Korea intensifies efforts to track hackers behind bank cyberattacks

Financial Services Commission Chairman Lee Eog-weon speaks during a parliamentary audit  at the National Assembly in Seoul, Thursday. Yonhap

Financial Services Commission Chairman Lee Eog-weon speaks during a parliamentary audit at the National Assembly in Seoul, Thursday. Yonhap

China-based suspect possibly linked to recent hackings on Korean banks

Authorities are stepping up efforts to identify the hackers behind an unprecedented series of artificial intelligence (AI)-assisted cyberattacks targeting Korea's major financial institutions, Thursday, as a global cybersecurity firm pointed to a possible suspect based in China.

CrowdStrike said in a report released the previous day that the threat actor was likely a Chinese speaker and financially motivated.

The firm assessed that the attacker may have been a Chinese-speaking individual, citing the use of ARTEX, a Chinese-developed autonomous penetration-testing tool and Chinese-language prompts observed during the attacks.

In its report, CrowdStrike suggested that the attacker primarily used DeepSeek's V4.1-Flash as the large language model backend for ARTEX, while also using GLM-5.3 from Chinese AI company Zhipu AI and Grok 4.6 in separate Claude Code sessions.

A key clue emerged from a Claude Code session in which the attacker asked the AI tool to draft a resume for a security researcher. The information entered into the session included an age of 26, an educational background at South China University of Technology and a location in Maoming, Guangdong Province, according to the report.

However, it remains unclear whether the information is genuine.

The individual had initially entered a September 2007 birth date, which would make the person 19 this year, before later listing the age as 26.

Yet these findings may provide early clues about the possible identity of the person behind the attacks as Korean law enforcement authorities accelerate their probe.

Police said they are investigating multiple possibilities, including whether the attacks were carried out by an individual or an organized group. They cautioned that an IP address alone cannot establish an attacker's whereabouts, as IP addresses can be routed through other locations.

Of the 28 IP addresses identified in connection with the attacks so far, most were found to have been used to conceal the attacker's actual traces, according to police.

A person walks past ATMs belonging to major banks in Seoul, Wednesday. Yonhap

The probe centers on a series of cyberattacks carried out last week that affected at least five lenders, including Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank and BNK Busan Bank.

Shinhan Bank reported that about 25,000 customers were affected, with names, phone numbers, annual income and loan limits exposed. KB Kookmin reported 119 affected customers, while Hana Bank said personal information belonging to 89 customers was exposed.

The attacks have also prompted calls for an overhaul of cybersecurity defenses across the financial sector.

Financial Services Commission Chairman Lee Eog-won acknowledged that the government's early response to AI-assisted cyberattacks had been inadequate.

"Even in some very basic areas, our response has been inadequate. We need to thoroughly review these issues and make changes," Lee said during a parliamentary audit on Thursday.

"To prevent attacks using AI, we ultimately have no choice but to use AI in defending them," he said, adding that the government is considering easing network separation rules to allow financial institutions to use AI more actively for cybersecurity.

Financial authorities have been discussing easing network separation rules for cybersecurity purposes since June, with the aim of allowing financial institutions to use external AI and security services to identify vulnerabilities more quickly.

The latest attacks have also prompted broader scrutiny of cybersecurity practices in the banking sector.

Earlier in the day, the National Assembly's Policy Affairs Committee approved a plan to summon the heads of the country's five major commercial banks — KB Kookmin, Shinhan, Hana, Woori and NH NongHyup — as witnesses for the Financial Supervisory Service parliamentary audit on Oct. 19.

Park Sang-hyuk, a ruling Democratic Party of Korea lawmaker and the committee's secretary, said the bank CEOs would be questioned about their responsibility for cybersecurity lapses.

"We will seek specific commitments from financial institutions to increase security investments and address vulnerabilities so that they view security not as a cost, but as an investment in providing better financial services," Park said.

Interesting contents

Taboola 후원링크

Recommended Contents For You

Taboola 후원링크