Hacking IPs Also Targeted Internet-Only Banks Earlier This Year
The internet protocol (IP) addresses — unique numbers identifying computers — used in attempted hacks of South Korea's financial sector also targeted internet-only banks such as K bank, Kakao Bank and Toss Bank starting early this year. A server inspection at K bank found four access records from the IPs used in the recent attack, spanning July and September. The same IPs accessed Kakao Bank in January and March, with attempts to probe for security vulnerabilities in September, while Toss Bank logged around 10 access attempts from January to August. However, all three banks blocked the access attempts, and no personal information was leaked.
This contrasts with commercial banks, where the leak occurred through linked services such as a loan broker lookup site. Jang Sang-geun, a research director at security firm Logpresso, explained, "Large banks operate a wide range of IT infrastructure systems as well as agencies and branches, so they have a great many points of attack."
Meanwhile, the financial authorities have so far identified a total of 28 attack IPs. The IP list and country information have been shared across the entire financial sector. However, the Financial Supervisory Service noted, "Some IP addresses cannot be traced to a specific country, and even when a country is identified, attackers can reroute through others."
Believing that loan-related fraud or voice phishing could be attempted using the leaked personal information, the FSS announced it will run a one-month special response period against secondary damage from the personal data leak, starting today.
