Series of Financial-Sector Personal Information Leaks Prompt Warning Over Bank Impersonation Phishing
IT DAILY ·
✦ Resumen de IA
Personal information leak incidents have been confirmed at Shinhan Bank and KB Kookmin Bank.
Shinhan Bank leaked the names, phone numbers, and loan-related information of more than 25,000 customers, while KB Kookmin Bank leaked the names, phone numbers, addresses, and encrypted resident registration numbers of 119 customers.
The leaked information could be abused for voice phishing, malicious emails, and fraud impersonating bank employees, so caution is needed.
Personal information leak incidents have been occurring one after another in the financial sector. Following Shinhan Bank, an incident has also been confirmed at KB Kookmin Bank. According to a statement from the financial sector on the 2nd, the leaked names, contact information, and loan-related data could be used in voice phishing or malicious email attacks, so caution is needed.
The cause of the Shinhan Bank incident was identified as abnormal external access. The scale of the leak at Shinhan Bank is about 25,000 customers. The leaked items included names, phone numbers, annual income related to loan processing, credit limits calculated for loan processing, and workplace information related to loan processing. It also included 66 resident registration numbers and 97 CI records for some customers.
The scale of the leak at KB Kookmin Bank is 119 customers. KB Kookmin Bank said the affected system was an employee mobile work support system. It also said the system was separate from customer financial transaction systems such as internet and mobile banking.
The leaked items at KB Kookmin Bank differ by customer. The leaked information included customer names, phone numbers, addresses, and encrypted resident registration numbers. The financial sector said caution is needed as these personal information leak incidents have continued to surface.
Information leaks can go beyond simple exposure and raise concerns about additional damage. Leaked personal information can be combined with income and loan information, and such combined data can be exploited for fraud tailored to the victim's situation. Hwang Seong-ho, country manager of NordVPN Korea, raised concerns about the possibility of combining exposed personal and financial information.
Hwang Seong-ho, country manager of NordVPN Korea, explained that if criminals link phone numbers with income information and loan limits, they can plan personalized scams. He also cited cases of phishing attempts impersonating financial company employees. Criminals can use leaked information to learn a customer's financial situation.
Based on this, criminals can carry out scams posing as Shinhan Bank employees. In the process, they can build trust by mentioning loan and income information, and may pressure victims to provide sensitive information such as passwords.
Generative AI can also be used to make phishing more sophisticated. Through generative AI, it is possible to carry out phishing at a level that makes it difficult to tell whether it is fake, and it can also be used to write convincing phishing emails and text messages. In addition, generative AI can be used to create crime scenarios tailored to individual victims.
After a leak incident, impersonation scams using it as a pretext can follow, so caution is needed. Criminals may pose as bank employees in the name of protecting victims' accounts, and they may also pose as bank employees in the name of checking whether data has been leaked. Hwang said criminals create an urgent atmosphere to pressure victims.
To prevent secondary damage from leaked information, it is important to be wary of unexpected contact from banks. NordVPN said that if an unsolicited phone call or email asks for a password, it should not be provided. NordVPN also said that if an unsolicited phone call or email asks for a one-time password (OTP), it should not be provided.
Even if the other party claims to be a bank employee, their identity needs to be verified by contacting the official customer center directly. Links claimed to have been sent by the bank should not be clicked. Instead, it is necessary to use safe channels such as the official app and homepage.
It is necessary to check account transaction history and also to check notifications for access to the bank app. If a transaction is found that was not executed by the account holder, it should be reported to the bank immediately. If a login attempt that was not made by the account holder is found, it should also be reported to the bank immediately.
Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241988
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
Ver originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.