Skip to content

Invest1 publisherNot yet confirmed elsewhere3 min readPublished

Korea's financial watchdog tells firms to police request patterns after flagging 30 suspected AI-attack IPs

Korea's Financial Supervisory Service told financial firms that blocking the 30 IP addresses tied to suspected AI-agent attacks will not be enough. Attackers can swap addresses through proxies, so the regulator wants firms to judge how requests behave.

The Investor · Invest desk

How we use AISend a correction

What happened

  • The FSS urged firms to consider caps on requests made through individual accounts, sessions and APIs, along with measures to block abnormal input.
  • Its first notice, sent on Sept. 30, named two suspicious addresses and cited the suspected use of AI agents, according to data submitted to Rep. Park Sung-hoon of the People Power Party.
  • That first guidance told firms to check whether their systems had communicated with the addresses and to block any further connections.
  • The warnings follow a string of AI-based cyberattacks that leaked personal information at major commercial banks and at churches.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • cost Request caps per account, session and API are engineering each firm has to build and tune on its own traffic, so the defense bill moves from the regulator's shared notices to individual firms' budgets.
  • constraint A cap on repeated requests for one function has to be set as a threshold, and one tight enough to stop an AI agent is likely to slow some legitimate customers, leaving each firm to choose the level.
  • precedent Once the FSS has written down the request patterns it treats as suspicious, firms can expect examiners to ask whether their logs catch them, a harder test than a firewall entry for 30 addresses.

The list the FSS keeps sending grew from two addresses on Sept. 30 [2] to 30 unique addresses by Tuesday [5]. That is 28 more than the first notice carried [15]. Six notices produced 35 listings in all [5]. Five of them repeated an address already listed [16]. The tally through Monday had stood at 28 unique addresses [5], so two new ones arrived in a day [17].

"IP blocking alone has limitations because attackers can change their source IP addresses through proxies and other means," the FSS said in separate guidance sent on Tuesday [6]. "Detection and response should instead be strengthened by focusing on patterns in requests and responses." A proxy relays internet traffic, so an attacker blocked at one address can reconnect through another [7]. The patterns the FSS described include repeated requests for the same function in a short period, and a new request that immediately reflects information from an error message [9]. It also told firms to analyze requests together when an attacker spreads them over time across rotating addresses [9]. The report does not include a deadline or a cost estimate for any of the changes.

"AI hacking threats are increasing, but our response remains inadequate even in some basic areas," Financial Services Commission Chairman Lee Eog-weon said at a National Assembly audit on Thursday [10]. "We will conduct a thorough review and make the necessary changes." He also said, "Ultimately, we have no choice but to use AI to defend against AI" [12]. The government is separately seeking to ease network separation rules while keeping security safeguards in place [11].

If the unique count keeps rising, as the FSS's proxy argument predicts, the blocklist becomes a daily task with no end date. CrowdStrike's findings allow a second outcome. The U.S. cybersecurity company's analysis on Wednesday raised the possibility that the person behind the attacks is a 26-year-old living in Guangdong Province, China [13]. Its clues came from Claude Code chat records left on a server linked to the attacks. The user had entered an age and place of residence while asking the tool to prepare a job resume [13]. One person may control a limited supply of addresses. A third outcome depends on Lee's review, if it turns Tuesday's suggestions into requirements with deadlines [10].

I think the address count is the wrong figure for a firm to manage against. The FSS's own guidance says any blocked address can be replaced through a proxy [7], and two new addresses in a day [17] fit that. The counter-thesis rests on CrowdStrike's lead. If one person is behind the attacks, 30 addresses may be most of what that person controls, and blocking them would have done more than the FSS credits. CrowdStrike acknowledged that its information was not enough to identify the attacker conclusively [14]. The view is wrong if the unique count stops climbing and no new leaks of personal information are reported [4].

What to watch

  • Network separation rule changes, and whether they let firms deploy the AI-based defenses Lee described.
  • Any bank disclosure of what account and API request caps cost to build, or how many legitimate customers they throttle.
  • A conclusive identification of the attacker by investigators, the test of whether one person's supply of addresses limits the blocklist.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence58
Adoption
Insufficient
Hype gap+10
Incentives35
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    The Financial Supervisory Service warned financial firms that blocking suspicious IP addresses alone will not be enough to stop a wave of suspected AI-powered cyberattacks.

    ReportedSupportedSource: Korea JoongAng DailyView cited source
  2. [2]

    The FSS identified two suspicious IP addresses in a document sent to firms on Sept. 30 and explicitly noted the 'suspected use of AI agents,' according to data submitted to Rep. Park Sung-hoon of the People Power Party.

    ReportedSupportedSource: Data submitted to Rep. Park Sung-hoon, reported by Korea JoongAng DailyView cited source
  3. [3]

    The initial guidance instructed financial firms to check whether their systems had communicated with the addresses and to block further connections.

    ReportedSupportedSource: Korea JoongAng DailyView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. koreajoongangdaily.com

    1 article · October 8, 2026

    IP blocking alone isn’t enough against AI hackers, financial watchdog warns

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories