South Korea’s Financial Services Commission has paused the next phase of a program intended to loosen bank security rules. The agency pulled the plug just a day before the next set of banks were to be picked.
The reason for the cancellation is a recent run of AI-assisted hacks that tore through seven financial firms and exposed tens of thousands of customer records.
The South Korean Financial Services Commission has suspended the next phase of its bank deregulation program following a series of AI-assisted hacks. The idea of loosening bank security rules in the first place was based on the premise that AI would strengthen defenses, but these recent attacks hit even the firms that were rated most secure.
The policy that was supposed to be loosened is Korea’s network separation rule that requires financial companies to keep their internal business systems physically walled off from the internet.
The rule was initially imposed due to cyberattacks in the late 2000s, with public agencies covered from 2007 and banks from 2014. For years, the rule worked. During the 2017 WannaCry outbreak, for instance, Korean finance escaped largely unscathed because malware could not reach isolated networks.
However with the introduction of generative AI, regulators argued that the rule blocked banks from running the very AI tools they needed to detect threats, so the FSC began carving out exemptions.
Vice Chairman Kwon Dae-young convened a roundtable in May on advanced-AI security risks, and the first round of relaxation covered 49 firms with at least 10 trillion won in assets and 1,000 staff, each granted a one-year exemption to test AI-driven defenses.
The second phase was supposed to grow the eligibility to 75 companies, with the asset bar cut to 2 trillion won and the headcount floor to 300. The number of firms chosen was also set to rise from 10 to as many as 15. Selections were scheduled for October 7.
The FSC is now saying that it needs further review with the Financial Supervisory Service while it contains the breaches. The regulator insists it still backs deregulation in principle.
The breaches began on September 30 at Shinhan Bank, where an outside party slipped past identity checks in a loan-agent service and pulled the personal data of roughly 25,000 customers.
Following the discovery of the breach, the FSC circulated the attacker’s IP addresses, leading to other firms checking their own logs and finding that their systems had also been breached.
Reportedly, 25,727 records at Shinhan were breached. 119 at KB Kookmin Bank, 89 at Hana Bank, and 11 outsourced developers at BNK Busan Bank.
The damage then reached secondary lenders like Yegaram Savings Bank which disclosed a breach affecting about 40,000 customers, the largest single figure so far. Welcome Savings Bank lost up to 2,200 corporate records and Hyundai Capital exposed data on 146 of its mortgage loan agents.
Shinhan reportedly took more than 15 hours to spot its breach, Hana nearly 42 hours, and KB Kookmin close to 68 hours.
The Korea Financial Security Institute says the common thread in these hacks is ARTEX AI, an open-source, large-language-model penetration-testing system distributed on GitHub mainly within Chinese-speaking circles.
Analysts reportedly first spotted an “ARTEX — Autonomous Penetration Testing Console” string on servers tied to the Shinhan attack. The tool also won an offensive-security contest run by Baidu’s security response center this year.
An institute official clarified that the tool did not act alone and was simply used by a hacker as a tool to extract internal employee and partner systems data, which the official said had been “managed less rigorously” than services offered to the public.
The institute also said that two or three IPs overlapped at each bank, and blocking one simply pushed the intruder to another, with the activity still live.
FSC Chairman Lee Eog-weon urged industry representatives at an emergency meeting on October 4 to stay on “the highest alert.”
The FSC, the Financial Supervisory Service and the institute have ordered emergency self-inspections at roughly 500 firms, with banks and card companies due to report first and savings banks, insurers and e-finance operators by October 8.
The institute believes that direct financial theft is unlikely since the attackers didn’t seize control of accounts, but voice-phishing scams will be far harder to detect now that attackers are armed with accurate sensitive information like loan and credit details.
If you're reading this, you’re already ahead. Stay there with our newsletter.