The network of South Korea's biggest bank Nonghyup broke down for 3 days after a suspected cyber attack, leaving tens of thousands of customers unable to access their money ,AFP reproted.

I am in charge of a bank Internet department work which our side will be held responsible for all the consequences arising therefrom in the event that something was come up as mentioned above.

Our department are suffering for server data security under the pressure of are exploring possible paths and looking for some data recovery and data loss prevention hardware for ending the stalemate.

We were merely in great complete bewilderment at the sight when inadequate information in GOOGLE was a shock to our eyes.Do you have some suggestions?

Thx.

Dani AI

Generated

Brief, practical guidance for and anyone else handling a bank outage caused by a suspected cyber incident. First priorities are containment, evidence preservation and recovery while following regulator and law‑enforcement notification rules. Avoid posting operational details publicly — and are right to flag that risk — and route procurement requests through official channels. The NIST incident‑response guide is a concise, authoritative playbook for organizing these steps (NIST SP 800‑61 Rev. 2). (csrc.nist.gov)

Immediate triage (do these now):

  • Isolate impacted network segments; prevent lateral movement but don’t destroy evidence.
  • Capture forensic evidence (memory dumps, full disk images, and centralized logs) before any reboots.
  • Preserve backup copies and mark suspected compromised backups read‑only; do not restore until validated.
  • Revoke/rotate privileged credentials and close external admin access.
  • Notify regulator/FS‑ISAC and law enforcement; engage a digital forensics firm if available.

These actions reflect CISA’s ransomware response checklist and NIST forensics guidance. (CISA StopRansomware, ). (cisa.gov)

Recovery and data‑protection controls to implement ASAP: adopt a 3‑2‑1 (or 3‑2‑1‑1‑0) strategy with immutable, air‑gapped copies; enable object/WORM locks for archives; maintain offline tape or isolated object storage for last‑resort restores; document RTO/RPOs and rehearse full restores on a schedule. For key material, use FIPS‑validated HSMs or equivalent key management. (See CISA backup best practices and vendor immutability guidance.) (cisa.gov)

Longer term: deploy layered prevention — EDR/AV + SIEM, network + endpoint DLP, strong MFA and least privilege for all admin access, microsegmentation, and regular IR/DR exercises. For protecting cryptographic keys and meeting regulator expectations, rely on validated cryptographic modules and CMVP guidance. Also document notification timelines required by your regulator and include lessons‑learned in updated runbooks. ([NIST SP 1800‑29], CMVP info). (nist.gov)

This summary is intentionally operational: containment first, preserve evidence, recover from trusted immutable copies, then harden and test.

Recommended Answers

All 5 Replies

lol

First reaction, LOL.
Second, what help do you actually want? Data recovery software or some helpful tips?
Third, after checking your profile you seems to be in China so why are you in South Korea. Or did i get that part wrong?

First reaction, LOL.
Second, what help do you actually want? Data recovery software or some helpful tips?
Third, after checking your profile you seems to be in China so why are you in South Korea. Or did i get that part wrong?

my lol reaction is because a bank security worker is on a help forum looking for suggestions on security software to use at there bank .

read the story , it starts off about a bank in south Korea being broken into ,and poster is responsible for his banks security and is looking for suggestion from a open help forum ,i just found/find it hilarious lolololol

If we just tell him won't other people know of it. That is really LOL

If we just tell him won't other people know of it. That is really LOL

or if i could create my own software for them ,and just send all there extra money to my own bank acct

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.