Attackers unidentified in most hacking attacks on financial firms: lawmaker议员称,大多数针对金融公司的黑客攻击中,攻击者身份不明。
The attackers behind 16 of 18 suspected overseas hacking attacks against South Korean financial companies reported since 2024 remain unidentified,...

South Korean financial companies reported 18 suspected overseas hacking attacks since 2024, with attackers identified in only two cases. Seoul Guarantee Insurance Co. suffered a 64-hour disruption from a GUNRA ransomware attack last July, while Baro Savings Bank was attacked by INC Ransom in April. Rep. Song Eon-seok called for an AI-based defense system as recent leaks at Hana Bank, KB Kookmin Bank and Shinhan Bank raised further concerns.
The Financial Supervisory Service data cited by Rep. Song Eon-seok showed that 13 of the 16 unresolved cases involved IP addresses believed to be overseas, while three had unknown origins.
The reported countries of origin included China, the United States, Bulgaria and Vietnam, although an IP address may not identify an attacker’s physical location.
Seoul Guarantee Insurance Co. operations were disrupted for 64 hours after the GUNRA ransomware attack in July last year.
Rep. Song Eon-seok said technologies are needed to identify attackers because IP addresses can be concealed or disguised.
Published Oct 9, 2026 9:36 am KST
ATMs are seen inside a building in Seoul, Wednesday. Yonhap
The attackers behind 16 of 18 suspected overseas hacking attacks against South Korean financial companies reported since 2024 remain unidentified, a lawmaker said Friday.
According to a report by Rep. Song Eon-seok of the main opposition People Power Party, citing data from the Financial Supervisory Service, local financial firms have reported 18 hacking attacks originating overseas since 2024 through Thursday, with the attackers identified in only two cases.
In July last year, Seoul Guarantee Insurance Co. suffered an attack by GUNRA, an international ransomware group, which disrupted operations for 64 hours. In April, Baro Savings Bank experienced an attack by the ransomware group INC Ransom.
Of the remaining 16 cases, 13 were linked to internet protocol (IP) addresses believed to be located overseas, while the countries of origin were unknown in three cases.
The countries of origin included China, the United States, Bulgaria and Vietnam, although an IP address does not necessarily indicate where an attacker is physically based.
"We need to promptly establish an AI-based defense system to address hacking attempts," Song said, stressing the need to develop technologies to identify attackers, as IP addresses can easily be concealed or disguised.
Several financial companies, including Hana Bank, KB Kookmin Bank and Shinhan Bank, suffered leaks of customer information in a series of hacking attacks last week, raising concerns over possible data breaches at more firms.
自2024年以来,韩国金融公司报告了18起疑似境外黑客攻击事件,但仅有两起案件确定了攻击者身份。首尔担保保险公司去年7月遭受GUNRA勒索软件攻击,导致其业务中断64小时;巴罗储蓄银行则在今年4月遭到INC Ransom勒索软件攻击。鉴于近期韩亚银行、KB国民银行和新韩银行的数据泄露事件引发了更多担忧,韩国众议员宋彦锡呼吁建立基于人工智能的防御系统。
宋彦锡议员引用的金融监督院数据显示,16起未决案件中有13起涉及据信来自海外的IP地址,另有3起案件的来源不明。
据报道,攻击者的来源国包括中国、美国、保加利亚和越南,但 IP 地址可能无法识别攻击者的实际位置。
去年 7 月,首尔担保保险公司遭受 GUNRA 勒索软件攻击后,运营中断了 64 小时。
宋彦锡议员表示,由于 IP 地址可以被隐藏或伪装,因此需要利用技术来识别攻击者。
发布于2026年10月9日上午9:36(韩国标准时间)
周三,首尔一栋建筑物内可见自动取款机。(韩联社)
一位议员周五表示,自 2024 年以来,韩国金融公司遭受的 18 起疑似海外黑客攻击事件中,有 16 起的攻击者身份仍然不明。
据主要反对党国民力量党议员宋延锡援引金融监督院的数据报道,自2024年以来,截至周四,韩国本土金融公司报告了18起源自海外的黑客攻击,但只有两起案件的攻击者身份得到确认。
去年7月,首尔担保保险公司遭受国际勒索软件组织GUNRA的攻击,导致其运营中断64小时。今年4月,巴罗储蓄银行也遭遇了勒索软件组织INC Ransom的攻击。
在剩余的 16 例病例中,13 例与据信位于海外的互联网协议 (IP) 地址有关,而 3 例的来源国不明。
攻击者的来源国包括中国、美国、保加利亚和越南,但 IP 地址并不一定表明攻击者的实际所在地。
宋先生表示:“我们需要尽快建立基于人工智能的防御系统来应对黑客攻击。”他强调,需要开发识别攻击者的技术,因为 IP 地址很容易被隐藏或伪装。
上周,包括韩亚银行、KB国民银行和新韩银行在内的多家金融公司在一系列黑客攻击中遭遇客户信息泄露,引发了人们对更多公司可能出现数据泄露的担忧。