Gov't issues consumer alert, launches monthlong effort to prevent fraud after data breaches

ATMs belonging to major banks are installed in Seoul, Monday. Yonhap

ATMs belonging to major banks are installed in Seoul, Monday. Yonhap

AI hacking fears spread to brokerages, insurers, card issuers

Financial authorities issued a consumer alert at the “caution” level Tuesday after suspected artificial intelligence (AI)-assisted cyberattacks stole personal information from banks, savings banks and a capital finance company.

They also launched a monthlong special response period to prevent scams involving the stolen data.

The measures follow data breaches reported at seven firms since the beginning of this month — Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. The incidents suggest the attacks, first reported in the banking sector, are having a broader impact.

During the special response period, financial firms must open dedicated support channels for affected customers and immediately report any confirmed or suspected cases of fraud that may follow to regulators.

Firms must also strengthen monitoring through their fraud detection systems. Suspicious information linked to the breaches will be promptly shared through an AI-powered platform for sharing and analyzing voice phishing information for financial institutions, telecom companies and investigative agencies. This will help firms take swift action, including suspending payments to or from suspicious accounts.

Authorities said no financial losses, such as the theft of money from customers’ accounts, have been confirmed. They are nevertheless taking precautions against fraud involving the compromised information.

“Although passwords were not leaked, scammers could piece together personal details from the exposed data to impersonate loan advisers or lure victims with promises of compensation for the data breaches,” an official at the Financial Supervisory Service (FSS) said.

Authorities stressed that consumers should not assume a call or message is legitimate simply because the sender knows their income, borrowing limit or other financial details.

People were advised to check whether their information was stolen through their financial institution’s official website or main telephone number. Those affected should also avoid storing resident registration numbers, account passwords or copies of identification documents on their phones to reduce the risk of further exposure.

Regulators may extend the special response period as needed and will immediately raise the consumer alert level if further harm is confirmed.

Amid growing concerns, brokerages, insurers and credit card issuers are stepping up security measures and checking for potential breaches.

Attempted intrusions detected across several parts of the financial sector have led regulators and industry officials to suspect that the attackers were scanning a broad range of companies for weaknesses rather than pursuing a single target.

Further cases may come to light, they warned, noting that smaller firms have relatively limited security staffing and that the attacks were timed during October’s extended holiday period.

At some brokerages, staff responsible for security reportedly worked through the long holiday weekend to conduct internal reviews.

“We have not identified any data leaks in the brokerage industry so far, but we are staying alert and carrying out further checks,” an official at a Seoul-based securities firm said.

Insurers have also reported no confirmed leaks or system intrusions linked to the attacks but continue to monitor for and block potential threats.

“We work closely with the financial authorities to share threat information, including IP addresses associated with breaches,” an official at a Seoul-based insurance company said.

Card issuers, for their part, are conducting their own inspections, paying particular attention to IT infrastructure and services accessible from outside their networks.

Reviews are focusing on identity verification and access controls following indications that the attackers exploited weaknesses in business support systems and information lookup services used by employees and loan agents.

The digital risk analysis team at the FSS has identified about 30 IP addresses associated with the attacks across multiple countries and territories including the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, Sweden, Germany and Korea.

The attacker may have used IP addresses in different locations to obscure their trail while searching financial companies’ systems for exploitable weaknesses. The location of an IP address alone does not establish the attacker’s nationality or the actual source of an attack, according to authorities.

Regulators have circulated these IP addresses and security guidance to firms across the industry. Companies have been instructed to check externally accessible IT assets and services for vulnerabilities and verify that the addresses have been blocked.

In a written notice, the FSS called on each firm to identify its externally accessible IT infrastructure, assess vulnerabilities and take corrective action. It also urged companies to review authentication, authorization and validation controls in systems that attackers could exploit to gain entry.


Interesting contents

Taboola 후원링크

Recommended Contents For You

Taboola 후원링크