Multiple IPs used to hide origin of recent cyberattacks against financial firms
Summary
South Korean financial institutions faced back-to-back customer-information leaks in recent hacking attacks. The Financial Supervisory Service identified 28 IP addresses linked to the attacks, but police believe many were used to conceal the hackers’ locations. Investigators are tracing the attack path through international cooperation, while the National Police Agency formed a 28-member investigative team.
Key Facts
- Hana Bank, KB Kookmin Bank and Shinhan Bank were among the financial companies that suffered customer-information leaks.
- The Financial Supervisory Service shared the 28 IP addresses and associated country information with financial companies.
- Authorities warned that the attackers may have used indirect connections to disguise the origin of the attacks.

A person walks by ATMs in Seoul following a recent series of hacking attacks against some South Korean banks, Wednesday. Yonhap
A considerable number of internet protocol (IP) addresses were found to have been used to mask those responsible for recent cyberattacks against South Korean financial institutions, sources said Wednesday.
Several financial companies, including Hana Bank, KB Kookmin Bank and Shinhan Bank, suffered back-to-back leaks of customer information in recent hacking attacks, prompting a major police investigation.
While the Financial Supervisory Service identified 28 IP addresses in connection with the attacks, police have determined a significant number of them were used to hide the hackers' whereabouts, according to the sources.
Investigators are said to be tracing the attack path through international cooperation.
The financial watchdog earlier shared the IP addresses with financial companies, along with country information, while noting the possibility of the attackers using indirect connections.
In response to the cyberattacks, the National Police Agency formed a 28-member team to investigate the case.
Explore More
- Q.
- Q.
- Q.