AI Cuts Hacking Time to 72 Minutes, but State Lenders Barely Add Security Staff | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


The risk of AI-driven hacking across South Korea’s financial sector has risen sharply, yet information security staffing at state-run financial institutions has barely moved. Budget and headcount allocations rank low in priority, prompting calls to lift such limits at least for information security.

The Korea Development Bank had 19 information security specialists as of the end of last year, down from 23 a year earlier, according to financial industry sources on the 7th. The figure stood at 22 as of the end of June this year. The Korea Asset Management Corporation, which handles debt relief for vulnerable groups, kept its dedicated staff at nine last year, unchanged from the previous year. The Export-Import Bank of Korea, with nine, and the Korea Credit Guarantee Fund, with eight, also saw little change in staffing even as data breaches hit one financial firm after another last year. The credit guarantee fund raised its count to 11 in the second half of this year.

Market observers say state-run financial institutions lack the security staff their roles and size warrant. According to cybersecurity firm Palo Alto Networks, the average time from an attempted hacking attack to data exfiltration was about 285 minutes in 2024 as AI advanced, but fell to 72 minutes last year. Police on the previous day upgraded their inquiry into hacking at financial firms to a formal investigation, booking suspects on charges of violating the Information and Communications Network Act and forming a 28-member dedicated investigation team.

Newsis - Seoul Economic Daily Finance News from South Korea
Newsis

The Industrial Bank of Korea (024110.KS) had 17.12 million individual customers and 2,250,422 corporate clients as of the end of last year. As a state-run lender specializing in small and medium-sized enterprises that also serves retail customers, it counts roughly 20 million accounts. The Korea Development Bank has about 2 million corporate clients.

State-run financial institutions holding large volumes of such sensitive data have also become targets for hackers. Beyond personal data and financial transaction records, they hold income and asset information, family relationships and other details. Last year the Industrial Bank of Korea faced more than 860,000 cyberattacks, including 370,000 hacking attempts, 410,000 distributed denial-of-service attacks and 80,000 malicious emails. That amounts to exposure to nearly 900,000 attacks a year, yet its information security staffing last year stood at 50% to 70% of levels at commercial banks such as NH NongHyup Bank, with 118, and Woori Bank, with 101.

Officials at state-run financial institutions say they face far greater difficulty than private financial firms such as banks and brokerages in securing information security budgets and expanding staff. The Industrial Bank of Korea, the Korea Inclusive Finance Agency and others are subject to annual government headcount controls like other state-run institutions, and their total payroll is capped under the total labor cost system. An official at one state-run financial institution said, “With the organization’s total headcount and structure under government control, adding dedicated information security staff means cutting staff in other departments.”

Officials also point to weaker pay competitiveness at a time when competition for IT specialists has intensified across every industry because of rising AI-driven hacking risks. Institutions based outside the capital region face particular difficulty securing qualified staff.

What matters is that commercial banks are also struggling to fill positions. Their situation is better than that of state-run financial institutions, but they have not secured sufficient staff overall.

About half of the dedicated information security staff at the four major commercial banks turned out to be external personnel. An analysis of information security disclosures filed with the Korea Internet & Security Agency showed that KB Kookmin Bank, Shinhan Bank, Hana Bank and Woori Bank had a combined annual average of 367.4 dedicated information security staff last year. Of those, 202 were internal and 165.4 were external, meaning outside personnel accounted for 45% of the total.

By bank, 52 of Woori Bank’s 101 total information security staff were external, an outsourcing share of 51.5%. At Hana Bank, 36.6 of 71.9 were external, a share of 50.9%. Shinhan Bank followed at 44.5%, or 43.5 staff, and KB Kookmin Bank at 34.4%, or 33.3 staff. Internal information security staff as a share of total employees came to 0.43% at Shinhan Bank, 0.42% at KB Kookmin Bank, 0.36% at Woori Bank and 0.30% at Hana Bank.

Internet-only banks, by contrast, run their operations mainly with their own staff. Of Toss Bank’s 30 information security staff, 28.4 were internal, or 94.7%, with external personnel accounting for just 1.6, or 5.3%. At KakaoBank (323410.KS), 52.2 of 78.5 were internal, or 66.5%. Internal information security staff as a share of total employees also ran higher than at the four major banks, at 3.73% for Toss Bank and 2.99% for KakaoBank.

Internet-only banks, which have no branch staff, inevitably have a different staffing structure from commercial banks, but experts agree that securing internal staff matters for continuity in security work. An official at one internet-only bank said, “This does not mean external personnel are less skilled, but because their work presumes a move once the contract ends, there are inevitable differences from internal employees in terms of continuity and accountability.”

The industry has long warned that third-party risk grows as financial firms expand IT outsourcing. After Toss Bank, KakaoBank and K Bank also saw attempts to access their servers from the start of this year through the internet protocol addresses used in major hacking incidents at financial firms, but the internet-only banks are credited with having fended them off. Lim Jong-in, professor emeritus at Korea University’s Graduate School of Information Security, said, “Security staff should be hired as permanent employees wherever possible,” adding that “the country needs to train security specialists who can skillfully use AI.”



Click Here For The Original Source.

——————————————————–

..........

.

.