NEWS

South Korean Officials Believe AI Agents Were Used to Hack Several Banks

AI agents linked to the Chinese Artex tool are suspected in breaches at Shinhan, KB Kookmin, Hana and Woori banks, exposing data on 68,000+ people.

Dylan H.

News Desk

October 6, 2026
8 min read
South Korean Officials Believe AI Agents Were Used to Hack Several Banks

South Korean Banks Breached in Suspected AI-Driven Hacking Campaign

South Korean President Lee Jae-myung said on October 6, 2026 that officials believe AI agents were used in a wave of breaches that hit at least seven financial institutions, exposing the personal data of more than 68,000 people. Investigators have pointed to Artex AI, a Chinese-developed, open-source autonomous penetration-testing tool, as the likely instrument behind the intrusions — what officials are calling the first confirmed instance of AI-agent-assisted hacking against a national financial sector.

"Signs have emerged" suggesting AI agents were deployed in at least some of the attacks, Lee told a cabinet meeting, adding that "it's now become possible to use AI to hack with ease even without specialized skills." The breaches, which first surfaced at Shinhan Bank on September 30, 2026, quickly spread to additional lenders, triggering an emergency government response, a multi-agency investigation, and a sector-wide self-inspection order covering roughly 500 financial companies.


Incident Details

AttributeValue
Disclosure dateSeptember 30 – October 6, 2026
Banks confirmed affectedShinhan Bank, KB Kookmin Bank, Hana Bank, Woori Bank (reports also cite BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank, Hyundai Capital)
Records exposedAt least 68,000 individuals; roughly 2,200 corporate records
Suspected toolArtex AI — Chinese-language, open-source autonomous penetration-testing framework
Attack techniqueCredential stuffing combined with parameter manipulation against loan-broker and customer portals
IP addresses identified28–33 attacker IPs traced by the Financial Security Institute; a separate threat-intel count found 359 IPs globally tied to Artex activity
Countries linked to infrastructureRoughly a dozen, including the US, Japan, Germany, Thailand, Vietnam, and Hong Kong
Investigating agenciesNational Office of Investigation (cyberterrorism unit), Financial Services Commission (FSC), Financial Supervisory Service (FSS), Financial Security Institute
Data types exposedNames, phone numbers, annual income, borrowing/loan history, credit card data

How the Breaches Unfolded

Initial compromise at Shinhan Bank

The incident chain began on September 30, when Shinhan Bank disclosed that an unauthorized party had bypassed identity checks in its loan-broker service, exposing personal information — names, phone numbers, and annual income figures — tied to roughly 25,000 customer loan applications. The bank issued a public apology the following day. Investigators from the Financial Security Institute traced the attacker's IP addresses and server logs from the Shinhan incident and shared those indicators across the sector, which triggered a wave of belated discoveries at other institutions reviewing their own access logs against the same IPs.

Spread to additional institutions

Within days, similar unauthorized access was confirmed at KB Kookmin Bank (reports cite exposed credit card data tied to roughly 119,000 clients), Hana Bank, and Woori Bank, with some reporting extending the pattern to smaller lenders including savings banks and consumer-finance firms. The Financial Services Commission put the combined total at more than 68,000 exposed records across confirmed institutions as of October 6, though exact per-bank figures vary across local outlets as investigations continue.

The Artex AI connection

The AI link emerged on October 2, when Moon Jong-hyun, head of the Genian Security Center, identified an HTML title string — "ARTEX-自主渗透测试控制台" ("autonomous penetration testing console") — on a web server believed to have been used in the credential-stuffing campaign. Artex AI is an open-source, LLM-based penetration-testing framework built by a Chinese security researcher known by the alias "Autumn," distributed primarily through GitHub and originally intended to help organizations find vulnerabilities in their own networks. Rather than being a standalone AI model, Artex orchestrates calls to external large language models — including Anthropic's Opus, OpenAI's GPT family, and China's DeepSeek — to automate reconnaissance, vulnerability discovery, attack-path planning, and verification with limited ongoing human direction. The tool reportedly placed first in a September competition run by Chinese technology firms to benchmark agentic AI platforms for offensive and defensive security use.

