Skip to content

Security2 publishers2 min readPublished

South Korea's financial regulator orders firms to inspect and report on every externally accessible system

South Korea's FSC ordered financial firms to audit and report on all exposed systems after bank breaches local media put at 144,000 customers. Each firm's findings go to a regulator that has also pledged to oversee compensation and look for rule changes.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying South Korea's financial regulator orders firms to inspect and report on every externally accessible system
Generated illustration

What happened

  • At the FSC's emergency meeting, officials confirmed a data breach at Shinhan Bank and said other cybersecurity incidents hit banks including Kookmin.
  • Hana Bank also suffered a limited-scope breach after its sales-support system was compromised, local media reported.
  • President Lee ordered a thorough investigation into personal data leaks at financial and public institutions, local outlets reported.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint A bank's inspection has to include internal tools reachable from the internet, so the inventory it reports on is larger than its customer-facing services.
  • contradiction Officials applied the term data breach only to Shinhan, yet local counts put Kookmin's leak at nearly five times Shinhan's, so the official record and the press rank the two banks' damage differently.
  • exposure If the ARTEX AI link holds, the tooling automates finding and verifying weak exposed services, so any financial firm with the gaps the FSC listed is in reach, beyond the three banks reported.

Results are due "as soon as possible" [7]. The instruction as published sets no date. Its scope is every externally accessible IT system and service a financial company runs, including those that are not customer-facing [4]. A sales-support system like the one compromised at Hana Bank [10] is in scope if it can be reached from the internet.

The checklist is narrow and technical. Firms must cut unnecessary information exposure and check for missing or inadequate authentication and access controls [5]. They must also share threat information quickly and coordinate their responses [6]. The public account of the meeting does not say how attackers got into Shinhan or Kookmin. In my view the checklist is the regulator's clearest statement of where it thinks the gaps are.

The breach sizes come from local media reports. Those reports put Shinhan's leak at the details of 25,000 customers [11] and Kookmin's at credit card information for 119,000 clients [12]. On those counts Kookmin's figure is about 4.8 times Shinhan's [19], and the two add up to 144,000 [18]. Both are large private commercial banks, each with more than $400 billion in assets [17].

Attribution is thinner. Official channels gave no details about the perpetrators [13]. The suspected AI link rests on the Yonhap page-title report [14]. ARTEX AI is an open-source penetration-testing system. Its agents automate the work of collecting information, finding vulnerabilities, planning attack paths, running security tools and confirming the vulnerabilities they find [15]. Neither the bank nor the financial authorities have confirmed it was used against Shinhan, and the string in Chinese does not tie the attacks to any particular threat actor [16]. Moon Jong-hyun, head of the Genian Security Center, wrote on LinkedIn that several threat analysts believe the breaches involved AI-based attack automation tools [20].

The commission is treating the incidents as one series of cyberattacks on financial institutions [1]. It opened on-site investigations after receiving incident reports and shared actionable information with agencies including KISA [3]. It has also pledged to oversee consumer protection and compensation and to analyse the incidents for necessary regulatory improvements [8]. Firms' inspection results go to those same authorities [7].

What to watch

  • Whether the FSC sets a fixed deadline for inspection results or publishes what firms found across the sector.
  • Whether Kookmin's incident is confirmed as a data breach and the 119,000 card-record figure is confirmed by the bank or the regulator.
  • Whether the on-site investigations or KISA confirm or rule out ARTEX AI in the Shinhan breach.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories