Protecting Only the Core Entry Points Is Not Enough: "The Gap Between Core and Support System Security Must Be Reduced"
Security Gaps in the Financial Sector: Expert Analysis
Personal Information Exposed at Shinhan, KB Kookmin, and Hana Banks
Attackers Exploit Vulnerabilities in Peripheral Systems and Support Networks
"Comprehensive Management of Entir
The commonality between Shinhan Bank, KB Kookmin Bank, and Hana Bank, whose customers’ personal information was leaked due to external hacking attacks, is that the breaches occurred through external, exposed systems—not the core financial networks. Rather than the main networks that provide financial services such as account transfers, it was the surrounding systems or partner-only websites—areas with relatively weaker security management—that served as infiltration points. Experts emphasize that security capabilities should not be focused solely on core financial networks, but that external-facing support networks and peripheral systems must be managed to a standard nearly equivalent to the core networks.
According to the financial industry on October 6, from September 28 to October 3, six banks—including Shinhan, Hana, KB Kookmin, Busan, NH NongHyup, and Woori—were targeted by external hacking attacks. At Shinhan Bank, personal data of about 25,000 clients was leaked; at KB Kookmin Bank, 119 people’s information was exposed; and at Hana Bank, data for 89 individuals was compromised. At Busan Bank, personal information of 11 outsourced developers was exposed. NH NongHyup Bank and Woori Bank successfully blocked the attack, avoiding data leakage. The banks affected by data breaches—Shinhan, KB Kookmin, and Hana—have activated emergency response systems and are inspecting for further possible breaches. However, there are concerns that individual company checks and responses alone cannot keep pace with increasingly sophisticated and automated hacking attacks.
This latest wave of attacks did not target just one specific financial institution. Using AI-based techniques to exploit vulnerabilities, attackers launched attempts over several days, targeting multiple banks. They concentrated their efforts on peripheral systems and partner-only websites, which tend to have looser security controls than core financial systems.
Park Chanam, advisor to the National AI Strategy Committee and CEO of cybersecurity firm Stillion, commented, “While banking and other core systems have high levels of security, there are resource limitations—such as budget and manpower—when it comes to maintaining the same level of control for peripheral systems with external touchpoints, like partner-only websites. As we prioritize the most important systems, security management for peripheral systems tends to be deprioritized.”
Professor Kim Myungjoo, head of the AI Safety Laboratory and professor of Information Security at Seoul Women’s University, also pointed out, “One root cause of this problem may be that the security standards applied to support systems are relatively lax just because they’re not part of the core financial infrastructure.”
This is why it’s essential to move away from protecting only the core financial network and instead manage the entire “attack surface” across all external touchpoints. Professor Yeom Heungyeol from the Department of Information Security at Soonchunhyang University noted, “In core financial services—such as account transfers—there are multiple layers of authentication, but in support networks, authentication may be weaker or entirely lacking. With this incident as a lesson, the disparity in security standards between core and support networks must be minimized when overhauling a bank’s security infrastructure.”
Not only has there been a “neglect” of support systems, but a shortage of personnel has also been cited as another factor delaying incident detection and post-attack responses. In these hacking attacks, banks took tens of hours to become aware of the breaches after they occurred. Shinhan Bank identified the breach about 27 hours after the event, KB Kookmin Bank after 25 hours, and Hana Bank only realized the data leak 42 hours after it happened.
Professor Kim Myungjoo explained, “Even if warning signals are generated by the system, there needs to be a notification process and enough personnel to continuously monitor and respond. When access is distributed across different sites, detecting abnormal activities can be even more challenging.”
To plug these ‘holes,’ security management must be extended even to systems previously seen as of lower importance. Not only should budgets and staffing be increased, but the authority of security personnel should be amplified. While increased investment in budget and personnel cannot guarantee complete protection against hacking, it does boost the chances of preempting or quickly detecting attacks through more robust security investments.
Im Jongin, professor emeritus at Korea University’s Graduate School of Information Security, stated, “Hiring more AI professionals and increasing investment in token and computing costs is key. Financial regulators should provide advanced curricula and best practices for AI-powered defense, sharing them across banks and secondary financial institutions to strengthen sector-wide defense, and prepare concrete post-breach response measures.”
CEO Park also commented, “If you look solely at this incident, the larger problem wasn’t that ‘AI wasn’t used.’ Instead, areas that could have easily been addressed by security managers weren’t backed by sufficient investment, leading to lapses in vulnerability management and failure to properly correct known issues. Strengthening AI-driven security ultimately requires further investment in token usage and GPU infrastructure.”
Some caution that the logic of being powerless before sophisticated, automated AI attacks should not serve as an excuse for this incident. Professor Kim said, “The areas breached at these banks are the same ones that have always been vulnerable—even before AI was in play. Regardless of whether AI is used, we must first address these pre-existing weak points.”
Experts noted that this problem should not be viewed as limited to the financial sector. Since even banks—where security standards are relatively high—were compromised via external touchpoints, public institutions and small and medium-sized enterprises, which typically have weaker security, must also prepare for possible attacks targeting their vulnerabilities.
Hot Picks Today
[Exclusive] "Forecasts of Over 10 Billion, but Only 100 Million Earned"... 95% Followed This Pattern: Why Are KOSDAQ Special Exception IPOs Inflated? [KOSDAQ Inflated IPOs]①
- "If You Wear Heavy Makeup, You Look Unsophisticated"... North Korean Teens in Love with 'Korean-Style No-Makeup Makeup'
- "My Debt Is 73 Million Won"... Sharing Every Repayment Led to an Unexpected Turn
- "Drinking This in the Morning Is Like Drinking Alcohol"..."Doctors Warn: Never Consume It"
- Is 'KOGUMA' Coming Too?... "Japan in Serious Trouble" - Archipelago on High Alert Ahead of Holidays
CEO Park concluded, “Particularly within the financial sector, now that the specific routes and methods of these recent attacks have been publicized, we can’t discount the possibility of attackers targeting other organizations and companies with similar vulnerabilities. This financial sector hacking incident should serve as a turning point for raising security standards across industries as a whole.”
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.