Skip to content

Invest1 publisher3 min readPublished

Korea's regulator widens its AI security exemption to about 15 more financial firms

Korea's Financial Services Commission is due on the 7th to name about 15 more financial firms exempt from network separation rules, after a first round of 10. Network separation rules are what stop lenders running AI security tools, so the list decides who can use AI against AI-driven hacking.

The Investor · Invest desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • The regulator concluded the first 10 firms, among them Shinhan, Hana and Woori banks, Hanwha Life Insurance and NH Investment & Securities, were too few for AI-driven threats.
  • To qualify for the second round, a firm needs at least 2 trillion won in total assets and 300 or more employees.
  • AI-driven hacking attempts hit banks, savings banks and capital firms from late September into early October.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • decision The FSC has to decide whether the country's largest bank joins the exempt group on the 7th or stays outside it for a second round.
  • constraint Smaller savings banks and capital firms under the asset or headcount floor stay outside the exemption however often they are targeted, a bar security industry officials call too high.
  • cost The exemption removes a legal barrier and funds nothing, so AI tools and the specialists to run them come out of each firm's own security budget.

The FSC reached its "too few" verdict on September 3 [1], weeks before the attempts began [5]. The second list was sized before the attacks and will be named after them [4]. Scanning that looked like reconnaissance for further hacking was reported at one or two life insurers on October 5 [17].

The security budgets do not line up with the first-round list. Korea Internet & Security Agency disclosures put Shinhan Bank's information security spending last year at 36.9 billion won, down 0.4%, and Woori Bank's at 36.4 billion won after an 18.1% cut [10]. Working backwards, Woori spent about 44.4 billion won the year before, so it took out roughly 8 billion won [2]. Hana spent 37.2 billion won, and KB Kookmin raised its spending 1.9% to 43.3 billion won [11]. The bank left out of the first round outspent Woori by about 6.9 billion won [4], or rather outspent all three first-round banks in the disclosure [5]. The four together spent 153.8 billion won [3].

"Even if firms want to run AI to block AI-driven hacking, the financial sector faces real obstacles because of its distinctive network separation rules," a security industry official said on October 5 [9]. A financial industry official said: "With AI threats growing, information security spending needs to rise sharply alongside deregulation" [12]. "The financial sector has built its security around network separation," said Lee Sang-geun, who teaches in Korea University's School of Smart Security, part of its Graduate School of Information Security. "It is an approach that digs a wide moat to keep attackers out, but the belief that they are cut off from the outside has left internal defenses relatively neglected" [13].

Older code sits behind the network rules. According to the financial authorities and the Financial Security Institute, some firms still run languages such as COBOL [14]. "In many cases, functions have been bolted onto old legacy programs over decades, so even when a vulnerability is known it is hard to fix," a senior financial industry official said [15]. KB Kookmin, the bank outside the exemption, began recruiting in December last year for staff to automate COBOL-to-Java conversion with AI [16].

If KB Kookmin is named on the 7th, the exempt group reaches about 25 firms [1] and includes the biggest spender in the disclosure [5]. A list filled from the same tier of large lenders leaves the savings banks and capital firms caught in the attack wave outside; the record does not show how many of them clear the floor [3][5]. Should the regulator speed up later rounds and make the arrangement permanent, as industry officials want [8], any single list matters less. In my view the exemption costs the FSC little, and the spending it requires falls on banks that, in the case of first-round names Shinhan and Woori, cut security budgets last year [2][10]. That view is wrong if Shinhan's and Woori's next disclosures show security budgets rising sharply [10].

What to watch

  • Whether the reconnaissance scanning reported at life insurers turns into attempts on firms that miss the asset or headcount floor.
  • Whether the authorities widen AI diagnostics from major systems to business support services, which one security official said were not examined closely enough.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories