South Korean President Lee Jae Myung commanded on Sunday, October 4th, for a comprehensive investigation to be launched into the recent spate of personal information leaks at banks, financial companies, and public institutions, and to develop corresponding measures.
According to Reuters’ report on Sunday, the spokesperson for the South Korean President, Kang Yu-jung, stated that Lee Jae Myung requested relevant departments to fully grasp the severity of the incidents and to make every effort to address them.
On the same day, Lee Eog-weon, the Chairman of the Financial Services Commission (FSC), and Lee Chan-jin, the Director of the Financial Supervisory Service (FSS), convened an emergency meeting with representatives from banks, securities, insurers, credit card companies, savings banks, and financial technology firms. Lee Eog-weon urged the entire finance industry to maintain the highest level of vigilance.
The FSC has mandated financial institutions to conduct comprehensive security checks, strengthen access controls, restrict external system connections, enhance consumer protection, and require the industry to promptly share threat intelligence such as attack methods and IP addresses.
Regulatory authorities have also proposed a strategy of “using artificial intelligence to counter artificial intelligence attacks” and urged businesses to participate in government-led AI security testing.
Reportedly by Korea Times, Shinhan Bank reported on September 30th that data from the institution had been leaked, affecting approximately 25,000 customers. Subsequently, KB Kookmin Bank, Hana Bank, and BNK Busan Bank also reported similar incidents.
Among them, Hana Bank identified information leaks of 89 customers, including customer names, phone numbers, annual incomes, loan amounts, and in some cases, resident registration numbers were also exposed.
Following that, the scope of this information leak incident expanded from large banks to non-bank financial institutions. Yegaram Savings Bank disclosed personal information leaks of around 40,000 customers; Hyundai Capital had some personal data of 146 mortgage brokers exposed.
Welcome Savings Bank confirmed on Sunday, October 4th, that information of corporate clients had leaked, with an estimated 2,200 records stolen, including company names, contact names, email addresses, and phone numbers.
So far, seven financial institutions have confirmed discoveries of information leaks.
Woori Bank and NH Nonghyup Bank were also reported to be targeted but both institutions announced successfully thwarting unauthorized system access, with no customer information leakage.
However, Yonhap News Agency cited sources disclosing that Woori Bank also experienced data leaks, indicating conflicting information.
Additionally, Korea Electric Power Corporation (KEPCO) revealed on Sunday that personal data of around 24,000 employees, including names, titles, and phone numbers, had been leaked and posted on an external website.
KEPCO stated that they are still investigating the cause of the information leak, which appears unrelated to recent AI-related hacker attacks in the finance sector, as customer information was stored in a separate system and not breached.
Regulatory authorities in South Korea stated that the attack traffic originated from IP addresses in the United States, Japan, Singapore, Vietnam, and the United Kingdom. Assessments suggest attackers could be scanning multiple financial company systems for vulnerabilities rather than targeting a specific institution.
Authorities have not yet found sensitive information that could be used for unauthorized payments leaked, and online and mobile banking services remain unaffected, with no confirmed financial losses.
Nevertheless, regulatory agencies warned that leaked information could be used for subsequent crimes like voice phishing scams. South Korean police have launched investigations into the related attacks.
According to South Korean financial industry insiders, the hackers suspected of attacking Shinhan Bank may be located overseas and are believed to have utilized advanced artificial intelligence (AI) tools to extract customer information.
Analysts believe that evidence indicates hackers may have leveraged the open-source automated security testing tool ARTEX in the attacks.
ARTEX, developed by a Chinese company and based on Large Language Models (LLM), is an open-source AI-driven penetration testing system.
Reports suggest traces of a Chinese AI penetration testing tool on a server suspected to have been used in the attack, with the server’s web page title containing the Chinese words “Artificial Intelligence Autonomous Penetration Testing Console”.
Currently, South Korean authorities have not yet disclosed the final investigation findings, with most information coming from analysts and media reports. The FSC simply mentioned that the possibility of attackers using AI cannot be ruled out.
