Security

Hack Spreads Across Financial Sector, Prompting Emergency Security Checks

IT DAILY ·

[Photo: Pixabay]

✦ AI Summary

After Shinhan Bank's personal information leak came to light, damage was also confirmed at KB Kookmin Bank, Hana Bank, Busan Bank, Yegaram Savings Bank, Welcome Savings Bank, and Hyundai Capital.

As of the 6th, intrusion incidents had occurred at 7 financial companies, while no actual information leak was reported at Woori Bank or NH NongHyup Bank.

Financial authorities instructed banks, card companies, securities firms, insurers, savings banks, and electronic financial businesses to conduct emergency inspections and shared 19 attack IP addresses with financial companies.

After Shinhan Bank's personal information leak came to light, damage has been confirmed at other banks, savings banks, and capital firms, spreading the fallout from the hacking attack across the financial sector. After damage was confirmed not only at commercial banks but also at savings banks and capital firms, the entire financial industry has been put on alert. As of the 6th, intrusion incidents had occurred at 7 financial companies.

The situation began in earnest on the 1st, when it was confirmed that personal credit information related to loans for about 25,000 customers had been leaked from Shinhan Bank. The institutions in which hacking damage has been confirmed include Shinhan Bank, KB Kookmin Bank, Hana Bank, Busan Bank, Yegaram Savings Bank, Welcome Savings Bank, and Hyundai Capital. No additional damage has been confirmed so far.

As the entire financial sector went on alert, financial authorities instructed banks and card companies to complete emergency inspections by the 6th. The securities industry is also continuing checks for similar damage. Major companies in electronics, automobiles, and aviation have also begun security inspections.

Based on the circumstances, this attack is believed to have occurred simultaneously across the financial sector. Two U.S. IP addresses used in the attack on Shinhan Bank were found to have attempted access to Toss Bank 14 times in January and July-August this year.

Hack attempts targeting Woori Bank and NH NongHyup Bank were also detected around the same time. However, no actual information leak occurred at Woori Bank or NH NongHyup Bank.

On the 6th, the Financial Supervisory Service secured 19 attack IP addresses related to the hacking and shared them with financial companies. By location, the attack IPs were led by 5 in the United States, followed by 2 in Japan, 2 in Sweden, and 2 in Germany, while 1 domestic IP was also identified. The hackers are believed to have infiltrated via IP addresses in multiple countries and attacked multiple systems.

After the incident last week, financial authorities convened an emergency meeting to review the situation and response efforts. The Financial Supervisory Service distributed the attack IPs and security advisories to about 500 companies across the financial sector.

Under the authorities' instructions, banks and card companies must complete emergency inspections by the 6th, while securities firms, insurers, savings banks, and electronic financial businesses must do so by the 8th. The emergency inspections are being conducted based on a 12-item checklist, which includes whether the attack IPs have been blocked, whether damage has been investigated, whether externally exposed IT assets and services have been identified, and whether security has been strengthened. Any shortcomings must be corrected immediately.

As reports of repeated hacking incidents in the financial sector emerged, the Ministry of Science and ICT and the Korea Internet & Security Agency launched cyber threat responses to prevent additional damage. In response, KISA's Internet Intrusion Response Center (KISC) strengthened monitoring in preparation for the possibility of further damage and also reinforced its intrusion incident response staff.

At the same time, major companies outside the financial sector, including electronics, automobiles, and aviation, also began responding. These major companies started blocking the attack IPs and began inspecting externally accessible systems.

In the same vein, the Ministry of Science and ICT sent security inspection recommendation emails on the 4th to about 28,000 companies that had reported a CISO. On the 3rd, KISA's Threat Analysis Team issued a 'recommendation to strengthen corporate security in preparation for cyberattacks' and urged companies and institutions to inspect API vulnerabilities and review their authentication information management practices. The team also identified API vulnerabilities as a factor that could be exploited as an initial intrusion path.

Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=242024

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.