South Korean police trace relay addresses linked to attacks on financial firms
Investigators say many of 28 IP addresses linked to attacks on South Korean financial institutions concealed the route used by the attackers. Their identities and actual location remain unknown.
South Korean police said on October 7 that many of 28 internet protocol addresses linked to recent attacks on financial institutions were relay points that concealed the attackers’ location. Investigators are tracing the connections, including through international cooperation, as they examine breaches affecting banks in South Korea. The finding means an address’s apparent country cannot, by itself, identify where an attack began.
The Financial Supervisory Service, or FSS, identified the 28 addresses and shared them with financial companies, along with country information where available. Seoul Economic Daily reported that the figure excludes duplicate addresses. Its reporting said police had confirmed that many addresses served as intermediate connections and were still analyzing the rest. Neither its report nor Yonhap’s specified how many of the 28 were relays.
Why the 28 IP addresses do not identify the attackers
An IP address can show a point through which a connection passed without showing who controlled the original connection. The FSS cautioned that even when an address can be assigned to a country, an attacker may have connected indirectly through servers elsewhere, according to Seoul Economic Daily. Yonhap likewise reported the regulator’s warning that indirect connections could make country information misleading.
SBS News reported on October 6 that addresses linked to the attempts spanned 12 countries. It also reported the FSS’s caution that some countries could not be determined and that an identified country might represent a bypass connection. That spread therefore describes observed network addresses, not the attackers’ nationality or a confirmed place of origin. The SBS English article says it was translated by AI and may contain errors.
SBS quoted the FSS as saying it had identified 33 addresses associated with attempted hacking, which became 28 after duplicates were removed. The watchdog distributed the resulting list to financial firms with some country information, SBS reported. The list gives firms addresses to check against their systems while investigators work to establish the route behind the activity; the available reporting does not establish who operated those connections.
Which South Korean banks were affected
Yonhap reported customer-information leaks at Hana Bank, KB Kookmin Bank and Shinhan Bank amid the recent attacks. The reporting available here does not give a verified count of affected customers or a breakdown of what information was exposed at each bank. Those limits matter when assessing the scale of the breaches: the confirmed tracing finding concerns the route of the attacks, not a final accounting of their impact.
SBS separately reported that some of the same addresses associated with attacks on commercial banks also attempted to reach the servers of KakaoBank and K Bank. It said those attempts were blocked by security systems without damage. That distinction separates reported leaks at the three commercial banks from the blocked attempts against the internet-only banks; an attempted connection does not establish a breach of each institution it targeted.
How police are tracing the attack route
Police are working backward through the intermediate connections to establish how the intrusions were carried out, Seoul Economic Daily reported. The newspaper said investigators had begun international cooperation to obtain information along the route and might seek further assistance as analysis proceeds. Police also said they had secured material with help from other agencies and were using it to examine both attack methods and routes.
The National Police Agency assigned 28 officers to the case, according to Yonhap. Seoul Economic Daily reported that they are organized into four teams, with the Cyber Terror Investigation Unit designated to handle the inquiry and the head of the Cyber Terror Response Division leading it. The agency’s staffing decision shows the investigation’s scope, but it does not resolve which person or group carried out the attacks.
According to Seoul Economic Daily, police opened a preliminary inquiry into the financial-sector hacking on October 1 and converted it into a formal investigation after confirming the facts, on suspicion of a breach of South Korea’s information-network protection law. Police were also considering whether the case had to be reported to the Serious Crimes Investigation Agency. They asked the Financial Services Commission to interpret whether the affected systems qualify as electronic financial infrastructure, a question relevant to that notification requirement. Police said the jurisdiction review was not delaying evidence collection or analysis.
Sources and context
- Multiple IPs used to hide origin of recent cyberattacks against financial firmsYonhap News Agency
- Police Trace Hacking Route After Many Attack IPs Found to Be RelaysSeoul Economic Daily
- KakaoBank and K Bank Servers Also Targeted... Financial Authorities Identify 28 IPsSBS News
AI-assisted article checked against the listed sources. NewsJaws did not conduct interviews or attend the reported events.
Topics
About NewsJaws Desk
AI-assisted reporting and explainers reviewed against the linked source documents. No claim of on-scene reporting or original interviews.