AI-based attack tools used in the hacking of South Korea’s financial sector are operating on hundreds of servers worldwide, according to new findings. Attackers bypassed existing blocking systems by alternating between overseas leased servers, commercial proxies, and South Korean IP addresses. The possibility of sophisticated voice phishing schemes exploiting leaked loan-related information has also emerged as a serious concern.
According to a threat intelligence report released on the 8th by S2W (488280.KQ), a South Korean security and data intelligence company, hundreds of servers worldwide are currently running the same open-source AI infiltration tools used in the financial sector breach. This indicates that infrastructure capable of automating vulnerability discovery and attacks through AI is spreading rapidly.
Most of the IP addresses used in the attack were newly registered with little to no prior reporting history in global threat reputation databases. Analysts note that filtering out addresses previously classified as malicious alone was insufficient for preemptive blocking. The attack paths also included South Korean IPs, making it difficult to respond effectively through simple measures such as blocking overseas connections.
Fake Leaked Data Sales Emerge
Fraudulent transactions exploiting the post-incident confusion have also been detected. Posts claiming to sell millions of customer records from major South Korean credit card companies appeared in succession on the Dark Web and Telegram. However, S2W’s cross-analysis of actual attack information and samples attached to the sales posts confirmed that a significant portion contained fabricated data.
The fake data prominently featured legacy mobile phone prefixes such as 011, 016, and 019, which are rarely used in South Korea today. Some samples also contained uncommon Korean surnames and overseas email addresses. S2W explained that fraudulent sales posts leveraging the names of well-known companies tend to surge immediately after major security incidents.
Concerns Over Targeted Voice Phishing Using Loan Information
The potential for secondary damage from actually leaked information is more severe. According to South Korean financial authorities, core payment information such as account passwords and one-time passwords (OTPs) was not compromised. However, in addition to names and contact details, loan-related inquiry records were leaked.
If attackers know a victim’s actual loan status, they can execute targeted voice phishing that goes beyond indiscriminate smishing. Tactics include approaching victims with offers of preferential loan terms, or sending text messages claiming to verify personal information leaks to induce installation of malicious apps and demand passwords and OTPs.
Structural Limitations of Outsourced Security Workforce
While cyber threats grow increasingly sophisticated, the security response foundation in South Korea’s financial sector remains vulnerable. A significant number of financial institutions rely on outsourced and contract personnel for security monitoring and incident response (CERT) functions, making it difficult to accumulate expertise within organizations.
As South Korean financial regulators shift toward a corporate self-regulation model, frontline teams that must analyze tens of thousands of abnormal events daily are operating in challenging conditions. Analysts argue that holding individual practitioners or Chief Information Security Officers (CISOs) accountable after each incident is insufficient to counter the surge in AI-based attacks.
S2W emphasized that beyond disputes over inspection responsibilities, it is urgent to internalize frontline security professionals and provide institutional support for financial institutions to build their own AI security assessment capabilities. The company also raised the need for stronger penalties against cyber attackers.
Click Here For The Original Source.
