
Opposition lawmakers criticized the government's handling of recent hacking attacks on financial firms during a parliamentary audit, saying the response had been inadequate because agencies worked in silos.
Rep. Choi Hyung-doo of the People Power Party said at the National Assembly Science, ICT, Broadcasting and Communications Committee's audit of the Ministry of Science and ICT on the 6th that the hacking of financial firms "is not a matter for the Financial Services Commission or the Financial Supervisory Service but, under the government's structure, a matter for the Ministry of Science and ICT." He added: "On an issue where even the president has called for a thorough investigation, the Ministry of Science and ICT, as the lead agency responsible for cyber hacking and cybersecurity in science and technology, cannot say this falls outside its remit and belongs to the Financial Services Commission." He also said the barriers between ministries that the government pledged to remove in last year's cross-agency information protection package remain in place, and that "in an era of AI-driven hacking, standing by on the excuse of jurisdiction means giving up its own qualification as the lead ministry."
Rep. Seo Cheon-ho, also of the People Power Party, said, "The Ministry of Science and ICT must accept its responsibility as the lead agency for hacking response," noting that response systems are divided by agency and that there is no government-wide task force.
In response, Bae Kyung-hoon, deputy prime minister and minister of science and ICT, said, "The Ministry of Science and ICT will take the lead in managing and responding to breach incidents and will step up efforts to pass information on to companies and across ministries." He said the ministry is working to improve its response to cybersecurity breaches, including raising its information protection budget by 44% from a year earlier.
Bae also said, "The revised Information and Communications Network Act took effect only recently, so its effectiveness is not yet immediately visible, but clear results will emerge going forward," adding that the government "will also strengthen punitive and economic sanctions." Under the amended act, which took effect on the 1st of this month, authorities can conduct on-site investigations immediately when signs of hacking are detected, even without a separate report from the company.






