Science & Tech · Cybersecurity · 1 day ago
Most overseas-linked hacks of South Korean financial firms remain unattributed
South Korean financial firms had 18 hacking incidents believed to have come from abroad between 2024 and October 8, 2026.
Authorities identified the attacker in only two cases.
In 13 others, they estimated a foreign location from the attackers’ internet addresses, while three were classified as having an unknown country.
An internet address does not necessarily show who carried out an attack or where they were, because attackers can disguise it or connect through a VPN.
Separate incidents at electronic payment and online investment firms had a similar problem: only one of 12 attackers was identified.
Police are investigating recent attacks, and a cybersecurity company has suggested one may be linked to a 26-year-old man in China, who denies involvement.
Lawmakers say South Korea needs better tools to trace attack routes and identify attackers, as AI-assisted hacking grows.
South Korea recorded 18 suspected overseas-origin hacking incidents at financial companies from 2024 through October 8, 2026, according to data submitted by the Financial Supervisory Service.
Investigators identified the attackers in two of the 18 cases; in the other 16, 13 were linked only to IP addresses estimated to be overseas and three were classified as having an unknown country of origin.
The two identified attacks targeted Seoul Guarantee Insurance in July 2025 and Baro Savings Bank in April 2026.
Among electronic financial service providers and online investment-linked finance companies, attackers were identified in one of 12 suspected overseas-origin incidents.
The Financial Supervisory Service said attackers often disguise IP addresses or route connections through VPNs, making it difficult to identify them from IP location data alone.
CrowdStrike suggested that a 26-year-old resident of China's Guangdong province might be behind recent attacks, based on records from an AI coding tool found on an attacker’s server; the person denied involvement.
- Who
- South Korean financial companies and electronic financial service providers; attackers were identified in only a small number of cases.
- What
- A review found that most suspected overseas-origin hacking incidents had no identified attacker.
- When
- From 2024 through October 8, 2026.
- Where
- South Korea; the suspected attacks were traced to overseas IP addresses in some cases.
- Why
- Attackers often disguise IP addresses or use VPNs, making it difficult to identify who is responsible.
This story does not have two clearly opposing sides.
In most cases, attackers disguise IP addresses or route connections through VPNs, so it is virtually impossible to identify the attacker based only on the country information associated with an IP address.
Building an AI-based defense system to respond to hacking is urgent.
Because attackers can route or disguise IP addresses, it is difficult to identify them based only on overseas IP addresses. Developing technology to trace attack routes and identify the actual attackers is becoming important.
This story does not have a timeline yet.
- Suspected incidents at financial companies
- 18 from 2024 through October 8, 2026
- Cases with identified attackers at financial companies
- 2
- Other financial-company cases
- 13 had overseas locations inferred from IP addresses; 3 were classified as having an unknown country of origin
- Electronic finance and online investment-linked finance incidents
- 12, with an attacker identified in 1 case
- Identified ransomware groups
- GUNRA targeted Seoul Guarantee Insurance in July 2025; INC Ransom targeted Baro Savings Bank in April 2026
- IP addresses shared by the regulator
- 28 unique attack IP addresses, shared with some country information











