- The Financial Services Commission said it is reviewing revisions to the Electronic Financial Supervision Regulations to shorten reporting times for hacking breaches in response to a rise in AI-driven hacking attacks.
- The FSC said it is considering a shorter reporting deadline so it can quickly share information on hacking incidents and help other financial firms block additional damage more efficiently.
- The FSC said it is reviewing a plan to increase the security vulnerability inspection cycle from once a year to at least twice a year and expand oversight to external business systems.
Forecast Trend Report by Period

AI Speeds Up Hacking, Prompting Rewrite of Electronic Finance Rules
Security Vulnerability Checks to Be Increased to at Least Twice a Year

South Korea’s financial authorities are moving to shorten the time financial firms have to report hacking breaches as attacks using artificial intelligence become more frequent. The push comes amid criticism that security rules for the financial industry still place too much weight on periodic inspections and after-the-fact reporting, even as AI now scans for vulnerabilities around the clock and automates attacks.
According to the financial industry on Oct. 8, the Financial Services Commission is reviewing revisions to the Electronic Financial Supervision Regulations, which currently require financial firms to report hacking incidents to the FSC within 24 hours. Under the rules, financial companies and electronic financial service providers must report the details and impact of a breach to the FSC without delay, and the filing cannot be delayed beyond 24 hours without a valid reason.
The FSC’s review reflects the view that AI-driven hacking moves far faster than conventional cyberattacks. The sooner authorities can share information on breaches across the industry, the more efficiently other financial firms can check whether they have also been compromised and block additional damage.
Swift information sharing is especially important because there have been few reported cases of AI-based hacking. At the same time, the FSC is weighing the fact that individual firms may need considerable time to determine whether they have been hacked, limiting how much a shorter reporting deadline alone can improve response times.
The FSC has already said it would shorten the cycle for security vulnerability checks at financial companies and broaden the scope of those reviews. The current Electronic Financial Supervision Regulations require vulnerability analysis and assessments at least once a year for general information processing systems and at least twice a year for public-facing websites. The FSC is considering raising the once-a-year inspection cycle to at least twice a year and expanding oversight to external business systems that were excluded from the existing rules.
While financial authorities have said they will move to overhaul the regulations, the effort is also drawing criticism for coming only after a series of hacking incidents exposed weaknesses in the existing security framework.
Park Si-on, Hankyung.com reporter ushire908@hankyung.com
Click Here For The Original Source.
