Infiltration Via IPs from 12 Countries Including the US and Japan
Traces of a Chinese-Language AI Penetration Tool
Authorities Do Not Specify Attack Perpetrators

Financial authorities have reportedly identified 19 IP addresses associated with attempted hacking attacks involving artificial intelligence (AI) targeting commercial banks and other financial institutions.


According to the financial sector on October 6, the Financial Supervisory Service narrowed down the attacker's range of IPs by tracing those that accessed some banks, including Shinhan Bank, through abnormal routes and stole customers' personal information.


The attackers’ IP addresses spanned 12 countries, including the United States, Japan, Hong Kong (China), Singapore, Vietnam, Thailand, Malaysia, Spain, Japan, Latvia, Sweden, and Germany. The United States accounted for five IP addresses, the most among them, and there was also one domestic IP address.


It is believed that the hackers bypassed security using IPs from multiple countries to infiltrate financial institutions’ systems, scanned the services, and aggressively exploited any security vulnerabilities they found.


The Financial Supervisory Service shared the list of attacker IPs with the entire financial sector and requested that internal inspections and necessary corrective measures be completed by October 8. The authorities also urged institutions to thoroughly inspect vulnerabilities in externally exposed IT assets and services, as well as the authentication, authorization, and verification functions of outward-facing systems.


The authorities distributed a checklist of 12 items, which included whether the attacker IPs had been blocked, whether intrusion attempts or damage occurred, and whether real-time security control systems were being operated.


Financial institutions are expanding the time frame and scope of their inspections. It was found that at Toss Bank, not only during July and August this year but also in January, there were abnormal access attempts using some of the IPs identified by the financial authorities.



Some in the industry are speculating that this attack originated from China, based on evidence of Chinese-language-based AI penetration testing tools that were released in July. However, the financial authorities have not identified any specific party or perpetrating country. The true nature of the attack is expected to be clarified through investigations by the financial authorities, the Financial Security Institute, and the police.


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing