FSS Identifies 33 IP Addresses Used in Hacking Attacks on Financial Firms

One-Month Special Response Period Designated Regulator Warns of Rerouting, Urges Internal Checks Firms Told to Block Unauthorized Access, Bulk Requests Lenders' Security Status, Damage Also to Be Reviewed

Finance|
| Updated 2026.10.06. 18:03:30
|
By Cho Ji-wonjw@sedaily.com
||
The Financial Supervisory Service. Yonhap News - Seoul Economic Daily Finance News from South Korea
The Financial Supervisory Service. Yonhap News

Financial regulators have identified 33 internet protocol addresses used in recent hacking attacks on the financial sector and ordered firms to block them. The addresses were detected in 12 countries including South Korea, the United States, Hong Kong and Japan, but regulators also called for thorough internal reviews because IP addresses alone make it difficult to identify attackers.

The Financial Supervisory Service and the Financial Security Institute said on the 6th that they had distributed critical threat information, including 33 IP addresses used in recent hacking attempts against financial firms — 28 after removing duplicates — along with details on security vulnerabilities. The addresses were spread across South Korea, the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, Sweden and Germany. The United States accounted for the most with five, followed by Japan, Sweden and Germany with two each.

Regulators said the location of an IP address alone does not establish an attacker's nationality or point of origin. "Some IP addresses cannot be traced to a specific country, and even when they can, there is a possibility of rerouting, so the data should be interpreted with caution," an FSS official said.

The FSS also distributed an information technology security self-assessment checklist for preparing against breaches to all financial firms and asked each company to work through it. Firms must first block the attacker IP addresses identified by regulators and check whether any intrusion attempts or damage occurred from those addresses. Regulators also instructed firms to identify externally exposed IT assets and services that could be exploited as entry points, and to review vulnerabilities and access controls.

Firms must also check whether they have applied controls such as request threshold limits to prevent abnormal bulk requests or automated bot attacks. Attackers used methods including credential stuffing — repeatedly entering stolen account credentials — at some banks such as Shinhan Bank. Firms must also build detection and monitoring systems to identify and block suspicious activity, including abnormal URL patterns, unauthorized IP addresses and attempts to access administrator accounts at night or on holidays.

The FSS also plans a broad review of hacking damage and security conditions in the consumer lending industry. It will gather cases of hacking damage at lenders through the Korea Consumer Credit Finance Association and order them to conduct their own security reviews.

The Financial Services Commission on the same day designated a one-month special response period for secondary damage from personal data breaches and laid out measures to prevent such harm. During the period, a dedicated counseling channel for data breach cases will operate, and any damage reports received must be relayed immediately to financial regulators. Regulators said they would closely monitor suspicious transactions involving leaked data and share information through an artificial intelligence platform for voice phishing data sharing and analysis to block any secondary damage.

Original reporting by Cho Ji-won for Seoul Economic Daily.

AI-translated from Korean. Quotes from foreign sources are based on Korean-language reports and may not reflect exact original wording.

Watch · Seoul Economic Daily

More →
4:39

AI KEY

Preview
Korean Corporate Intelligence HubKOSPI · KOSDAQ · 12 sectors

A live, cap-weighted view of every KOSPI and KOSDAQ sector, with same-day Korean reporting distilled by company — built for foreign investors, correspondents and analysts who need to scan Korea before the next session.

Korea Company Atlas

Preview
Market Ontology · The Feedback LoopKFTC 2025 · 92 groups · 121,954 articles

An English ontology of the Korean market — how companies, the media, the government and the National Assembly move each other in a loop. Korea's named controlling persons and designated business groups are a mechanism, not a risk to be priced blind.

SIGNAL

Now live
English Edition · Capital MarketsM&A · IPO · PE · Fund Flows

SIGNAL English Edition is live — Korea's deal desk reporting in English. M&A, IPOs, private equity and fund flows, covered daily for global institutional investors. Browse free; subscriber-only scoops at the 50% intro rate.