September 28, 2026, Seoul. The system Shinhan Bank uses for loan agency inquiry services began coming under repeated penetration, and the attack continued for three days, with the names, phone numbers, annual income, loan limits and resident registration numbers of 25,729 customers stolen. This was the starting point of a week-long chain of attacks.
Within days that followed, the employee mobile business support system at KB Kookmin Bank was breached, leaking the information of 119 customers; Hana Bank's sales support system was hacked, affecting 89 people; the personal information of 11 outsourced developers at BNK Busan Bank was stolen; roughly 40,000 customer records were taken from Yegaram Savings Bank; the information of 146 housing loan agents at Hyundai Capital was taken; and Welcome Savings Bank confirmed it was breached but did not disclose the scale. Woori Bank and NH NongHyup Bank detected anomalous access attempts, and because their systems blocked them successfully, no customer information loss has been confirmed.
According to Yonhap News Agency, investigators found that on a server linked to the Shinhan Bank incident, the server's HTML page title contained a Chinese string meaning "AI autonomous penetration testing console," pointing to an open-source tool named ARTEX AI. Moon Jong-hyun, head of the security center at the South Korean security firm Genian, said publicly on LinkedIn that a number of threat analysts believe the intrusions involved AI-driven attack automation tools.
What ARTEX AI Is, and Why It Shows Up Here
ARTEX AI is an open-source autonomous penetration testing framework built on large language models (LLMs), published mainly in Chinese and distributed through GitHub. Its design goal is to let AI agents automatically complete the entire penetration testing workflow that previously had to be carried out manually: information reconnaissance, vulnerability scanning, attack path planning, invocation of security tools, and vulnerability verification. According to security research media reports, ARTEX AI won first place for the year in the "Agent+" attack-and-defense challenge hosted by the Baidu Security Response Center (BSRC).
That background makes this incident mean far more than a single leak. For a penetration tool that took first place in a public competition, the threshold between a benchmarking scenario and a real financial crime scene turns out to be this low.
One point deserves particular emphasis: as of now, South Korean financial authorities have not formally confirmed that ARTEX AI was used in the Shinhan case. According to South Korean officials, "AI was indeed used in this attack, but the AI did not act autonomously — the hackers were using AI as a tool." That statement draws an important boundary: this is not the autonomous AI intrusion of science fiction, but human attackers using AI tools to sharply lower the cost of attacks and speed up their pace.
What Was Breached Was Never the Core Systems
The intrusions at the seven institutions share one feature worth examining again and again: not a single core business system was breached. Everything hit was a so-called "edge system" — a dedicated inquiry port for loan agents, an employee mobile business support system, a sales support back office, outsourced developer accounts.
In an emergency meeting, Lee Eok-won, chairman of South Korea's Financial Services Commission, put it bluntly:
"No matter how solid a security system is, a single unmanaged gap can become the weak point of the entire system."
The specific vulnerabilities the investigation exposed are equally sobering: some loan information inquiry services could be accessed without identity verification; access controls on employee mobile devices were not functioning properly; and attackers exploited known vulnerabilities (not zero-day flaws) on servers to plant malware and steal log files. This was not a high-end attack; it was a failure of basic security.
The attacking IPs were scattered across many countries, including the United States, Japan, Hong Kong (China), Singapore, Vietnam, Thailand and the United Kingdom. The IPs used against commercial banks differed from those used against savings banks and capital companies, but the methods were highly similar. South Korean authorities characterized it as a "coordinated multinational intrusion."
What 40,000 People's Data Is Enough For
Officials stressed in particular that sensitive information usable for illegal payments (bank card numbers, online banking passwords) has not leaked, core transaction systems were not breached, and no financial losses have been confirmed so far. That is the lower bound of this incident.
But the upper bound is not encouraging. The leaked data combinations include names, phone numbers, addresses, annual income and loan limits, and in some cases resident registration numbers (the equivalent of South Korean ID numbers). South Korean authorities explicitly warned that this combination is enough to support secondary fraud — the success rates of targeted voice phishing (vishing) and SMS phishing (smishing) will rise significantly as a result. The names, loan records and contact details of 40,000 people amount to a high-value list for targeted fraud.
