
Financial regulators have identified 33 internet protocol addresses used in recent hacking attacks on the financial sector and ordered firms to block them. The addresses were detected in 12 countries including South Korea, the United States, Hong Kong and Japan, but regulators also called for thorough internal reviews because IP addresses alone make it difficult to identify attackers.
The Financial Supervisory Service and the Financial Security Institute said on the 6th that they had distributed critical threat information, including 33 IP addresses used in recent hacking attempts against financial firms — 28 after removing duplicates — along with details on security vulnerabilities. The addresses were spread across South Korea, the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, Sweden and Germany. The United States accounted for the most with five, followed by Japan, Sweden and Germany with two each.
Regulators said the location of an IP address alone does not establish an attacker's nationality or point of origin. "Some IP addresses cannot be traced to a specific country, and even when they can, there is a possibility of rerouting, so the data should be interpreted with caution," an FSS official said.
The FSS also distributed an information technology security self-assessment checklist for preparing against breaches to all financial firms and asked each company to work through it. Firms must first block the attacker IP addresses identified by regulators and check whether any intrusion attempts or damage occurred from those addresses. Regulators also instructed firms to identify externally exposed IT assets and services that could be exploited as entry points, and to review vulnerabilities and access controls.
Firms must also check whether they have applied controls such as request threshold limits to prevent abnormal bulk requests or automated bot attacks. Attackers used methods including credential stuffing — repeatedly entering stolen account credentials — at some banks such as Shinhan Bank. Firms must also build detection and monitoring systems to identify and block suspicious activity, including abnormal URL patterns, unauthorized IP addresses and attempts to access administrator accounts at night or on holidays.
The FSS also plans a broad review of hacking damage and security conditions in the consumer lending industry. It will gather cases of hacking damage at lenders through the Korea Consumer Credit Finance Association and order them to conduct their own security reviews.
The Financial Services Commission on the same day designated a one-month special response period for secondary damage from personal data breaches and laid out measures to prevent such harm. During the period, a dedicated counseling channel for data breach cases will operate, and any damage reports received must be relayed immediately to financial regulators. Regulators said they would closely monitor suspicious transactions involving leaked data and share information through an artificial intelligence platform for voice phishing data sharing and analysis to block any secondary damage.






