South Korean financial companies report that most suspected hacking attacks linked to overseas origins have unidentified attackers. A lawmaker says data from the Financial Supervisory Service show 18 such incidents since 2024 through Thursday, with attackers identified in only two cases. The remaining 16 cases involve activity tied to internet protocol (IP) addresses believed to be overseas, though the attacker location is not necessarily the same as the IP’s physical origin.

Outlets also report that investigators find multiple IP addresses used to obscure the hackers’ true whereabouts. One watchdog report cited by Yonhap and sources described by Korea Times says 28 IP addresses are connected to recent attacks, while police assess that many were used to hide the attack path. The investigation involves tracing through international cooperation and includes newly formed police resources, while earlier disclosures from the watchdog to financial firms include the IPs along with country information, alongside a warning that indirect connections are possible.

Reported ransomware incidents include a GUNRA attack on Seoul Guarantee Insurance in July 2023, which disrupted operations for about 64 hours, and an INC Ransom attack on Baro Savings Bank in April 2023.