The Government's Response Timeline
On October 4, South Korean President Lee Jae-myung ordered that the matter be taken seriously, thoroughly investigated and met with countermeasures. That same afternoon, the Financial Services Commission and the Financial Supervisory Service convened an emergency meeting of the entire industry, attended by the CEOs of banks, securities firms, insurers, credit card companies, savings banks and fintech companies as well as heads of industry associations.
Regulators set specific deadlines: banks and credit card companies must complete a comprehensive security self-inspection by October 6; securities firms, insurers, savings banks and electronic financial businesses must submit their results by October 8. The scope was explicitly required to cover all externally exposed IT assets, access control status and patch remediation.
Financial authorities also pushed the attacking IPs and a security advisory to roughly 500 financial institutions, and coordinated intelligence sharing with the Korea Internet & Security Agency (KISA).
At the meeting, Chairman Lee Eok-won offered a statement of direction:
"We need to quickly build a security system that uses AI to defend against AI attacks."The weight of that sentence lies in this: it is the first time South Korean regulators have publicly and explicitly set "defending against AI with AI" as a policy direction, rather than leaving it as a purely technical discussion.
Two Key Questions Still Unresolved
First, who the attackers are. Traces of a tool labeled in Chinese appeared on the server, but ARTEX AI is a public tool that anyone can download and use; the attacking IPs are scattered across eight countries, so it is impossible to point to a specific country or organization on that basis. The cyber investigation unit of South Korea's National Police Agency has formally opened a case, but attribution takes time.
Second, how deeply the AI tool was actually involved. The evidence in hand so far is a string in the server's HTML page title — a lead, not a conclusion. There is still a considerable distance between "AI was used in the attack" and "AI was the primary attack vector."
The answers to these two questions will determine whether this incident is an "ordinary data theft that happened to use an AI tool," or one of the first genuine cases of "large-scale crime using AI attack tools."
The Meaning of the Signal
Whatever the final attribution, this incident sends a clear signal: the barrier to AI penetration tools has fallen low enough for them to be adopted in real financial crime. ARTEX AI is a publicly released, freely downloadable tool with complete documentation. The work it can automate — target reconnaissance, vulnerability scanning, attack path planning — used to require an experienced human, and can now be run concurrently against dozens of targets at extremely low cost.
Everything breached in South Korea this time was an "edge system," but those edge systems held the real data of 40,000 people. Financial institutions have long concentrated their security spending on core systems, leaving the depth of coverage for peripheral interfaces seriously inadequate. The emergence of AI attack tools gives attackers, for the first time, the ability to run carpet-style scans of these peripheral entry points at extremely low cost — no one has to watch, no one has to rest, and no one has to write a separate script for each target.
This is not AI overturning the security landscape; it is AI raising by an order of magnitude the speed at which already-existing entry points are exposed. The security self-inspection checklist South Korean regulators today demanded be completed within 48 hours should have been basic daily operations all along: map externally exposed IT assets, check patch status, and shut down unnecessary public internet access. All AI has done is make the price of "not doing these things" arrive faster.
Sources: - [South Korea probes bank breaches amid suspected AI-powered attacks - BleepingComputer](https://www.bleepingcomputer.com/news/security/south-korea-probes-bank-breaches-amid-suspected-ai-powered-attacks/) - [South Korea Orders Investigation into AI-Powered Cyberattacks - GBHackers](https://gbhackers.com/south-korea-orders-investigation/) - [South Korea Probes AI-Powered Cyberattacks - Cyberpress](https://cyberpress.org/south-korea-probes-ai-powered-cyberattacks/) - [Exclusive: Chinese AI tool ARTEX used in wave of bank hacks - The Herald Business](https://mbiz.heraldcorp.com/article/10892497) - [Multiple South Korean banks hit by hackers, personal data leaked; President Lee Jae-myung orders thorough investigation - ITHome](https://www.ithome.com)© 2026 Winzheng.com 赢政天下 | 转载请注明来源并附原文链接