The recent series of hacking incidents in the financial sector is expected to be a major topic during the National Assembly's Financial Services Commission audit starting October 6. The focus will be on the security management of financial companies and the oversight responsibilities of regulatory authorities. There are calls for additional testimonies from the CEOs of the five major banks, aiming to investigate not only the causes of the incidents but also whether existing security checks and vulnerability improvements have been effectively implemented.
According to the National Assembly, the Financial Services Commission audit is scheduled for October 8, followed by the Financial Supervisory Service audit on October 19. Initially, issues such as household loan management, sanctions on Hong Kong ELS, and the governance structure of financial holding companies were expected to dominate discussions. However, the recent data breaches have shifted the focus to security management and oversight responsibilities.
Park Sang-hyuk, a member of the ruling Democratic Party and the Financial Services Commission's standing committee, stated that they will summon the five bank CEOs to question them about the causes and responsibilities related to the incidents. Depending on whether additional witnesses are called, the audits on October 19 and the comprehensive financial audit on October 22 may address the banks' responses to the incidents and measures to prevent recurrence.
Given that the incidents occurred through external points such as loan recruitment and employee systems, the scope and effectiveness of existing security checks are expected to be scrutinized. Key verification tasks will include whether the affected services were included in the inspection targets, whether improvements were made following identified vulnerabilities, and whether authorities confirmed the implementation of corrective actions.
In response to the incidents, financial authorities have initiated emergency inspections across the entire financial sector. From September 30 to October 3, breaches were confirmed at seven companies, including Shinhan, KB Kookmin, Hana, Busan Bank, Yegaram, Welcome Savings Bank, and Hyundai Capital. The Financial Services Commission, the Financial Supervisory Service, and the Financial Security Institute began on-site investigations on the day of the Shinhan Bank incident report and are also looking into additional reports.
The Financial Supervisory Service has disseminated the internet addresses (IP) used in the attacks and security precautions to about 500 financial companies, requiring them to conduct emergency inspections. Banks and card companies must complete their inspections by October 6, while insurance, securities, savings banks, and electronic financial service providers must finish by October 8. They are required to verify 12 items, including blocking attack IPs, investigating damages, and identifying externally exposed digital assets, and to promptly address any deficiencies.
Authorities are particularly focused on eliminating blind spots in the management of external systems. Lee Ok-won, chairman of the Financial Services Commission, emphasized during an emergency inspection meeting on October 4 that checks should extend beyond customer services to include external points used by employees, loan recruiters, and outsourced companies. He ordered that access to external systems be generally blocked unless essential for service provision or business operations, and even in unavoidable cases, access rights and inquiry information should be minimized.
Lee stated, “If similar incidents occur due to negligence in necessary inspections and responses despite already shared attack information and incident cases, we will hold those responsible strictly according to relevant laws.”
As the deadline for emergency inspections for banks and card companies coincides with the start of the audit, and inspections for other sectors continue until the Financial Services Commission audit, vulnerabilities and corrective measures identified during the inspections are likely to be addressed during the audit. The management responsibilities of the financial companies involved in the incidents, along with whether the authorities' inspections and oversight effectively identified and improved actual security vulnerabilities, are expected to be key issues.
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.

