주메뉴바로가기본문바로가기
비즈한국 비즈한국

Major Financial Firms Respond Differently to SKT Hacking; Concerns Raised Over Neglect of Information-Vulnerable Groups

This article was automatically translated by AI. There may be errors compared to the original Korean article.  Read original in Korean →

[비즈한국] A massive data breach at SK Telecom017670, the top mobile carrier in South Korea, has put the financial sector on high alert. Immediately following the incident, financial authorities urged financial firms to prevent secondary damages and held meetings with relevant agencies to assess the situation. In the meantime, financial firms have been guiding consumers on response measures via their websites and apps, but the varying approaches taken by each firm have drawn attention. A review of response notices from major banks, including commercial banks, regional banks, and internet-only banks, shows that while some provided detailed information on their security services, others did not even post a notice regarding the incident.

SK Group Chairman Chey Tae-won bowing after offering a public apology regarding the SK Telecom hacking incident on May 7. Photo = Reporter Park Jung-hoon
SK Group Chairman Chey Tae-won bowing after offering a public apology regarding the SK Telecom hacking incident on May 7. Photo = Reporter Park Jung-hoon

The shockwaves of the SKT hacking incident immediately hit the financial sector. There is a risk that leaked USIM information and personal data could be exploited to misappropriate financial assets, leading to secondary damage. On April 30, financial authorities, along with relevant agencies such as the Financial Security Institute, Korea Credit Information Services, and Korea Financial Telecommunications & Clearings Institute, formed an emergency response headquarters. Financial Services Commission (FSC) Chairman Kim Byung-hwan stated at a monthly meeting on the 7th, "We have been reported that there have been no cases of financial damage received in the financial sector so far."

The authorities have instructed financial firms to implement additional authentication or strengthen Fraud Detection System (FDS) monitoring if the device information of customers using mobile financial apps changes. Additional authentication will be applied to services that previously only relied on mobile phone identity verification and SMS authentication. Financial consumers have been advised to sign up for services that block non-face-to-face account opening and credit transactions.

As financial authorities take preemptive measures, financial firms are also guiding customers who use SKT on how to respond to the hacking. From April 28 to 30, financial firms posted response measures through their platforms. A review of the websites of major banks (commercial, regional, and internet-only) revealed that while some provided detailed explanations of available security services or how to respond to hacking damages, others did not even issue a notice, indicating a wide disparity in security awareness within the banking sector.

Commercial banks (KB Kookmin, Hana, Shinhan, Woori, iM Bank) and NH Nonghyup and IBK Industrial Bank mostly explained the "non-face-to-face safety block" (for account opening and credit transactions) before introducing their own security services. While the notices were similar, the level of recommended security services differed. For instance, Kookmin Bank and Nonghyup Bank limited their guidance to safety blocks or blocking mobile OTP issuance, while some other banks proactively promoted their own enhanced security services to prevent hacking.

iM Bank and Industrial Bank offered features that allow non-face-to-face financial transactions only in five specific regions (each offering "Address-based Login Restriction Service" and "Electronic Financial Usage Location Setting"). In these cases, login is restricted or electronic banking cannot be used outside the user-defined region—even within the country, not just abroad—which can block hacking attempts. Hana Bank proposed a "Forex Image Service for Phishing Prevention," which displays specific national exchange rates in the app menu to help distinguish genuine financial apps from phishing apps.

Financial Supervisory Service Governor Lee Bok-hyun (left) and Financial Services Commission Vice Chairman Kim So-young visiting the Shinhan Bank headquarters on March 12 to hear an explanation of the sign-up process for the non-face-to-face account opening safety block service. Photo = Financial Services Commission
Financial Supervisory Service Governor Lee Bok-hyun (left) and Financial Services Commission Vice Chairman Kim So-young visiting the Shinhan Bank headquarters on March 12 to hear an explanation of the sign-up process for the non-face-to-face account opening safety block service. Photo = Financial Services Commission

Among regional banks (Kyongnam, Gwangju, Busan, Jeonbuk, and Jeju Bank), some failed to provide any damage prevention guidance or offered only perfunctory explanations. JB Financial Group's Jeonbuk Bank posted prevention tips, but these only included "replace your USIM" and "check SKT notices frequently," without mentioning any financial security services. Its affiliate, Gwangju Bank, did not post any incident prevention notices for SKT users at all.

Some firms replaced direct explanations with citations. On April 28, BNK Financial Group's Busan Bank posted a notice to SKT customers stating, "Financial transactions cannot be completed with telecom authentication alone, and assets are being safely protected through FDS and additional authentication procedures," and added a link to SKT's notice while urging users "not to leak account numbers, passwords, certificates, or identification cards to third parties."

Of the three internet-only banks (KakaoBank, K-Bank, Toss Bank), only Toss Bank did not post a notice for SKT customers. Toss Securities, which uses the same platform, followed suit. However, Toss Mobile, a budget phone affiliate that uses the SKT network, did announce a sign-up for a USIM protection service. KakaoBank and K-Bank used simple notices to encourage users to utilize identity theft prevention and safety block services.

Regarding the varying levels of response to the SKT hacking incident among financial firms, a banking industry official stated, "Although there is significant concern due to the data breach, the information security level of the domestic financial industry is generally high. Because the identity verification process is stringent, it is not easy for identity theft or hacking to occur even if a customer does not sign up for a separate security service. The fact that financial authorities led the introduction of non-face-to-face credit transaction and account opening safety block services even before this incident occurred also seems to be a reason why some banks scaled back their damage prevention guidance."

However, critics point out that given the existence of information-vulnerable groups, the complacent response of some banks is regrettable. In fact, for the credit transaction safety block service, the sign-up rate among those aged 60 and older is the highest at 53%, revealing high concerns among them regarding identity theft. Previously, at a financial authority review meeting, Kwon Dae-young, Secretary General of the FSC, ordered that "the industry must respond carefully so that security blind spots, such as for the elderly, do not arise, as the SKT hacking incident could lead to not only serious damages but also social anxiety if it evolves into a financial security incident."

This article was automatically translated by AI. There may be errors compared to the original Korean article.
심지영 기자

금융, 가상자산, 핀테크, 투자 업계 중심으로 취재하고 있습니다. 언제든 제보주세요.

jyshim@bizhankook.com
저작권자 ⓒ 비즈한국 무단전재 및 재배포 금지