Investigators eye common attacker, AI use in string of breaches

Regulators, bank chiefs face grilling at post-holiday national audit

ATM machines from major commercial banks in Seoul. [Herald DB]
ATM machines from major commercial banks in Seoul. [Herald DB]

Financial authorities and the Korea Financial Security Institute are stepping up their investigation into a string of hacking and data-breach incidents at South Korean banks, focusing on the cause, attack methods and whether a single actor was behind the incidents. Because the probe also covers whether each institution met its security obligations, sanctions could follow depending on the findings. The incidents are also expected to dominate the upcoming parliamentary national audit.

Staff at the financial authorities came in Saturday to discuss the circumstances of the recent bank hacking incidents and map out a response. The Korea Financial Security Institute is leading the technical analysis, while the Financial Services Commission and the Financial Supervisory Service are conducting on-site inspections of the affected institutions and reviewing their security frameworks.

The central question in the investigation is who carried out the attacks and how. Authorities are working on the possibility that a single actor or a linked group was responsible, given that similar attack methods were used across multiple banks within a short period. Investigators have also established that some of the IP addresses used in the attack on Shinhan Bank match those used in the attack on KB Kookmin Bank.

"It is highly unusual for multiple banks to experience similar problems at the same time," an FSC official said. "Whether this is the work of the same perpetrator should become clearer as we piece together the current situation." IT experts cautioned that matching IP addresses alone are not sufficient to conclude a single actor was responsible, but said the overlap could indicate a connection between the attacks.

The Financial Services Commission office inside Government Complex Seoul in Jongno-gu, Seoul. [Yonhap]
The Financial Services Commission office inside Government Complex Seoul in Jongno-gu, Seoul. [Yonhap]

Attention is also turning to whether the investigation will result in sanctions. If inspectors find violations of relevant laws or internal control obligations, financial institutions and their executives could face regulatory action. Sanction criteria take into account not only the severity of the violation and the scale of the incident, but also whether it involved intent or gross negligence, and how effectively the institution managed the aftermath and limited losses. Depending on the nature of the leaked data and whether security measures were breached, fines and penalties under the Credit Information Act or the Personal Information Protection Act may also apply. Under the latter, the scale of the leak, compliance with security requirements and efforts to prevent further harm are all factored into any fine calculation.

Political pressure is also building. The FSC is scheduled to face the National Assembly's Political Affairs Committee national audit on Thursday. The bank hacking incidents have emerged as a key issue surrounding the financial authorities' oversight of cybersecurity and their incident-response systems.

Whether bank chiefs will be called to testify in person is another variable. Democratic Party of Korea lawmaker Park Sang-hyeok said he intends to summon the heads of the five major commercial banks as witnesses to establish the cause of the breaches and assign responsibility. There is also speculation that bank chiefs could be added as witnesses at the FSS national audit on Oct. 19 or the combined FSC-FSS audit on Oct. 22.

Meanwhile, about 25,000 customers had their data leaked from Shinhan Bank, and customer data breaches were also confirmed at KB Kookmin Bank and Hana Bank. Personal information belonging to outsourced developers was also taken from BNK Busan Bank. Woori Bank and NH NongHyup Bank faced similar intrusion attempts, but no customer data leaks have been confirmed at either institution so far.


rim@heraldcorp.com
hyuk@heraldcorp.com