe the leaked information alone is unlikely to enable fraudulent loans, as core financial data — including credit information and passwords — was not compromised.

"Loan screening procedures have become much stricter in recent years, so it is impossible to take out a loan using just a name, mobile phone number and resident registration number," a bank official said. "The likelihood of fraudulent loans through card loans or unsecured credit, or unauthorized withdrawals, is low."

However, regulators say they intend to take a hard look at the disparities in security standards across banks. "Whether financial damage occurred and whether the back-office support systems were managed carelessly are separate issues," an authority official said. "If the investigation confirms shortcomings, we will take corresponding action."

The incident is also expected to put banks' information security budgets under the microscope. Data submitted to People Power Party lawmaker Kim Jae-seop by the Financial Supervisory Service showed that information security spending accounted for only about 10 percent of the five major banks' total budgets from 2022 through last year.


hyuk@heraldcorp.com
rim@heraldcorp.com