Policy

Hacking Attacks Spread to BNK Busan Bank After Shinhan, KB Kookmin and Hana, Raising Alarm Over Data Leaks

IT DAILY ·

[Photo: AI-generated image]

✦ AI Summary

Hana Bank confirmed that external hacking forces had made abnormal access to its office support system (ODS) and identified the leak of personal information of 89 customers.

At BNK Busan Bank, a leak of personal information from 11 outsourced development employees was confirmed, and the bank blocked the problematic web page before reporting the matter to the financial authorities.

The Financial Services Commission ordered a comprehensive inspection of externally exposed IT assets and authentication procedures in the process of querying personal information.

Following Shinhan Bank and KB Kookmin Bank, personal information leaks have also been confirmed at Hana Bank and BNK Busan Bank, putting the financial sector on alert over its security response. With hacking and personal data leaks being confirmed one after another at multiple banks, the overall level of vigilance across the financial sector has risen.

Hack attacks also occurred at Woori Bank and NH NongHyup Bank, but no signs have been found that the incidents led to external leaks of customer information or other data. As even banks without confirmed leaks came under attack, and as the possibility that AI was used in the attack process has been raised, the need has emerged to broaden security inspections beyond customer information to include outsourced staff's work support areas involving personal data processing.

On the 2nd, Hana Bank announced that external hacking forces had made abnormal access to its office support system (ODS). Hana Bank said it identified the leak of personal information of 89 customers as a result, and said the leaked items were names, resident registration numbers, addresses, email addresses, phone numbers, mobile phone numbers and company names.

The bank said the system is a separate channel from internet and mobile banking transaction systems. The bank said it had detected the hacking attempt.

The bank reported the matter to the financial authorities. It also individually notified affected customers. After signs of intrusion were detected, it urgently blocked the relevant IP address and inspected similar systems.

Separately, BNK Busan Bank confirmed a leak of personal information from 11 outsourced development employees. The confirmation came around 4:30 a.m. that day. The leaked information included names, phone numbers, dates of birth and email addresses, and the leaked information had been posted on a web page.

At BNK Busan Bank, the possibility of an incident caused by hacking attacks targeting employee mobile sales support systems and other systems was raised. BNK Busan Bank blocked the problematic web page and reported the matter to the financial authorities. It also strengthened monitoring in preparation for similar attacks.

These incidents showed that the financial sector's protection targets are not limited to customer financial transaction information. Customer information stored and queried in work and sales support systems, as well as the personal information of outsourced development staff, are also subject to inspection. Confirming the system's purpose, the information it holds and who is permitted access were also presented as items requiring review.

The security industry is raising the possibility that AI-based automation tools were used in the attacks on the financial sector. This suspicion is based on the fact that strings related to 'ARTEX AI' were found in the title of a web server page linked to the suspected attack targeting Shinhan Bank. Moon Jong-hyun, head of the Genians Security Center, disclosed those signs and raised the possibility that an AI-based attack automation tool was used.

However, whether ARTEX AI was actually used in the Shinhan Bank incident remains unconfirmed by the financial authorities and the bank. Accordingly, the investigation needs to determine whether AI tools were used, along with the actual intrusion path.

Specifically, it is necessary to check whether authentication procedures were bypassed, the scope of customer information that could be queried through the work support service, and whether abnormal access detection and blocking mechanisms worked properly. This should be handled together with examining not only whether the tool was actually used, but also how the attack was carried out.

As a response measure, it is necessary to strengthen authentication at the information retrieval stage, reinforce access-right verification and quickly block repeated abnormal requests in preparation for automated attacks. At the same time, work to determine whether AI tools were used and work to improve information leak routes also need to proceed in parallel.

The Financial Services Commission held an emergency situation response meeting in the afternoon. The meeting was chaired by Secretary General Shin Jin-chang, and the Financial Supervisory Service, the Korea Financial Security Institute, major commercial banks and card companies attended.

The FSC instructed the financial sector to comprehensively identify externally exposed IT assets and services. It also called for inspections of security vulnerabilities and access control status. The inspection targets cover all systems that can be accessed externally, regardless of whether they are for customers or what kind of service they provide.

The FSC also instructed the sector to check whether authentication procedures were omitted or insufficiently applied in the process of querying personal information and internal information. Related agencies and financial companies agreed to quickly share attack IP addresses, methods and details of intrusion attempts.

The FSC plans to receive reports on the results of self-inspections using a vulnerability checklist. Secretary General Shin Jin-chang said that thorough preparedness to prevent incidents such as information leaks is the top priority.

Shin said that when an incident occurs, rapid response is needed to prepare to minimize consumer damage. He added that the financial sector will push ahead with close cooperation, including closely monitoring intrusion attempts and quickly sharing threat information. He also said the causes of intrusion incidents and attack methods will be thoroughly analyzed, and necessary institutional improvements will be prepared quickly.

The two banks presented response policies in the event that customer damage becomes a reality after the incidents. Hana Bank said that if actual damage occurs due to an information leak, it will fully compensate customers in accordance with relevant regulations, while KB Kookmin Bank said that if customer damage occurs from this incident, it will fully compensate customers and plans to review the entire related process from scratch.

Source: IT DAILY · Lee Jae-young
Original: https://www.itdaily.kr/news/articleView.html?idxno=242003

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.