|
|
1월부터 문 두드린 AI 해커… 금융사 '공동 보안 경보' 가동 안됐다
Financial Sector's Joint Alert System Missed Early AI Hacking Attempts
경보 발령도 공격 탐지도 늦어
IPs linked to recent breaches accessed banks since January but weren't shared, delaying alerts until Shinhan Bank leak
최근 유출과 연관된 IP들이 1월 이후 은행에 접근했지만 공유되지 않아, 신한은행 유출 사건까지 경고가 늦어졌다
유준호 기자 입력 2026.10.07. 00:47 조선일보
신한은행 유출 사고 뒤 전 금융권 공유
KB국민은행 공격 인지까지 68시간 소요
금감원 8일까지 전 금융회사 자체 점검 요청
금융감독원은 최근 금융권에서 발생한 인공지능(AI) 해킹 추정 공격과 관련해 공격에 사용된 인터넷주소(IP) 33개를 특정해 금융권에 전파했다고 6일 밝혔다. 이날 서울 시내 한 건물에 설치된 주요 시중은행 현금 자동입출금기(ATM) 모습. /뉴시스
최근 동시다발로 불거진 금융권 AI(인공지능) 해킹에 쓰인 일부 인터넷주소(IP)가 대규모 개인정보 유출 사고가 터지기 8개월 전인 지난 1월부터 인터넷은행 등의 서버에 접근했던 것으로 나타났다. 당시 인터넷은행들은 공격을 막았지만, 이 정보는 금융권 전체에 공유되지 않았다.
같은 IP가 여러 금융회사를 두드리고 있었는데도 이를 하나의 위험 신호로 묶어내지 못한 것이다. 결국 신한은행에서 대규모 정보 유출이 터진 뒤에야 전 금융권이 공격 IP를 공유해 전수 점검에 나섰고, 이 와중에 과거 인터넷은행 등에 대한 접근 흔적이 발견됐다. 해킹에 대한 금융권 ‘공동 경보’ 체계의 허점이 드러난 것이다.
6일 금융권에 따르면, 최근 신한은행 공격에 사용된 IP 가운데 미국 소재 IP 2개는 지난 1월 24일 토스뱅크 서버에도 세 차례 접근했다. 같은 IP는 7, 8월에도 11차례 토스뱅크에 추가 접근을 시도했다. 토스뱅크가 이를 모두 차단하면서 개인정보 유출 등 실제 피해는 발생하지 않았다. 또 일부 IP는 올해 1월부터 카카오뱅크에도 수차례 접근했다. 카카오뱅크는 보안 체계를 통해 탐지·차단했다. 7월에는 같은 IP로 케이뱅크에도 접속 시도가 확인됐으나, 접속 시도로 인한 피해는 없었다.
그래픽=김의균
◇공격은 막았지만 ‘공동 경보’는 없었다
문제는 이처럼 한 금융회사가 해킹 공격을 막아낸 뒤 남은 흔적이 금융권 전체의 경보로 이어지지 않았다는 데 있다.
이번 연쇄 AI 해킹에서 금융권의 공동 대응이 본격적으로 시작된 것은 지난 1일 신한은행에서 개인정보 유출 사고가 확인된 뒤였다. 금융당국은 신한은행 사고 직후 공격에 사용된 IP들을 은행 등 다른 금융회사들에 공유했고, 각 금융회사는 그제야 해당 IP가 과거 자사 시스템에도 접근했는지 접속 기록을 다시 확인해 추가로 이상 징후를 찾아냈다.
다만, 이미 금융권에는 사이버 위협이 발견되면 정보를 공유하는 체계를 갖추고 있다. 금융보안원은 2023년부터 금융권에서 포착되는 침입 정보를 모아 의심 IP와 악성 접속경로(URL), 악성파일 등을 분석하고 이를 금융회사들 사이에 실시간으로 공유하는 ‘차세대 금융보안관제’ 서비스를 운영하고 있다.
하지만 금융보안원 관계자는 “(1월) 당시 각 은행에서 정보유출 등 실제 침해사고로 이어지지 않았기 때문에 보고하지 않은 것으로 보인다”며 “통상 시스템 장애나 개인정보 유출 등 실제 침해사고가 발생하거나, 새로운 악성코드·공격 수법처럼 중요성이 큰 위협이 확인됐을 때 관련 정보가 공유되는 상황”이라고 했다.
