Financial Services Commission Chairman Lee Eok-won warned that regulators will “hold firms strictly accountable under the relevant laws if similar breaches occur,” pointing to the possibility that artificial intelligence was used in a recent string of personal data leaks at financial companies. He also urged the industry to treat the incidents not merely as a problem to clean up but as an opportunity to raise its information security systems to a higher level.
Lee held an emergency review meeting with the financial industry at 2 p.m. on the 4th at the Government Complex Seoul, joined by Financial Supervisory Service Governor Lee Chan-jin. “The possibility of attacks using AI cannot be ruled out,” he said. “This is a moment when the entire financial sector must recognize the gravity of the situation and maintain the highest level of vigilance.” The FSC had initially planned to hold the emergency meeting on the 7th but moved it forward after confirming that the damage had spread to non-bank lenders.
Also attending were officials from related agencies including the Ministry of Science and ICT, the Personal Information Protection Commission, the Korean National Police Agency and the Korea Internet & Security Agency (KISA), along with the heads of industry associations such as the Korea Federation of Banks and the Korea Financial Investment Association, and executives from seven major financial companies.
Describing the nature of the attacks, Lee said cases had been confirmed in which hackers targeted “areas that drew relatively less attention in terms of management, such as external web pages and servers used by loan brokers and employees for work convenience.” He added, “No matter how solid a security system is, a single unmanaged gap can become the weak point of the entire system.”
Lee said information that could be used for fraudulent payments had not yet been leaked, but called for vigilance. “There is a possibility of secondary damage such as voice phishing and smishing that exploit the leaked information, so do not let your guard down and respond pre-emptively,” he said.
Lee then asked the industry to act on five points: swift and thorough security checks across all financial sectors; minimizing potential risk factors such as external points of contact; prompt and effective consumer protection and compensation for damages; faster sharing of threat intelligence and stronger joint responses; and building security systems that “defend against AI attacks with AI.”
Click Here For The Original Source.
