South Korea's Financial Services Commission has ordered financial companies to immediately review all externally accessible IT assets and services following recent data breaches and cyberattacks. The sectorwide response focuses on identifying security and access control weaknesses, blocking unauthorized access and unnecessary information exposure, and accelerating threat intelligence sharing among financial companies and relevant authorities. Firms must examine every externally accessible system, regardless of whether it is customer-facing, and identify any route that allows access to internal information without adequate authentication. Particular attention must be given to authentication controls used when accessing personal and other internal data. The commission plans to provide a vulnerability checklist and require firms to report their review results promptly. The measures follow a Sept. 30 data breach at Shinhan Bank and subsequent attacks affecting KB Kookmin Bank and other major financial companies. Financial authorities have begun on-site investigations after receiving incident reports and are sharing attacker IP addresses, attack methods and other threat data with bodies including the Korea Internet and Security Agency. They will also supervise affected firms' consumer protection and compensation measures while analyzing the incidents for possible policy changes.
South Korea's Financial Services Commission orders immediate security reviews after financial sector cyberattacks
South Korea's Financial Services Commission has ordered financial companies to review all externally accessible systems, strengthen authentication and access controls, and rapidly share cyberthreat information. The action follows a Shinhan Bank data breach and attacks affecting KB Kookmin Bank and other major financial companies, with affected firms also subject to supervision over consumer protection and compensation.