Wednesday, September 9, 2026

"Prepare for AI Hacking Threats"—CISOs Across the Financial Sector Summoned

Input
2026-09-09 14:45:24
Updated
2026-09-09 14:45:24
Yonhap News Agency

[Financial News] As hacking threats using Mythos-level artificial intelligence (AI) become increasingly apparent, the Financial Supervisory Service summoned Chief Information Security Officers (CISOs) from financial companies and called for stronger security response systems.
Lee Jong-oh, Deputy Governor in charge of the Digital and IT sector at the Financial Supervisory Service, chaired a meeting of CISOs from across the financial sector on the 9th. Representatives from 16 major financial companies and financial associations attended.
According to the Financial Supervisory Service, the National Institute of Standards and Technology (NIST) disclosed 35,872 new security vulnerabilities in the first half of this year, up 51.6% from the same period last year. The Korea Internet & Security Agency (KISA) issued 199 security advisories during the first half of this year, a 46.3% increase over the same period. If AI is used for hacking, it can not only rapidly identify vulnerabilities but also launch automated attacks targeting multiple financial companies.
The Financial Supervisory Service asked financial companies to establish enterprise-wide IT risk management systems led by senior management and strengthen the identification and management of IT assets, security vulnerability management, and cyber incident response systems. Financial companies with inadequate responses will face close monitoring, on-site inspections, and meetings with their executives.
The agency also emphasized compliance with basic IT controls. It pointed out that failures in basic controls—including failure to apply critical security patches, leaving former employees’ accounts active, and inadequate encryption of user information—had caused several major IT incidents recently. Financial companies across the sector will carry out voluntary corrective measures through November, and future inspections will focus on how basic controls are operated.
The Financial Supervisory Service plans to consider reducing sanctions for minor incidents when companies address deficiencies through proactive voluntary corrective measures. However, it will take stern action if formalistic self-correction leads to a large-scale IT or cyber incident. It also plans to support the financial sector in building a security system that "defends AI with AI" by gradually expanding emergency measures to ease network-separation regulations.
Lee Jong-oh urged financial companies to remain highly vigilant, saying, "Frontier AI-based security threats are no longer a vague concern but a real-world problem directly linked to the survival of financial companies. We must therefore maintain a much higher level of awareness." He added, "Under the direct leadership of senior management, please establish enterprise-wide measures to strengthen IT security and thoroughly prepare for cyber threats armed with new technologies by expanding your organizations, staffing, and budgets."

[email protected] Park Moon-soo Reporter