해킹 전문가 박찬암 스틸리언 대표는 “실제 사고가 나기 전이라도 반복적으로 포착되는 수상한 IP나 새로운 공격 수법은 신속히 공유할 수 있도록 기준을 정교하게 만들 필요가 있다”고 했다.
◇공동 경보도, 은행 자체 탐지도 늦었다
금융권 전체 경보가 늦게 울렸을 뿐 아니라 실제 정보가 유출된 은행들이 공격 사실을 알아차리는 데도 상당한 시간이 걸렸다. AI 해킹의 특징이 다양한 취약 지점을 은밀하게 찾아서 빠른 속도로 공격한다는 건데, 이런 해킹 추세에 느린 속도로 대응한 것이 문제점으로 지적된다.
국회 정무위원회에 제출된 자료에 따르면, KB국민은행은 지난달 27일 오후 11시 19분 처음 공격을 받은 뒤 약 68시간이 지난 30일 오후 7시쯤에야 이를 인지했다. 공격은 29일 오후 6시쯤까지 43시간가량 이어졌고, 공격이 종료 뒤에도 약 25시간 동안 침입 사실을 알아채지 못했다.
신한은행은 28일 오후 6시 4분 비정상 접근이 시작된 뒤 15시간쯤 지나서야 이상 징후를 감지했고, 고객정보 유출 사실은 공격 시작 약 25시간 뒤인 29일 오후 7시 3분쯤 파악했다. 공격을 완전히 차단한 것은 30일 오전 0시 15분이었다. 하나은행도 최초 공격에서 인지까지 41시간 44분이 걸렸다.
현행 규정상 금융회사는 침해사고를 인지하면 24시간 안에 금융당국에 최초 보고해야 한다. 하지만 금융회사가 공격 자체를 뒤늦게 알아차리면 당국 보고와 다른 금융회사에 대한 경보도 함께 늦어질 수밖에 없다.
◇금감원, 공격 IP 33개 공유
AI 해킹 피해가 확산하자 금융당국은 뒤늦게 공격 흔적을 한데 모아 금융권 전체에 전파하고 있다. 금융감독원은 6일 최근 금융권 침해사고와 관련해 해킹에 사용된 것으로 파악된 IP가 현재까지 총 33개이며, 중복을 제외하면 28개라고 밝혔다.
금감원과 금융보안원은 이 IP와 확인 가능한 일부 국가 정보도 전 금융권에 공유했다. 금감원은 이 IP 목록을 토대로 전 금융회사에 8일까지 자체 점검과 미흡 사항에 대한 조치를 마치라고 요청했다.
5일 기준 공격 IP는 미국, 일본, 중국(홍콩), 싱가포르, 베트남, 태국, 말레이시아, 스페인, 일본, 라트비아, 스웨덴, 독일 등 12국에 흩어져 있었다.
다만 금융당국 관계자는 “IP 소재지가 곧 공격자의 실제 위치나 국적을 뜻하는 것은 아니다”라고 했다. 해외 서버 등을 거쳐 공격할 경우 얼마든지 IP 소재지를 우회할 수 있기 때문이다.
금융위원회, 금융감독원 등을 출입하고 있다. 은행과 보험, 카드 등 금융업권 전반을 취재한다. 367회·404회 이달의 기자상(경제보도 부문)을 수상했다.
