Skip to content

Invest1 publisher3 min readPublished

South Korea's opposition wants intelligence agencies inside the probe of six lender hacks

South Korea's People Power Party wants intelligence agencies in a joint probe of hacks it says have hit six lenders, four of them commercial banks. Its spokesperson concedes the attacker is unknown, so whether the six share one cause will decide who answers for them.

The Investor · Invest desk

Photograph accompanying South Korea's opposition wants intelligence agencies inside the probe of six lender hacks
Photo: en.sedaily.com

What happened

  • The lenders named as breached are Shinhan, KB Kookmin, Hana and BNK Busan Bank, plus Yegaram Savings Bank and Hyundai Capital.
  • Chief spokesperson Choi Bo-yoon cited North Korea's 2011 attack on Nonghyup and the March 20, 2013 outage at Shinhan Bank, Nonghyup and broadcasters.
  • Park Sung-hoon said this year's parliamentary audit will examine why multiple firms were exposed at the same time and whether regulators' oversight worked.
  • Lawmaker Yoon Sang-hyun wrote on Facebook that management should be pursued too if systems holding customers' sensitive information were laxly run.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • contradiction Choi points toward a possible North Korean operation while Park points to unlocked basics, so the party's own case leaves open whether the state or the lenders' managers should answer for the breaches.
  • decision The government has to choose between a police and intelligence team and the supervisors' self-inspection route, and that choice sets whether the breaches are handled as a security case or a supervisory one.
  • exposure Executives at the six firms now face questioning over their own handling of customer-data systems, alongside the regulators who supervised them.

The People Power Party is making two arguments about the same breaches. Choi Bo-yoon, its chief spokesperson, wants a joint team drawn from the National Police Agency's National Security Investigation Bureau, the National Intelligence Service and military intelligence [3], with the possibility of North Korean involvement kept in view [1]. A day earlier, Park Sung-hoon, also a chief spokesperson for the party, framed it as a failure of basic security: "Before worrying about cutting-edge AI hacking, we have to ask whether the basic front doors of the financial sector were even properly locked." [8]

Those two diagnoses send the cost to different parties. There are roughly three ways this resolves. In the first, one actor ran a campaign across all six firms [1], the case belongs to police and intelligence services, and the lenders look like targets of a hostile state. In the second, each firm left something open, and lawmaker Yoon Sang-hyun's line applies: "if management of systems handling customers' sensitive information was relatively lax, the responsibility of financial firms' management must also be sternly pursued." [10] The third is duller: unrelated intrusions of different severity surfacing together after supervisors asked each firm to inspect itself [6].

The precedent Choi cites fits the first version poorly so far. On March 20, 2013, the networks of financial firms including Shinhan Bank and Nonghyup, along with broadcasters, "went down simultaneously on the same day," Choi said [5]. This time Choi describes lenders "falling one after another" [2]. Choi also said: "We cannot determine who is behind the hacking at this point." [4]

I think the evidence supports a sector-wide exposure across two kinds of lender, four commercial banks and two non-banks [1], and does not yet support a single attacker. The counter-thesis is that six breaches in close succession, at firms with different business models, point to one campaign. Park raises that possibility himself when he says the party will ask "why multiple financial firms were exposed to attacks at the same time" [9]. The view fails if investigators tie the six to one actor or one shared tool.

The party's statements do not include a customer count, a description of the data taken, or a loss figure. Until they exist, the cost to follow is supervisory and managerial. Yoon wrote that "both corporate management responsibility and regulators' supervisory responsibility must be clearly established" [11]. The party plans to press financial authorities on the breaches at the parliamentary audit of government agencies [12].

On Choi's account, regulators have already abandoned their own timetable once. They had planned to collect each firm's self-inspection results after the holiday, then "hurriedly moved up an inspection meeting to today once the damage kept coming to light and anxiety spread," Choi said [6], in a statement issued on the 4th [2]. "At this point it is not defense but a belated reaction," Choi said [7].

What to watch

  • Whether the government activates a joint team with the National Intelligence Service and military intelligence, or leaves the case with financial supervisors.
  • Results from the regulators' inspection meeting and the firms' self-inspections, including any lender added to the six named so far.
  • Disclosure by any of the six firms of what customer data was taken and how many customers were affected.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories