18 overseas-origin hacking attempts targeting financial firms in three years; attackers unidentified in 16
- Input
- 2026-10-09 09:16:58
- Updated
- 2026-10-09 09:16:58

According to data submitted to Song Eon-seok, a People Power Party lawmaker on the National Assembly’s Political Affairs Committee, by the Financial Supervisory Service, a total of 18 incidents suspected to involve overseas cyberattacks on financial firms were reported over about two years and nine months, from 2024 through the 8th. The perpetrators were identified in only two of the cases.
The hacking incident at Seoul Guarantee Insurance in July last year was confirmed to have been carried out by the international ransomware group GUNRA. The group’s ransomware attack infected the company’s servers, disrupting its services for about 64 hours. Seoul Guarantee Insurance paid a total of 11.91 million won in compensation to customers affected by the incident.
The perpetrator of the hacking incident at Baro Savings Bank in April this year was identified after the ransomware group INC Ransom directly demanded payment.
Of the remaining 16 cases, excluding those two, the attacking IP addresses in 13 were believed to be located overseas based on domain lookups, detection by in-house security equipment, and investigations into the breaches, among other methods. The other three were classified as “country of origin unknown” because the perpetrators could not be identified.
Incidents suspected to involve hacking originating in China include the Lotte Card breach, in which data on about 2.97 million customers was leaked last year, as well as incidents at SC First Bank and KB Life Insurance that same year.
Attacks are also believed to have originated in the United States, Bulgaria, Vietnam, Indonesia, Japan, Hong Kong, Taiwan, Seychelles, Thailand and the United Kingdom, among other places. In reality, however, confirming an IP address located overseas does not make it easy to identify the actual perpetrator or their country.
The Financial Supervisory Service recently shared 28 attacking IP addresses with the financial sector, along with information on some of the countries involved, and cautioned that they should be interpreted carefully because the connections may have been routed through other locations.
In materials submitted to the lawmaker’s office, the Financial Supervisory Service also explained: “In most cases, attackers alter IP addresses or route their connections through virtual private networks (VPNs) and other means. It is virtually impossible to identify the perpetrators based solely on information about the countries where the IP addresses are located.”
Separately, it was also difficult to identify the perpetrators of overseas-origin cyberattacks during the same period on electronic financial service providers and online investment-linked financial companies.
Of the 12 incidents in those sectors, the perpetrators were identified in just one case.
The 2024 distributed denial-of-service (DDoS) attack on electronic financial service provider Eximbay could be attributed to its perpetrators because the company received an advance notice of the attack under the name of the external hacker group Alpha Jackals.
By contrast, after a hacking incident exploiting a security vulnerability occurred at Coem Payments in late August, the attacker contacted the company directly, but investigators could only estimate that the country involved was China.
As police investigate the perpetrators behind a recent series of cyberattacks targeting the financial sector, the possibility has also been raised that a 26-year-old living in Guangdong, China, was behind them. Global cybersecurity company CrowdStrike arrived at this assessment after finding clues in chat records from the generative AI coding tool Claude Code, obtained from the attacker’s server. However, the person identified as the attacker is reportedly denying any connection to the incidents.
[email protected] Kim Hyung-gu Reporter