
Financial authorities are known to have identified 19 internet protocol (IP) addresses related to financial sector hacking attacks suspected of utilizing artificial intelligence (AI) agents.
According to financial authorities and the financial sector on the 6th, the Digital Risk Analysis Team of the Financial Supervisory Service (FSS) pinned down 19 attacker IPs related to this financial hacking incident.
The IP locations spanned 12 countries.
They included the United States, Japan, Hong Kong (China), Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, Sweden, and Germany. (Note: Japan, Sweden, and Germany appeared multiple times.)
US-based IPs were the most numerous at 5, while Japan, Sweden, and Germany each had 2 duplicate IPs. There was also 1 domestic (South Korean) IP.
Hacker(s) of unknown nationality bypassed tracking by routing intrusions through IPs of various nationalities, explored multiple services within financial institution systems, discovered vulnerabilities, and launched focused attacks.
It is reported that the FSS narrowed down the range of attacker IPs based on the IPs that accessed non-normal paths at some banks, including Shinhan Bank, and stole customer personal information.
The FSS distributed this list of attacker IPs to the entire financial sector, requesting that self-inspections and rectifications of deficiencies be completed by the 8th.
Through an official document, the FSS urged, "We hope you will meticulously identify and inspect and take action on vulnerabilities in IT assets and services exposed to the external network," and added, "We hope you will check the authentication, authorization, and validation functions of external systems that could be exploited as intrusion paths."
In addition, the FSS distributed a 12-item "checklist" asking whether:
The shared attacker IPs have been blocked.
There were intrusion attempts or damages corresponding to the attacker IPs.
A real-time security monitoring system is in operation for the early detection and response of cyber threats and intrusion attempts.
Financial institutions are continuing their self-inspections by expanding the period and scope.
In the case of internet-only bank Toss Bank, it was found that abnormal access attempts were made through some attacker IPs pointed out by authorities not only in July to August of this year, but also as early as January.
Some security industry officials lean toward suspecting this hacking to be a China-originated attack. This is because traces of a Chinese-language-based AI penetration testing tool released last July were discovered.
However, at the authority level, only the nationalities of the attacker IPs have been shared, and specific circumstances suspected of a hacking originating from a specific country have not been explicitly mentioned.
A financial sector official stated, "It will take quite a long time for the investigations by financial authorities and the Financial Security Institute, as well as police investigations, to yield results," and added, "Before that, it is difficult to jump to conclusions about which country's hackers are responsible."
[Copyright (c) Global Economic Times. All Rights Reserved.]

![[등록] 2026-09-01 15:48:31](/support/_updata/banner2/tl181982910_6749.png)



























