Sunday, October 4, 2026

Private Companies Also Urged to 'Urgently Strengthen Security' Amid Indiscriminate Hacking Attacks on the Financial Sector

Input
2026-10-04 14:44:37
Updated
2026-10-04 14:44:37
Ministry of Science and ICT.

[Financial News] AI hacking attacks that began at major banks have spread to the non-bank financial sector, including savings banks and capital companies. As the ministry chiefly responsible for responding to hacking and security incidents, the Ministry of Science and ICT has also gone on high alert. The ministry has activated what is effectively an emergency response system and is making every effort to prevent further damage caused by the novel hacking methods that struck the financial sector from spreading to private companies.
According to industry sources on the 4th,  the Ministry of Science and ICT held an emergency meeting after a series of AI hacking incidents hit the financial sector and is working on response measures.  The Korea Internet & Security Agency (KISA), an affiliate of the ministry, posted a notice titled 'Recommendations for Companies to Strengthen Security Against Recent Cyberattacks,' urgently advising private companies to strengthen their security measures. It also raised the monitoring level for security incidents from 'Attention' to 'Caution.'
The AI Comprehensive Analysis Team of KISA's Threat Analysis Division noted that security measures need to be strengthened in preparation for additional attacks, as multiple security incidents have occurred at financial institutions and private companies in South Korea.
Because the attackers' IP addresses, intrusion routes and methods have not been accurately identified, companies need to respond swiftly in preparation for the possibility of further attacks on other businesses.
The Financial Services Commission (FSC) has summoned the heads of all financial-sector associations and the CEOs of financial companies affected by security incidents for an emergency inspection meeting. Separately from the financial authorities' response, the Ministry of Science and ICT has also begun developing separate security-enhancement measures as the ministry chiefly responsible for responding to hacking and security incidents.  
Unlike past attack patterns, which required specialized teams and personnel as well as software and infrastructure, AI agents are automating vulnerability scanning, repeated attacks and information gathering. This is raising concerns that attacks will become more sophisticated and faster, accelerating the spread of damage.
 KISA urged organizations to identify internet-exposed assets and remediate vulnerabilities, strengthen verification of vulnerabilities in web applications and application programming interfaces (APIs) and access privileges, protect accounts and authentication information, prevent server breaches and the spread of attacks to internal systems, and strengthen information-leak detection and coordinated monitoring.  
It stressed the need to block unused services and restrict access to administrator pages, databases and administrative access functions to only those required for business purposes and through designated access routes.   It also emphasized that multifactor authentication (MFA) should be implemented to prevent account takeovers.   
[email protected] Jang Min-kwon Reporter