Gov't issues consumer alert, launches monthlong effort to prevent fraud after data breaches政府发布消费者警示,启动为期一个月的行动,防止数据泄露后的欺诈行为。
Financial authorities issued a consumer alert at the “caution” level Tuesday after suspected artificial intelligence (AI)-assisted cyberattacks sto...

Financial authorities issued a consumer alert at the “caution” level Tuesday and began a monthlong response effort after suspected AI-assisted cyberattacks stole personal information from seven financial firms. Affected companies must support customers, report suspected fraud and strengthen fraud monitoring. Authorities said no customer financial losses have been confirmed, but warned that scammers could use exposed details to impersonate loan advisers or offer fake compensation. Regulators identified about 30 associated IP addresses and ordered firms to secure externally accessible systems.
The seven affected firms are Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital.
Financial firms must immediately report confirmed or suspected fraud cases, share suspicious information through an AI-powered voice-phishing platform and suspend payments involving suspicious accounts.
The Financial Supervisory Service identified about 30 IP addresses associated with the attacks across the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, Sweden, Germany and Korea.
Authorities said an IP address location does not establish an attacker’s nationality or the actual source of an attack.
The FSS instructed firms to identify externally accessible IT infrastructure, assess vulnerabilities, verify that associated addresses are blocked and review authentication, authorization and validation controls.
Published Oct 6, 2026 2:50 pm KST
Updated Oct 6, 2026 8:26 pm KST
AI hacking fears spread to brokerages, insurers, card issuers
ATMs belonging to major banks are installed in Seoul, Monday. Yonhap
Financial authorities issued a consumer alert at the “caution” level Tuesday after suspected artificial intelligence (AI)-assisted cyberattacks stole personal information from banks, savings banks and a capital finance company.
They also launched a monthlong special response period to prevent scams involving the stolen data.
The measures follow data breaches reported at seven firms since the beginning of this month — Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. The incidents suggest the attacks, first reported in the banking sector, are having a broader impact.
During the special response period, financial firms must open dedicated support channels for affected customers and immediately report any confirmed or suspected cases of fraud that may follow to regulators.
Firms must also strengthen monitoring through their fraud detection systems. Suspicious information linked to the breaches will be promptly shared through an AI-powered platform for sharing and analyzing voice phishing information for financial institutions, telecom companies and investigative agencies. This will help firms take swift action, including suspending payments to or from suspicious accounts.
Authorities said no financial losses, such as the theft of money from customers’ accounts, have been confirmed. They are nevertheless taking precautions against fraud involving the compromised information.
“Although passwords were not leaked, scammers could piece together personal details from the exposed data to impersonate loan advisers or lure victims with promises of compensation for the data breaches,” an official at the Financial Supervisory Service (FSS) said.
Authorities stressed that consumers should not assume a call or message is legitimate simply because the sender knows their income, borrowing limit or other financial details.
People were advised to check whether their information was stolen through their financial institution’s official website or main telephone number. Those affected should also avoid storing resident registration numbers, account passwords or copies of identification documents on their phones to reduce the risk of further exposure.
Regulators may extend the special response period as needed and will immediately raise the consumer alert level if further harm is confirmed.
Amid growing concerns, brokerages, insurers and credit card issuers are stepping up security measures and checking for potential breaches.
Attempted intrusions detected across several parts of the financial sector have led regulators and industry officials to suspect that the attackers were scanning a broad range of companies for weaknesses rather than pursuing a single target.
Further cases may come to light, they warned, noting that smaller firms have relatively limited security staffing and that the attacks were timed during October’s extended holiday period.
At some brokerages, staff responsible for security reportedly worked through the long holiday weekend to conduct internal reviews.
“We have not identified any data leaks in the brokerage industry so far, but we are staying alert and carrying out further checks,” an official at a Seoul-based securities firm said.
Insurers have also reported no confirmed leaks or system intrusions linked to the attacks but continue to monitor for and block potential threats.
“We work closely with the financial authorities to share threat information, including IP addresses associated with breaches,” an official at a Seoul-based insurance company said.
Card issuers, for their part, are conducting their own inspections, paying particular attention to IT infrastructure and services accessible from outside their networks.
Reviews are focusing on identity verification and access controls following indications that the attackers exploited weaknesses in business support systems and information lookup services used by employees and loan agents.
The digital risk analysis team at the FSS has identified about 30 IP addresses associated with the attacks across multiple countries and territories including the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, Sweden, Germany and Korea.
The attacker may have used IP addresses in different locations to obscure their trail while searching financial companies’ systems for exploitable weaknesses. The location of an IP address alone does not establish the attacker’s nationality or the actual source of an attack, according to authorities.
Regulators have circulated these IP addresses and security guidance to firms across the industry. Companies have been instructed to check externally accessible IT assets and services for vulnerabilities and verify that the addresses have been blocked.
In a written notice, the FSS called on each firm to identify its externally accessible IT infrastructure, assess vulnerabilities and take corrective action. It also urged companies to review authentication, authorization and validation controls in systems that attackers could exploit to gain entry.
