South Korean police expand financial hacking investigation team to 43
Police added 15 investigators as they trace attacks on financial institutions. The attacker’s identity and the scale of data loss remain unconfirmed.
South Korean police said on October 9 that they had expanded the team investigating attacks on financial institutions from 28 to 43 people. The 15 additional investigators include digital forensics specialists, as police examine how the institutions were breached and seek help across borders. The investigation concerns institutions including Hana Bank, KB Kookmin Bank and Shinhan Bank; the attacker’s identity and the full scale of the data loss remain unconfirmed.
How the South Korean police investigation expanded
The National Office of Investigation announced the larger team after police had already begun examining the affected institutions. Seoul Economic Daily reported that the task force was formed on October 5 and that additional specialists were assigned on October 7. The October 9 announcement set out the team’s new size: 43 investigators, up from 28. That is a staffing change in an investigation still underway, rather than an announced finding about who carried out the attacks.
According to Seoul Economic Daily, investigators are analyzing data and systems obtained from the financial institutions to work out the intrusion routes. The outlet also reported that police are pursuing international cooperation, including efforts to block attack servers based overseas. Yonhap likewise reported that police want to trace the path of the attacks through international cooperation. Neither account establishes that investigators have identified a suspect or completed their assessment of what was taken.
Which institutions and systems are involved
Yonhap identified Hana Bank, KB Kookmin Bank and Shinhan Bank among the institutions involved in the series of attacks. In its earlier report on a cybersecurity assessment, Yonhap said the breaches had prompted financial authorities and investigators to open inquiries. The cited reporting does not give a confirmed total for affected customers or the amount of stolen data, so the names of the institutions should not be read as a measure of each bank’s exposure.
The cybersecurity firm CrowdStrike described two types of compromised systems, according to Yonhap: a bank loan inquiry service used by financial brokers and a separate bank’s mobile work support system for employees. The account did not identify which banks operated those systems. That distinction matters for customers and staff trying to understand the reports: the available account identifies examples of systems, but does not establish the complete reach of the intrusions at any named institution.
What CrowdStrike assessed about the attacker
CrowdStrike assessed that an unidentified attacker believed to be a Chinese speaker used artificial intelligence tools against several South Korean financial institutions between late September and early October, Yonhap reported on October 8. The firm said the attacker used ARTEX, an open source penetration testing tool, alongside large language models. This is a cybersecurity firm’s assessment reported by Yonhap, not a police identification of a suspect or a finding about a state sponsor.
Yonhap quoted CrowdStrike as saying its Chinese speaker assessment had ‘moderate confidence,’ based on the use of a tool developed in China and observed Chinese language prompts. The firm said the activity had not been attributed to a named adversary. It also said the attacker’s identity, the full extent of the breaches and the amount of stolen data remained unconfirmed. The police expansion therefore comes while central questions about the intrusions are still being investigated.
Could the case move to another agency?
Seoul Economic Daily reported attention to a possible transfer of the case to the Major Crimes Investigation Agency. Under the rules described by the outlet, that agency may seek transfer of a cybercrime case it judges to be a major crime, regardless of how far another investigation has progressed. The reporting does not establish that this case will be transferred. Police said they would continue investigating until any transfer and asserted that a change of agency would cause no gap or delay.
Police also rejected criticism that their initial response had been slow. In the police account reported by Seoul Economic Daily, a pre-charge inquiry began on October 1, when the hacking was first reported, and investigators subsequently secured records and arranged cooperation with relevant organizations. Those dates and the assurance about continuity are police statements. For now, investigators say they are examining the compromised systems and pursuing the suspects; no completed attribution or final accounting of the breaches has been reported in the cited coverage.
Sources and context
- (LEAD) Police expand team investigating recent hacking of financial institutionsYonhap News Agency
- Police Expand Financial Hacking Task Force to 43 InvestigatorsSeoul Economic Daily
- Chinese-speaking hacker possibly linked to AI-driven attacks on S. Korean banks: reportYonhap News Agency
AI-assisted article checked against the listed sources. NewsJaws did not conduct interviews or attend the reported events.
About NewsJaws Desk
AI-assisted reporting and explainers reviewed against the linked source documents. No claim of on-scene reporting or original interviews.