
South Korean police have formed a 28-member task force and opened a formal investigation into a recent hacking attack on a financial institution. Police have registered the case as a suspected violation of the Act on Promotion of Information and Communications Network Utilization and are also reviewing whether it must be reported to the newly launched Serious Crimes Investigation Agency.
The National Police Agency said on the 6th that it had verified the basic facts of the recent hacking of a financial institution, converted the case into a formal investigation and booked it on suspicion of violating the information and communications network law.
Citing the gravity of the case, the agency designated its Cyber Terror Investigation Unit as the task force. Lee Dong-hoon, head of the Cyber Terror Response Division, will lead the team, which comprises four squads and 28 investigators in total. Police said the task force will focus on how the hacking was carried out and the scale of the damage.
Police are also examining whether the case falls under the reporting requirement for the Serious Crimes Investigation Agency. Under the law governing the agency, other investigative bodies must immediately notify its chief when they become aware of serious crimes designated by presidential decree in the course of an investigation.
In this case, the decisive question is whether the hacked system qualifies as an "electronic financial infrastructure facility."
Cybercrimes subject to the reporting requirement fall into two broad categories. The first is a violation of the information and communications network law through the hacking of national core infrastructure. Police concluded, however, that the financial institution itself does not constitute national core infrastructure, so the case is not reportable on those grounds.
The second is a violation of the Electronic Financial Transactions Act through hacking of an electronic financial infrastructure facility. That law defines information processing systems and communications networks used in electronic financial transactions as electronic financial infrastructure facilities. Accessing such a facility without authorization, or manipulating, destroying, concealing or leaking stored data, carries up to 10 years in prison or a fine of up to 100 million won.
Police have therefore asked the Financial Services Commission for a legal interpretation to determine whether the system actually breached in this case qualifies as an electronic financial infrastructure facility. If the commission finds that it does, the case could become subject to notification of the Serious Crimes Investigation Agency.
"We will work closely with related agencies and conduct a swift and strict investigation to ease public anxiety," an official at the National Police Agency said.