Police launch probe into recent cyber attacks at financial firms
AI-powered attacks on banks expose technological lag in Korea's financial cyber defenses
Shinhan, Kookmin, Hana data breaches fuel concerns over AI-powered cyberattacks in financial sector
周二,金融监管机构发布了“谨慎”级别的消费者警示,并启动了为期一个月的应对行动。此前,疑似人工智能辅助的网络攻击导致七家金融公司个人信息被盗。受影响的公司必须为客户提供支持,举报可疑欺诈行为,并加强反欺诈监控。监管机构表示,目前尚未确认客户遭受经济损失,但警告称,诈骗分子可能利用泄露的信息冒充贷款顾问或提供虚假补偿。监管机构已识别出约30个相关IP地址,并责令相关公司加强对外开放系统的安全性。
受影响的七家公司分别是新韩银行、KB国民银行、韩亚银行、BNK釜山银行、Yegaram储蓄银行、Welcome储蓄银行和现代资本。
金融公司必须立即报告已确认或疑似的欺诈案件,通过人工智能语音钓鱼平台共享可疑信息,并暂停涉及可疑账户的付款。
金融监督院查明了与这些攻击相关的约 30 个 IP 地址,这些地址分布在美国、日本、香港、新加坡、越南、泰国、马来西亚、西班牙、拉脱维亚、瑞典、德国和韩国。
当局表示,IP 地址位置并不能确定攻击者的国籍或攻击的实际来源。
FSS 指示各公司识别可从外部访问的 IT 基础设施,评估漏洞,验证相关地址是否被阻止,并审查身份验证、授权和验证控制。
发布于2026年10月6日下午2:50(韩国标准时间)
更新于2026年10月6日晚上8:26(韩国标准时间)
人工智能黑客攻击的担忧蔓延至经纪公司、保险公司和发卡机构。
周一,首尔安装了各大银行的自动取款机。(韩联社)
周二,金融监管机构发布了“谨慎”级别的消费者警示,此前疑似人工智能 (AI) 辅助的网络攻击从银行、储蓄银行和一家资本金融公司窃取了个人信息。
他们还启动了一个月的特别应对期,以防止利用被盗数据进行诈骗。
继本月初以来七家公司——新韩银行、KB国民银行、韩亚银行、釜山银行、艺嘉蓝储蓄银行、惠康储蓄银行和现代资本——相继发生数据泄露事件后,相关部门采取了这些措施。这些事件表明,最初在银行业发现的数据泄露攻击正在产生更广泛的影响。
在特别应对期间,金融公司必须为受影响的客户开通专门的支持渠道,并立即向监管机构报告任何已确认或疑似的欺诈案件。
各公司还必须加强通过反欺诈系统进行监控。与数据泄露相关的可疑信息将通过一个人工智能平台迅速共享,该平台用于共享和分析金融机构、电信公司和调查机构的语音钓鱼信息。这将有助于各公司迅速采取行动,包括暂停可疑账户的收付款。
当局表示,尚未证实发生任何经济损失,例如客户账户资金被盗。尽管如此,他们仍在采取预防措施,防范利用泄露信息进行的欺诈活动。
“虽然密码没有泄露,但诈骗分子可以从泄露的数据中拼凑出个人信息,冒充贷款顾问,或者以数据泄露赔偿为诱饵引诱受害者,”金融监督院(FSS)的一位官员表示。
当局强调,消费者不应仅仅因为发件人知道他们的收入、借款限额或其他财务细节就认为电话或短信是合法的。
建议民众通过金融机构的官方网站或主要电话号码查询个人信息是否被盗。受影响者还应避免在手机中存储居民登记号码、账户密码或身份证件复印件,以降低信息进一步泄露的风险。
监管机构可根据需要延长特别应对期,如果确认存在进一步损害,将立即提高消费者警示级别。
随着担忧情绪日益加剧,经纪公司、保险公司和信用卡发行机构正在加强安全措施,并检查是否存在潜在的安全漏洞。
在金融领域的多个方面检测到的入侵企图,让监管机构和行业官员怀疑攻击者是在扫描大量公司以寻找漏洞,而不是针对单一目标。
他们警告说,可能会有更多案件曝光,并指出规模较小的公司安保人员相对有限,而且这些袭击事件发生在 10 月份的长假期间。
据报道,一些经纪公司的安保人员在长周末假期期间加班进行内部审查。
“到目前为止,我们尚未发现经纪行业存在任何数据泄露,但我们会保持警惕并进行进一步检查,”首尔一家证券公司的官员表示。
保险公司也报告称,尚未发现与这些攻击相关的已确认的泄露或系统入侵事件,但会继续监控并阻止潜在威胁。
“我们与金融监管机构密切合作,共享威胁信息,包括与数据泄露相关的 IP 地址,”首尔一家保险公司的官员表示。
发卡机构方面也在进行自己的检查,尤其关注可从其网络外部访问的 IT 基础设施和服务。
审查的重点是身份验证和访问控制,因为有迹象表明攻击者利用了员工和贷款代理人使用的业务支持系统和信息查询服务的漏洞。
FSS 的数字风险分析团队已确定与这些攻击相关的约 30 个 IP 地址,这些攻击涉及多个国家和地区,包括美国、日本、香港、新加坡、越南、泰国、马来西亚、西班牙、拉脱维亚、瑞典、德国和韩国。
攻击者可能使用了位于不同地区的IP地址来掩盖其踪迹,同时搜寻金融公司系统中的可利用漏洞。据当局称,仅凭IP地址的位置无法确定攻击者的国籍或攻击的真正来源。
监管机构已将这些IP地址和安全指南分发给业内各公司。公司已被要求检查外部可访问的IT资产和服务是否存在漏洞,并确认这些地址已被屏蔽。
FSS在一份书面通知中,要求各公司识别其外部可访问的IT基础设施,评估漏洞并采取纠正措施。通知还敦促各公司审查系统中的身份验证、授权和验证控制措施,以防止攻击者利用这些措施入侵系统。
警方对近期针对金融机构的网络攻击展开调查
人工智能驱动的银行网络攻击暴露了韩国金融网络防御的技术滞后
新韩、国民、韩亚数据泄露事件加剧了人们对金融领域人工智能网络攻击的担忧