Attribution remains unsettled

Officials have been careful to separate tool identification from attacker attribution. A Financial Security Institute official said plainly: "It is correct that AI was used in the attack, but the AI did not act autonomously without human involvement." A separate government official told AFP it was "highly likely" Artex was used, while stressing that its use does not indicate the attackers themselves are Chinese — Artex is publicly available software, and the attacking infrastructure spans more than a dozen countries. No suspects have been publicly identified. Following the reports, Artex's developer updated the tool's usage guidelines to explicitly prohibit unauthorized intrusion and data theft.


Impact Assessment

Impact AreaDescription
Customer privacyNames, phone numbers, income, and loan/borrowing history exposed for 68,000+ individuals, raising risk of identity theft and impersonation fraud
Financial sector trustFirst confirmed AI-agent-linked intrusion into a national banking system; intrusions went undetected for hours to days even at South Korea's largest banks
Regulatory postureFSC suspended the second round of "network separation" deregulation that was scheduled for October 7, citing the ongoing breaches
Operational burdenRoughly 500 financial companies nationwide ordered into emergency self-inspection; 28 investigators assigned across four cyberterrorism-unit teams
Industry precedentDemonstrates that agentic AI tooling can lower the skill barrier for sustained, multi-target credential-stuffing campaigns against regulated sectors

Recommendations

For financial-sector security teams

  • Audit loan-broker and customer-facing portals for parameter-trust assumptions — the suspected technique combined credential stuffing with parameter manipulation, meaning backend systems trusted client-supplied values that should have been re-validated server-side.
  • Cross-reference authentication logs against shared IOC feeds — the Financial Security Institute's indicator-sharing is how most banks beyond Shinhan discovered their own exposure; build standing processes to ingest and act on sector-wide IOC bulletins quickly.
  • Assume AI-accelerated reconnaissance when modeling attacker dwell time — agentic tools can compress the recon-to-exploitation timeline that used to require a skilled human operator, so detection windows need to shrink accordingly.

For administrators and IT staff

  • Enforce MFA and rate-limiting on all loan-origination and account-servicing portals, not just primary online-banking logins.
  • Monitor for anomalous, high-velocity authentication attempts consistent with automated credential stuffing, and alert on bulk record access patterns rather than single-record lookups alone.
  • Treat open-source, LLM-orchestrating pentest frameworks (Artex and similar) as dual-use tooling — track their public repositories and signatures (unique HTML strings, server banners) as emerging indicators of compromise.

For affected customers

  • Monitor accounts for unauthorized loan applications or credit inquiries, since exposed data includes income and borrowing history that could support fraudulent loan applications in your name.
  • Watch for targeted phishing or impersonation calls referencing your real loan or account details.
  • Contact your bank to confirm whether your records were among those exposed, and request a credit freeze or fraud alert as a precaution.

Key Takeaways

  1. South Korean officials believe AI agents — specifically the open-source Artex AI framework — were used in breaches affecting at least seven financial institutions and 68,000+ individuals.
  2. The breach chain began at Shinhan Bank on September 30, 2026, via credential stuffing combined with parameter manipulation against a loan-broker service, and spread as shared indicators exposed similar compromises elsewhere.
  3. Artex AI is not itself a model but an orchestration layer that calls external LLMs (including Anthropic's Opus, OpenAI's GPT, and DeepSeek) to automate reconnaissance and attack planning with minimal human oversight.
  4. Officials explicitly caution that tool use does not equal attacker attribution — Artex is public software, and attacking infrastructure spans a dozen-plus countries.
  5. The South Korean government responded with a 28-investigator task force, emergency self-inspections at roughly 500 financial firms, and suspension of planned network-separation deregulation.
  6. The incident is being framed as the first confirmed case of agentic AI tooling being used to breach a national financial sector, underscoring that AI materially lowers the skill barrier for sustained, multi-target intrusion campaigns.

Sources