South Korean President Orders Probe into Data Leaks at Multiple Banks

InfoQuest··KR·Read original
4▲0 ▼0Impact / 5
Summary · why it matters

South Korean President Lee Jae-myung ordered a thorough investigation and the formulation of countermeasures after personal data leaks at multiple banks, financial companies, and government agencies in recent weeks. South Korea's Financial Services Commission, or FSC, said Lee Ook-won, the FSC chairman, convened an emergency meeting on Sunday, October 4, with financial industry associations, regulators, and executives of affected financial institutions, and warned that the financial sector must handle the situation with the highest level of caution. Lee Ook-won said relevant authorities cannot yet rule out the possibility that the perpetrators used artificial intelligence, or AI, in the attacks, and called for using AI-based approaches to defend against AI attacks and for broadly upgrading cybersecurity systems across the financial sector. The emergency meeting followed similar discussions on Friday, October 2, after Shinhan Bank and KB Kookmin Bank, along with other financial institutions, reported cyberattacks, while Hana Bank and Woori Bank were also affected by data leaks. Officials began on-site inspections after Shinhan Bank reported a data leak on September 30 and later expanded the investigation to other reported incidents. The FSC ordered financial institutions to comprehensively inspect security systems, tighten access controls, minimize connections from external systems, and strengthen consumer protection measures, and it will rapidly share information on attack patterns, IP addresses, and other threat data among financial institutions. Regulators believe the attacks may have been reconnaissance of multiple financial companies to find vulnerabilities rather than a targeted strike on any single institution, while attack traffic originated from IP addresses in several countries, including the United States, Japan, Singapore, Vietnam, and the United Kingdom. The Sunday emergency meeting was moved up from its original date of October 7 after additional data leaks were detected at smaller financial institutions. Meanwhile, the People Power Party, South Korea's main opposition party, called on authorities to investigate the possibility of North Korean involvement, citing past cyberattacks that were blamed on North Korea and targeted South Korean financial institutions.

Theme Impact 3

Off-coverage companies 3

Shinhan Banki
Private▼ NegativeRegulationrelevance

Shinhan Bank reported a data leak on September 30 that sparked on-site inspections and the FSC's ordered overhaul of security systems.

KB Kookmin Banki
Private▼ NegativeRegulationrelevance

KB Kookmin Bank reported a cyberattack/data leak, triggering a presidential-ordered probe and FSC-mandated security inspections and consumer-protection measures.

Woori Banki
Private▼ NegativeRegulationrelevance

Woori Bank was affected by data leaks, drawing it into the FSC's emergency meeting and mandated cybersecurity upgrades.

Related news

JapanUnited States
▲

Unauthorized Access Surges, Cyber Defense Inquiries Flood In as Hitachi, Fujitsu, and NEC Strengthen Systems

As unauthorized access to companies surges, electronics giants offering cyber defense services are receiving a flood of consultations and inquiries. In September, Hitachi launched a service that uses advanced AI models from U.S. firms such as Anthropic and OpenAI to provide end-to-end support spanning risk assessment, monitoring, and recovery. Fujitsu announced its cyber defense strategy in late August, and inquiries from client companies have poured in since then, increasing further in recent days, prompting it to establish a specialized organization of about 100 people effective October 1. NEC began offering a service in late September for financial institutions, manufacturers, and distributors that uses AI to automatically analyze risks and formulate response policies. Each company is strengthening its systems in anticipation of sophisticated AI-driven cyberattacks, and demand appears set to keep expanding.
About megatrends
Cybersecurity & Digital Trust › Cyber Resilience & Ransomware Recovery ▲Demand
Cybersecurity & Digital Trust › Network Security & SASE ▲Demand
6501.JP · Demand · Positive Hitachi launched an AI-based cyber defense service and is receiving a flood of consultations as unauthorized access surges.
6701.JP · Demand · Positive NEC began offering an AI cyber-risk service in late September to financial, manufacturing, and distribution clients amid surging attacks.
6702.JP · Demand · Positive Fujitsu's cyber defense inquiries have poured in since its late-August strategy announcement, prompting a new ~100-person specialized organization.
Read original ↗
時事通信·12hRead more →
Japan
▲

JR East: Over 2 Million Members' Data Possibly Leaked at Eki-net and Other Services

East Japan Railway Company announced on the 9th that more than 2 million members' information from its ticket reservation and travel support services "Eki-net" and "Otona no Kyujitsu Club" may have been leaked due to unauthorized access to a cloud service operated by a SoftBank subsidiary. Approximately 1.67 million email addresses of Eki-net members may have been compromised, while about 390,000 records from Otona no Kyujitsu Club, including membership numbers and credit card expiration dates, may have been leaked. Names, addresses, phone numbers, and credit card numbers were not included. In addition, email distribution to members of both services has been partially disrupted. IDC Frontier, the SoftBank subsidiary, suffered a ransomware attack on part of the systems of its cloud service "IDCF Cloud," affecting a wide range of contracted companies and local governments.
About megatrends
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▲Technology
Cybersecurity & Digital Trust › Cloud & Workload Security ▼Technology
Cybersecurity & Digital Trust › Cyber Resilience & Ransomware Recovery ▲Technology
9020.JP · Regulation · Negative Over 2 million members' data from JR East's Eki-net and Otona no Kyujitsu Club services may have leaked via unauthorized access to a SoftBank subsidiary's cloud, and member email distribution was disrupted.
9434.JP · Regulation · Negative SoftBank Corp.'s subsidiary IDC Frontier was hit by a ransomware attack on its IDCF Cloud, affecting a wide range of contracted companies and local governments.
9984.JP · Regulation · Negative SoftBank subsidiary IDC Frontier suffered a ransomware attack on its IDCF Cloud, exposing data of contracted companies and local governments including JR East.
Read original ↗
ロイター·2dRead more →
Japan
2

