Police have launched a formal investigation into a recent string of hacking incidents targeting banks and formed a dedicated task force.
The Korean National Police Agency said on Oct. 6, “In connection with the recent hacking incidents at financial institutions, after verifying the objective facts, we shifted to a formal investigation and booked the crime as a violation of the Act on Promotion of Information and Communications Network Utilization and Information Protection.”
The Korean National Police Agency said, “In view of the seriousness of the matter, we will designate the KNPA Cyber Terror Investigation Unit as the dedicated task force and conduct an intensive investigation.” It organized the task force with four teams and 28 members, led by the Cyber Terror Response Division chief as the Head of Team.
Police are also reviewing whether this case falls under the notification criteria for the Serious Crimes Investigation Agency (SCIA). Cybercrimes subject to SCIA notification are cases involving violations of the Act on Promotion of Information and Communications Network Utilization and Information Protection due to hacking of national core infrastructure, or violations of the Electronic Financial Transactions Act due to hacking of electronic financial infrastructure.
The victimized financial institutions do not constitute national core infrastructure, so the first criterion does not apply. However, depending on whether the hacked system is electronic financial infrastructure, the case could be subject to SCIA notification, so police requested an authoritative interpretation from the Financial Services Commission.
The Korean National Police Agency said, “We will work closely with relevant agencies to ease public anxiety,” adding, “We will proceed with the investigation swiftly and sternly.”
According to financial authorities, breaches were confirmed at seven institutions: Shinhan, KB Kookmin, Hana, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank, and Hyundai Capital. The IP addresses that attacked the commercial banks differed from those that attacked the savings banks and the capital firm, but the methods were found to be similar. The attacker appeared to repeatedly infiltrate financial companies’ systems while rotating IPs from multiple countries.
In particular, traces of “ARTEX AI” use were also found on the IPs that attacked the banking sector. ARTEX AI is an open-source autonomous security assessment tool that uses large language models (LLMs) to find vulnerabilities and attempt intrusions. Financial authorities are examining the possibility that the attackers used such AI tools to mount large-scale, automated attacks against multiple financial companies.
Click Here For The Original Source.
