US-based IPs most numerous at 5; one domestic IP also identified
Regulator shares list with entire financial sector, orders blocks and breach checks
South Korea's financial regulator has shared a list of 19 internet protocol addresses suspected of being used in recent cyberattacks targeting the financial sector, distributing the information across the entire industry, sources said. The IP addresses were traced to 12 countries, including the United States, Japan and nations across Europe and Southeast Asia. The regulator instructed financial firms to block the addresses and check for any signs of intrusion.
According to financial authorities and industry sources Tuesday, the Financial Supervisory Service identified 19 attacker IP addresses believed to have been used in recent hacking incidents at banks.
The addresses were located across multiple countries, including the US, Japan, Hong Kong, Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, Sweden and Germany. US-based addresses were the most numerous at five, while Japan, Sweden and Germany each accounted for two. One domestic IP address was also included on the list.
The FSS believes the attacker routed traffic through multiple countries to make tracing more difficult. Investigators suspect the attacker gained unauthorized access to financial firms' systems, probed for vulnerabilities across various services and then concentrated efforts on the weakest points.
The FSS narrowed the range of attacker IP addresses based on records of abnormal access and customer data leak pathways identified at Shinhan Bank and certain other financial firms. It subsequently shared the list with the broader financial sector and asked institutions to complete their own internal reviews and address any deficiencies by Thursday.
In an official notice, the FSS directed firms to conduct a comprehensive inventory of all externally accessible IT assets and services, and to check for vulnerabilities in the authentication, authorization and validation functions of external-facing systems. A 12-item checklist distributed alongside the notice covered whether the attacker IPs had been blocked, whether any intrusion attempts or damage had occurred, and whether real-time security monitoring systems were in operation.
Financial firms have also been widening their own investigations, reviewing historical access logs. In the case of Toss Bank, sources said abnormal access through some of the IP addresses shared by the regulator was found to have occurred not only in July and August this year but also in January.
Meanwhile, the Financial Services Commission postponed an announcement — originally scheduled for Wednesday — on the selection of candidates for the second round of emergency relaxations to network separation regulations. The commission said it is focused on managing the fallout from a string of hacking incidents that have spread from the banking sector to the broader financial industry, working alongside the FSS and other relevant agencies. It also determined that the related agenda items require additional review from a security standpoint.
rim@heraldcorp.com