Japan's FSA Asks Financial Institutions to Review Cyber Defenses, Tighten Driver's License Image Checks

Japan's Financial Services Agency on the 9th, following a spate of customer data leaks caused by unauthorized access, called on financial institutions to review their cybersecurity measures and issued a warning. It is asking them to thoroughly check images of driver's licenses and other ID documents for anything unusual, even when verifying identity without meeting customers face to face. The FSA stressed that it wants institutions to prevent the fraudulent use of financial services and act so as not to undermine trust, urging them to review their response plans for cyberattacks and to promptly take any necessary measures where shortcomings are found. Financial Services Minister Satsuki Katayama said at a post-cabinet press conference on the 9th that identity verification should be carried out appropriately, including by reading IC chip information, which is extremely effective as a countermeasure against fraud. The Ministry of Economy, Trade and Industry announced it will issue warnings to roughly 1,000 industry associations under its jurisdiction, including those in the automotive and retail sectors, calling on management to take the lead in checking communications equipment and systems for vulnerabilities.
About megatrends
Cybersecurity & Digital Trust › Identity & Access Management ▼Regulation
Cybersecurity & Digital Trust › Data Security & Cyber Resilience Regulation
Read original ↗
時事通信·2dRead more →
Japan

METI Issues Alert to About 1,000 Industry Groups After Spate of Unauthorized Access Incidents

Economy, Trade and Industry Minister Ryosei Akazawa said at a post-cabinet meeting press conference on the 9th that, in response to a series of incidents involving information leaks and other damage from unauthorized access in Japan, the ministry issued a broad alert the same day through roughly 1,000 industry groups under its jurisdiction. Akazawa called on companies to act on the understanding that they must manage security not only within their own operations but across the entire supply chain, and urged top management to take responsibility in securing the necessary resources and directing the response. He also encouraged them to quickly identify and address vulnerability information, monitor all activity on internal systems, and promptly provide information when damage occurs.
About megatrends
Cybersecurity & Digital Trust › Data Security Posture & DLP Regulation
Read original ↗
Reuters·2dRead more →
United States
▲

Rubrik Expands Project Hourglass With Code Guardian, Adds AHEAD, Trace3 and WWT

Rubrik announced the expansion of Project Hourglass, broadening its partner alliance to deliver Rubrik Code Guardian alongside Rubrik Agent Cloud. AHEAD, Trace3, and WWT joined the program, which already includes Cognizant, Deloitte, LTM, HCLTech, NTT DATA, and Wipro. Rubrik Code Guardian harnesses Anthropic's Claude Mythos 5 through a specialized security harness to evaluate code repositories against sophisticated, multi-step threat scenarios, testing a cloned, air-gapped copy of customer repositories rather than live production environments. According to Rubrik Zero Labs, 86% of cybersecurity and IT leaders anticipate that the proliferation of AI agents will outpace their organization's security guardrails within the next year. Rubrik Code Guardian is currently in private preview and accepting select design partners, and the company said it is not currently generally available and may change or be discontinued.
About megatrends
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▲Technology
Cybersecurity & Digital Trust › AI Security & Agent Guardrails ▲Technology
Cybersecurity & Digital Trust › Cyber Resilience & Ransomware Recovery Technology
RBRK · Technology · Positive Rubrik expanded Project Hourglass and launched Rubrik Code Guardian, a new AI-agent security product now in private preview with new partners AHEAD, Trace3, and WWT.
Read original ↗
Business Wire·2dRead more →
United StatesIsrael
▲

Core6 Partners with Armis from ServiceNow to Extend Exposure Management to Storage and Backup

Core6 announced a partnership with Armis from ServiceNow that integrates its StorageGuard storage security posture management platform with Armis' continuous asset intelligence, extending cyber exposure management to storage and backup systems. The integration correlates Armis' real-time asset intelligence with StorageGuard's authenticated vulnerability and misconfiguration findings for storage and backup systems, closing a gap that has left storage arrays and backup platforms outside exposure management programs. Core6 founder and CEO Gil Hecht said several banks the FSB classifies as globally systemically important harden their storage and backup with StorageGuard. Nadir Izrael, GVP of Cybersecurity and Risk at ServiceNow, said the partnership enables security teams to shift from reactive threat response to autonomous, AI-driven security. The integration is available immediately for existing Armis from ServiceNow and Core6 customers.
About megatrends
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▲Technology
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Technology
Cybersecurity & Digital Trust › Cyber Resilience & Ransomware Recovery ▲Technology
Core6 · Demand · Positive Core6's StorageGuard is integrated with Armis from ServiceNow, extending its storage security posture management to more customers.
Armis Security · Demand · Positive Armis' continuous asset intelligence is integrated with Core6's StorageGuard, expanding its cybersecurity platform's reach into storage and backup exposure management.
NOW · Demand · Positive Armis from ServiceNow partnership integrates Core6's StorageGuard, extending ServiceNow's exposure management offering to storage and backup systems.
Read original ↗
PR Newswire·2dRead more →