Tuesday, October 6, 2026

[Editorial] Ten years since the Defense Ministry’s operational plans were stolen, security awareness remains unchanged

Input
2026-10-06 18:27:29
Updated
2026-10-06 18:27:29
Prime Minister Han Seong-suk delivers opening remarks at a meeting on personal information leaks at financial and public institutions, held on the 6th at the Government Complex Seoul in Jongno-gu, Seoul. / Photo: News 1
As AI-powered hacking runs rampant across the financial sector, the government and financial institutions are scrambling to come up with countermeasures. But making a big fuss also carries the implication that the fuss will soon die down. Once this uproar passes, they will inevitably forget about hacking and personal information leaks, acting as if nothing ever happened.
It was only a year ago that customer information was leaked from Coupang and Lotte Card. Because the information of a major card company and a retail company had been stolen, there seemed to be recognition of the seriousness of the situation and preparations for countermeasures, but the effort fizzled out. We are always like this. We have a deeply ingrained “boiling-pot mentality”: when something happens, we make a huge fuss as if it were a catastrophe, but as time passes, even the memory fades. The government and the private sector are no different.
Now, core financial institutions have come under attack. Hackers infiltrated peripheral organizations and stole information; if they were to breach the main computer networks as well, it could lead to a major incident that brings the financial system to a halt. Even after last year’s incident, financial institutions remained complacent. One bank actually cut its investment in information security. One bank reportedly received a perfect score in an inspection for six consecutive years.
Cutting investment is a problem, but an even bigger one is that the authorities gave a perfect score despite glaring gaps in personal information protection. There is no way to describe it other than a perfunctory inspection. It also shows just how dismal the awareness and attitude are of the government, which is responsible for management and oversight. Ten years ago, a hacker believed to be from North Korea stole the Defense Ministry’s operational plans. Our security awareness has not changed since then.
Strengthening security requires investment in both personnel and resources. To keep pace with ever more sophisticated hacking techniques, we need to develop stronger defensive technologies and train security specialists. Investment is essential. Banks showed little interest in security even as they posted record profits. Financial incidents exploited that gap, and hacking has done the same.
The private sector alone cannot stop hacking. A response at the national level is needed. We must develop security talent and research the technology, even if that means establishing an organization like a security technology institute. The government could lead, with companies or financial institutions providing the funding. Hacking targeting financial institutions is not simply a breach of private security networks; it is an infringement on national security. Imagine the financial system collapsing because of a cyberattack.
Once again, we cannot help but point to the National Assembly’s dereliction of duty. An amendment to the Electronic Financial Transactions Act, intended to address information leaks after last year’s incident, was introduced but reportedly has not been discussed even once. The Assembly has spent its days in political bickering and ended up neglecting a bill that truly matters. The financial authorities also recently prepared “Guidelines for Responding to AI Security Threats,” but financial institutions paid little attention.
As AI technology continues to advance, there is every possibility that even bigger incidents will occur in the future. They can never be prevented with today’s lethargic and complacent mindset. The government and the National Assembly must come to their senses and, this time, put in place decisive measures.