-------------------------------------------------------------------------------------------------------------------------------------------
Financial Sector's Joint Alert System Missed Early AI Hacking Attempts
IPs linked to recent breaches accessed banks since January but weren't shared, delaying alerts until Shinhan Bank leak
| By Yu Jun-ho Published 2026.10.07. 00:47 The Chosun Daily Newspaper / 조선일보 Some internet protocol (IP) addresses used in recent simultaneous AI (artificial intelligence) hacking incidents targeting the financial sector were found to have accessed servers of internet-only banks as early as January, eight months before the large-scale personal information leak. At the time, the internet-only banks successfully blocked the attacks, but this information was not shared across the financial industry. Although the same IPs had targeted multiple financial institutions, they were not identified as a single threat signal. Only after the massive data breach at Shinhan Bank did the entire financial sector begin sharing the attack IPs for a comprehensive review, during which traces of past access attempts to internet-only banks were discovered. This exposed vulnerabilities in the financial sector’s “joint alert” system for cyberattacks. According to financial authorities on October 6, two U.S.-based IPs used in the recent Shinhan Bank attack had accessed Toss Bank’s servers three times on January 24. The same IPs attempted additional access 11 times in July and August. Toss Bank blocked all attempts, preventing any personal information leaks. Some IPs also repeatedly targeted Kakao Bank since January, but the bank detected and blocked them through its security system. In July, access attempts via the same IPs were detected at Kbank, though no damage occurred. ◇Attacks Blocked, but No Joint Alert Issued The issue lies in the fact that traces left after a financial institution successfully repelled an attack were not relayed as alerts to the entire sector. The financial industry’s coordinated response to the recent AI hacking incidents began only after Shinhan Bank confirmed the data leak on October 1. Financial authorities shared the attack IPs with other financial companies immediately after the Shinhan Bank incident, prompting each institution to review its access logs and identify additional anomalies. However, the financial sector already has a system for sharing cyberthreat information. Since 2023, the Financial Security Institute has operated a “Next-Generation Financial Security Monitoring” service, which collects intrusion data from the financial sector, analyzes suspicious IPs, malicious URLs, and files, and shares this information in real time. A Financial Security Institute official explained, “Since no actual breaches or information leaks occurred at the time (in January), the incidents were likely not reported. Typically, information is shared only when actual breaches like system failures or personal information leaks occur, or when significant threats such as new malware or attack methods are identified.” Park Chan-am, representative of Stealien, a cybersecurity firm, stated, “Even before actual incidents occur, there is a need to refine criteria for swiftly sharing suspicious IPs that are repeatedly detected or new attack methods.” ◇Delayed Joint Alerts and Internal Detection Not only were sector-wide alerts delayed, but the banks that suffered data leaks also took considerable time to detect the attacks. A key characteristic of AI hacking is its ability to stealthily exploit vulnerabilities and attack rapidly, yet the slow response to such attacks has been identified as a critical issue. According to data submitted to the National Assembly’s National Policy Committee, KB Kookmin Bank was first attacked on September 27 at 11:19 p.m. but did not detect the breach until 7:00 p.m. on September 30, approximately 68 hours later. The attack lasted around 43 hours until 6:00 p.m. on September 29, and the bank remained unaware of the intrusion for another 25 hours after the attack ended. Shinhan Bank detected abnormal access starting at 6:04 p.m. on September 28, approximately 15 hours after the attack began. It identified the customer data leak at 7:03 p.m. on September 29, roughly 25 hours after the attack started, and fully blocked the attack at 12:15 a.m. on September 30. Hana Bank took 41 hours and 44 minutes from its first attack to detection. Under current regulations, financial companies must report breaches to authorities within 24 hours of detection. However, delayed detection by institutions inevitably delays both regulatory reporting and alerts to other financial companies. ◇FSS Shares 33 Attack IPs As AI hacking damages spread, financial authorities have belatedly compiled attack traces and disseminated them across the sector. The Financial Supervisory Service (FSS) announced on October 6 that a total of 33 IPs—28 unique ones—had been identified as used in recent financial sector breaches. The FSS and the Financial Security Institute shared these IPs and partial country information with all financial institutions. Based on this list, the FSS requested all financial companies to complete self-inspections and address deficiencies by October 8. As of October 5, the attack IPs were scattered across 12 countries, including the U.S., Japan, China (Hong Kong), Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, Sweden, and Germany. A financial authority official noted, “The location of an IP does not necessarily indicate the attacker’s actual location or nationality, as attackers can easily bypass IP origins by routing through overseas servers.” · This article has been translated by Upstage Solar AI. |
21세기 영어교육연구회 / ㈜ 파우스트 칼리지
Phone : (02)386-4802 / (02)384-3348
E-mail : faustcollege@naver.com / ceta211@naver.com
Twitter : http://twitter.com/ceta21 21세기 영어교육연구회
Web-site : www.faustcollege.com (주)파우스트 칼리지
Cafe : http://cafe.daum.net/21ceta 21세기 영어교육연구회
Band : http://band.us/@ceta21 21세기 영어교육연구회
Blog : http://blog.naver.com/ceta211 21세기 영어교육연구회
|
|
