Surge of Cyber Attacks on Financial Sector Triggers Emergency Response by FSC and FSS
Kim Young Min Reporter
sskyman77@naver.com | 2026-10-06 16:31:28
As cyberattacks targeting the financial sector continue to surge, financial authorities have initiated an emergency inspection of security systems across the entire financial industry.
The Financial Services Commission (FSC) announced on the 5th that it held an "Emergency Inspection Meeting for All Financial Sectors" the previous day, led by FSC Chairman Lee Eok-won, with attendees from the Financial Security Institute, industry-specific financial associations, and major financial institutions. Related government bodies—including the Ministry of Science and ICT (MSIT), the Personal Information Protection Commission (PIPC), the Korean National Police Agency, and the Korea Internet & Security Agency (KISA)—also participated to discuss pan-governmental cooperation.
Following the receipt of a security breach report from Shinhan Bank on the 30th of last month, the FSC, the Financial Supervisory Service (FSS), and the Financial Security Institute immediately launched an on-site investigation to identify the causes and extent of the damage. Investigations into subsequent breach reports submitted by other financial institutions are also underway.
Prior to this, an emergency response meeting was held on the 2nd to review recent trends and directions for responding to security breaches, and identified attack intelligence was disseminated across the entire financial sector. Financial institutions were provided with security inspection checklists and requested to conduct self-inspections and report their findings.
Financial authorities directed all financial institutions—including not only banks and credit card companies, but also mutual finance cooperatives, savings banks, insurance companies, securities firms, and fintech companies—to comprehensively identify all externally exposed IT assets and services.
Institutions are required to fully reassess security vulnerabilities, authentication and access controls, and breach detection systems, as well as verify whether previously shared malicious IP addresses, attack vectors, and intrusion attempt data have been properly reflected in their detection and blocking systems.
External access management is also being reinforced. Financial institutions must identify external touchpoints and system access pathways used for operations, and fundamentally block all external access except when essential for consumer services and core business operations.
Even when external access is unavoidable, access privileges and retrievable information must be minimized to the strictest extent. Institutions must also check that personal credit information is neither unnecessarily stored nor queried on systems used by external personnel or employees, such as loan solicitors and outsourced vendors.
Consumer protection and damage compensation in the event of security breaches will be strengthened. Financial institutions must quickly determine the scope of leaked information and potential consumer harm, immediately implementing protective measures to prevent secondary information leakage or financial loss.
To prevent secondary damages such as voice phishing and smishing exploiting leaked information, preventive measures such as enhanced fraud detection systems (FDS) and customer guidance will be reinforced.
Financial authorities decided to expand the sharing of threat intelligence, including malicious IP addresses and attack methods, among financial institutions. Centered around the FSS and the Financial Security Institute, authorities plan to monitor financial sector intrusion activities and immediately disseminate information regarding any new attack signs to block further damage.
The government also agreed to expand threat intelligence sharing beyond the financial sector to various industries, while strengthening inter-ministerial cooperation among MSIT, PIPC, and the National Police Agency.
In particular, to counter novel attacks leveraging artificial intelligence (AI), the government is pushing to build a security framework based on the philosophy of "fighting AI attacks with AI security." Financial institutions are expected to actively participate in government-led AI security tests and transition toward AI-based security frameworks rooted in Zero Trust principles.
Meanwhile, as of the 5th, no customer information leaks caused by hacking attacks have been reported among securities firms. No unusual hacking-related activities have been discovered among securities-related institutions such as the Korea Exchange, Koscom, and the Korea Securities Depository. According to financial authorities, identical attacker IP addresses were discovered across seven security breach incidents, including those at Shinhan, KB Kookmin, Hana, and BNK Busan banks, Yegaram and Welcome savings banks, and Hyundai Capital. Reports indicate that the attacker leveraged AI tools to launch large-scale, automated attacks targeting multiple financial institutions.
The FSS has distributed malicious IP addresses and security precautions to approximately 500 financial institutions across the board. Banks and credit card companies must complete their emergency inspections by the 6th, while securities firms, insurers, savings banks, and electronic financial business operators are required to finish by the 8th.
[ⓒ Global Economic Times. 무단전재-재배포 금지]
WEEKLY HOT
- 1Gyeongsangbuk-do Tears Down K-Food 'Regulatory Barriers' on the Ground
- 2Andong’s Four World Heritage Sites Open the "2026 World Heritage Festival"
- 33 Gyeongsangbuk-do Universities Shine on National Stage for Regional Innovation
- 4Bucheon Workers' Rest Support Center Unveils "Today's Respect Type" Through Comics and Self-Diagnosis
- 5Voices of 15 Cities and Counties to Shape Youth Policy in Chungnam
- 6Chungnam Delegation Aims for 3rd Overall Place at National Sports Festival