Breached Despite Top-Level Security: Business Systems Became the Entry Point
As hacking attacks, believed to leverage AI, spread across the financial sector, commercial banks are reporting mixed results on whether customer data was leaked. The difference lies in how each bank applied customer identity verification and system access controls.
According to the financial industry on the 5th, personal data breaches linked to external hacking were confirmed at Shinhan Bank, KB Kookmin Bank, and Hana Bank. Woori Bank and NH NongHyup Bank were also targeted, but no leaks have been confirmed so far. For all three breached banks, the attack vector was a business system used by loan brokers or employees.
At Shinhan Bank, data was exposed through the simple lookup service of 'M-Shinhan,' a mobile website loan brokers use to check loan processing status. KB Kookmin Bank saw customer data leaked through abnormal access to its employee-facing mobile work support system, while Hana Bank experienced a breach via abnormal access to its sales support system (ODS).
Woori Bank, where no leak has been confirmed to date, uses a structure in which loan brokers enter information into ODS tablet terminals and must complete smartphone-based 'WON certificate' authentication when logging in. According to the bank, the system is designed to make ordinary external logins impossible.
