Key facts
- Multiple IP addresses were used to mask the origin of recent cyberattacks against South Korean financial institutions.
- Hana Bank, KB Kookmin Bank, and Shinhan Bank were among the institutions that suffered customer information leaks.
- The Financial Supervisory Service identified 28 IP addresses connected to the attacks.
- South Korean police are investigating the cyberattacks and have formed a 28-member team.
- Investigators are working with international partners to trace the attack path.
Multiple internet protocol (IP) addresses were used to conceal the origin of recent cyberattacks targeting South Korean financial institutions, according to sources. Several banks, including Hana Bank, KB Kookmin Bank, and Shinhan Bank, experienced back-to-back leaks of customer information due to these attacks, prompting a significant police investigation.
The Financial Supervisory Service identified 28 IP addresses associated with the attacks and shared this information with financial companies, noting the possibility of indirect connections used by the attackers. However, police have determined that a substantial number of these IPs were employed to mask the hackers' true locations. Investigators are currently pursuing the attack path through international cooperation.
In response to the security breaches, the National Police Agency has established a dedicated 28-member team to conduct a thorough investigation into the matter.
