Shinhan Hack IPs Also Targeted Toss Bank 14 Times; Breach Spreads to South Korea’s KEPCO, Universities — BigGo Finance | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Some of the attacker IP addresses used in the Shinhan Bank hack also attempted to access Toss Bank servers a total of 14 times since early this year, it has been revealed. The fallout from AI-based attacks targeting South Korea’s financial sector appears to have spread beyond banks, savings banks, and capital firms to internet-only banks.

According to data obtained from Toss Bank by Rep. Kim Hyung-yeon of the Rebuilding Korea Party, who sits on the National Assembly’s Political Affairs Committee, two US-based IP addresses used in the Shinhan Bank attack attempted to access Toss Bank servers 14 times—three times in January and 11 times between July and August. Toss Bank blocked the access, so no actual damage such as customer information leaks occurred.

Previously, hacking damage was confirmed at seven financial firms: Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank, and Hyundai Capital. The number of customers whose data was leaked totaled approximately 40,000 at Yegaram Savings Bank, over 25,000 at Shinhan Bank, 119 at KB Kookmin Bank, 89 at Hana Bank, and 11 at BNK Busan Bank.

Financial authorities believe the same attacker’s IP addresses were found across multiple incidents. The assessment is that the attacker rotated IP addresses while continuing the assault, using AI tools to launch large-scale automated attacks against multiple financial firms. However, the mere fact that the same IP addresses were used does not conclusively prove that the series of attacks was the work of the same individual or organization, so further investigation is needed.

Spreading Beyond Finance to Energy and Universities

Security concerns are rapidly spreading beyond the financial sector. Korea Electric Power Corporation (KEPCO) announced on the 4th that it became aware at around 3:59 p.m. on the 1st that the names, affiliations, and phone numbers of approximately 24,000 employees had been exposed on an external webpage. KEPCO immediately blocked access to the relevant internal systems and requested the webpage operator to delete the information, which was removed by midnight on the 2nd. Approximately 32 hours elapsed between detection and deletion.

According to KEPCO, unique identification numbers such as resident registration numbers, sensitive information, and customer data were not exposed. The webpage in question is reportedly not a publicly accessible site. KEPCO views this incident as unrelated to the AI-based hacking targeting the financial sector.

Seoul Cyber University also suffered an external leak of personal information belonging to current students, graduates, faculty and staff, and job applicants. The university received notification from the Korea Internet & Security Agency (KISA) on the 4th that data presumed to be personal information of its members had been posted on an external site. The information leaked or potentially leaked includes names, student ID numbers, dates of birth, contact details, email addresses, home addresses, department and academic status, and admission and academic records of students and graduates. The university explained that resident registration numbers, passwords, and account numbers were encrypted, and no evidence of decryption has been found so far.

Seoul Cyber University has formed an emergency task force and reported the incident to the Ministry of Education’s Cyber Safety Center and the Personal Information Protection Commission. The exact cause and scale of the leak are under investigation in cooperation with relevant agencies.

Government Recommends Security Inspections at 28,000 Companies

The recent string of incidents is striking in that the boundaries between attack targets have effectively disappeared. Financial institutions hold asset and credit information, schools hold personal and academic records of students and staff, and public institutions hold various data on employees and citizens. If a security vulnerability is breached at one location, it may not end with a single large-scale leak—the stolen information could be used for secondary attacks targeting other institutions or services.

The government has also raised its security response level. The Ministry of Science and ICT and KISA have switched the KISA Internet Intrusion Response Center (KISC) to a 24-hour emergency posture and expanded monitoring of major corporate websites. On the 4th, emails recommending security inspections were sent to approximately 28,000 companies that have registered a Chief Information Security Officer (CISO). Overseas attacker IP addresses identified by the Financial Security Institute were forwarded to the relevant cloud service providers with requests to block malicious activity.

The Financial Supervisory Service disseminated attacker IP addresses and security advisories to approximately 500 financial institutions across the sector. It ordered emergency inspections on 12 items, including whether attacker IPs have been blocked and damage investigations conducted, and whether externally exposed IT assets and services have been identified and hardened. Any deficiencies found must be remedied immediately.

The electronics and home appliance industry has blocked hacker IPs and conducted emergency security inspections. Companies plan to strengthen identification and protection measures for external touchpoints, address vulnerabilities as they are identified, and reinforce security systems including monitoring for external anomalies and data encryption. The automaker, steel, and construction industries have not yet suffered AI hacking damage but have conducted inspections in line with government and agency guidelines. The airline industry, given its handling of sensitive personal information, continues to conduct ongoing security checks.

Securities firms have also begun emergency inspections of internal systems based on attacker IP addresses and attack patterns received from financial authorities. They have taken preemptive measures such as blocking access from IPs confirmed to have been used in attacks, and continue to monitor for additional hacking attempts even after completing IP blocking and restriction measures. Many securities firms are maintaining emergency duty systems even during the holiday period.

Must Be Viewed as a Society-Wide Risk

With breach incidents now surfacing beyond financial firms and private companies to include energy public corporations and universities, calls are growing to expand the scope of inspections. Not only schools and public institutions holding large volumes of personal information, but also operators of critical infrastructure directly tied to citizens’ daily lives could be targeted. Account and access privilege management, externally exposed systems, and security of partner and subcontractor firms must all be re-examined.

The situation has evolved to the point where a single attacker or a small group can use AI and other automation tools to simultaneously identify vulnerabilities across multiple institutions. There is a growing chorus of voices arguing that cyberattacks must be treated not as individual corporate incidents but as a society-wide risk requiring a coordinated response framework.



Click Here For The Original Source.

——————————————————–

..........

.

.