![]() |
| A bank ATM installed inside a building in Seoul on the 5th, amid recent hacking incidents in the financial sector. / Yonhap |
Police have transitioned the recent financial institution hacking case into a formal investigation and formed a dedicated 28-member investigative task force. Police plan to focus on examining the intrusion circumstances and scope of damage at each financial firm, as well as potential links between the attacks.
The National Investigation Headquarters of the Korean National Police Agency announced on the 6th that, after verifying objective facts regarding the financial institution hacking incidents, it formally booked the case under charges of violating the Information and Communications Network Act and launched an investigation. Given the gravity of the matter, police designated the Cyber Terror Investigation Division of the National Police Agency as the dedicated task force. A total of 28 investigators across four teams will be deployed, headed by the chief of the Cyber Terror Response Division.
Data breach damage resulting from hacking was recently confirmed across major lenders, including Shinhan, KB Kookmin, Hana, and BNK Busan Bank, followed by additional breaches uncovered at savings banks and capital finance companies. While traces of identical IP addresses were identified in the attacks on the major banks, the IP addresses used in the attacks on the savings banks and capital firms were found to be different.
While establishing the circumstances of the breach and the extent of damage, police are also reviewing whether the case must be referred to the Serious Crimes Investigation Agency. Under the relevant act, offenses violating the Information and Communications Network Act targeting critical national infrastructure and crimes under the Electronic Financial Transactions Act may be subject to mandatory referral. Accordingly, police requested an authoritative interpretation from the Financial Services Commission on whether the systems breached in this incident qualify as critical electronic financial infrastructure.
Meanwhile, the Financial Supervisory Service shared intelligence on 33 IP addresses identified during the investigation—28 excluding duplicates—along with associated country data across the entire financial sector. However, because some IP addresses cannot be traced to specific countries and identified IPs may involve proxy routing, further investigation is needed to pinpoint the attackers. Financial authorities designated a one-month special response period against secondary damage from personal data leaks starting today, stepping up efforts to prevent compromised information from being exploited in financial fraud.
Seol So-young
Yoo Soo-jung
1
2
3
4
5
6
7