South Korea Bank Breaches Traced to Open-Source AI Tool

TL;DR: South Korea confirmed coordinated breaches at seven financial institutions between September 27 and October 1, 2026, exposing about 66,000 people and 2,200 corporate records. Investigators traced the attacks to ARTEX, an open-source AI penetration-testing tool, with a human operator driving it.

South Korea's banking sector just absorbed the clearest demonstration yet of what offensive AI tooling does to a mature financial system: a single open-source project, publicly posted to GitHub in July, was used to break into internal systems at seven lenders over one working week in early October 2026. The confirmed toll is about 66,000 individuals plus 2,200 corporate records, and the entry point in every case was the same blind spot, employee and partner portals rather than the mobile banking apps that customers actually use.

This article reconstructs what Korean regulators and police confirmed on October 6, how the attack chain worked inside the banks, what the ARTEX tool actually is and where it came from, what each institution lost institution by institution, why record security spending failed to hold this perimeter, and what the national response and the open questions look like from here.

What South Korea Confirmed

South Korea's regulators, police and cybersecurity agency now describe one coordinated campaign rather than a scattering of unrelated incidents: between Sunday September 27 and Thursday October 1, 2026, seven financial institutions were breached, and by Sunday October 4 the combined exposure stood at about 66,000 individuals and 2,200 corporate records. The confirmed list is four commercial banks (Shinhan, KB Kookmin, Hana and BNK Busan), two savings banks (Yegaram and Welcome) and one capital company (Hyundai Capital), with the Korea Herald reporting on October 6 that police had opened a full-scale probe into all seven.

The per-firm counts are small in absolute banking terms but unusually precise, because each institution disclosed its own number. Shinhan Bank, the largest exposed, reported 25,729 affected customers whose data passed through a loan-agent inquiry service used by loan solicitors. Yegaram Savings Bank reported about 40,000 affected individuals, the largest single-institution toll. Welcome Savings Bank estimated up to 2,200 records of corporate customers possibly leaked, including company names, account-manager names, email addresses and phone numbers. KB Kookmin reported 119 records from an employee mobile work-support system, Hana Bank 89 records from an employee sales-support system, BNK Busan information on 11 contract workers, and Hyundai Capital 146 mortgage loan solicitors whose names, contact details, email addresses and national ID numbers were taken.

Two larger lenders drew a different line. Woori Bank and NH NongHyup Bank were targeted in the same campaign but repelled the attacks with no confirmed data loss, because the specific vulnerabilities the attacker sought were absent at those firms. That gap also exposes a reporting asymmetry: Korean rules do not require institutions to publish incidents when no damage occurs, so the boundary between the seven breached firms and the ones that held is inherently incomplete.

Three confirmations elevated the case above ordinary breach reporting. The Korea Financial Security Institute tied the attacks to a specific tool and said so on the record. The Financial Supervisory Service circulated attack infrastructure to every financial firm for internal checks. And on October 6 the Korean National Police Agency assigned 28 investigators across four teams from its cyberterrorism unit, while President Lee Jae-myung ordered a thorough investigation and called for accelerating the development of cybersecurity-specific AI. The national cyber alert level moved from Caution to Watch the same week. What remains unconfirmed is who operated the tool, a question the next sections take up carefully.

Inside the Attack

Every confirmed intrusion shares one structural feature: the attacker never touched customer-facing internet or mobile banking. The hits landed on internal employee or partner-facing systems, a pattern investigators at Herald Business reported on October 3 and that each bank's own disclosure confirms. Shinhan's exposure ran through a loan-agent inquiry service used by loan solicitors. KB Kookmin's ran through an employee mobile work-support system. Hana's came from its ODS employee sales-support system. BNK Busan recorded attack attempts against its web servers that reached contractor records, and the savings banks lost data through internal inquiry services rather than consumer channels. Security on the customer-facing side has been enormously strengthened after a decade of financial regulation; the employee-facing side had been managed less rigorously.

The entry technique was credential stuffing plus parameter manipulation, the oldest playbook in web abuse, executed at unusual speed. Stolen or guessed credentials were replayed against internal portals, and where a page trusted its own parameters, the attacker simply moved them. The Korea Financial Security Institute confirmed the pattern while stress-testing it: a tool was used, but a human directed every step. That distinction matters because it explains the dwell times. Shinhan's initial intrusion began on September 28 and was not detected until the next morning, more than 15 hours after first access, with total dwell time of about 30 hours from first breach to blocked connection. KB Kookmin took roughly 43 hours to detect after first access. Hours, not weeks, but long enough to enumerate what an internal system holds.

The campaign itself was compressed into one working week, Sunday September 27 through Thursday October 1, with two to three attacker IP addresses overlapping at each bank. That overlap is how investigators linked the seven firms into a single operation, but it is also where the defensive limit appears: when one IP is blocked, the attacker switches to another. Regulators circulated 28 IP addresses for internal checks and simultaneously cautioned that IPs do not necessarily reveal where attackers are based. Blocking addresses, as one analysis put it, is little more than emergency first aid, because the method behind them stays identical after each block.

Read together, the mechanics say something uncomfortable about target selection. The attacker did not defeat the banks' strongest controls; they probed many institutions and pierced the ones with the weakest peripheral defenses, then stayed inside long enough to pull data out through ordinary authenticated pages. The scale of the breach, tens of thousands rather than tens of millions, is as much a story about what was hardened as about what was taken.

What ARTEX Actually Is

ARTEX is an open-source, LLM-based autonomous penetration-testing system distributed primarily through GitHub. It is designed to run reconnaissance, vulnerability discovery, attack-path planning, security-tool execution and result verification without continuous human direction, which is what makes it useful to legitimate testers and dangerous in the wrong hands. GitHub records show the project was released on July 26, its latest version was published on September 24, and the attacks on KB Kookmin began on September 27, three days later. The developer is known only by the GitHub ID Autumn-27. On September 3, before the bank campaign, ARTEX took overall first place among some 150 teams at a cyber offense-defense competition hosted by China's Baidu, which is how the project first drew attention.

The tool's fingerprints showed up in two independent places. First, an HTML title string reading ARTEX autonomous penetration testing console was found on a web server used in the credential-stuffing attacks, reported on October 2 by Genian Security Center head Moon Jong-hyun. Second, and more definitively, the Korea Financial Security Institute confirmed ARTEX AI was the tool used after tracing attack IPs and server logs from Shinhan Bank. Its statement carried the caveat that governs the whole story: it is true that AI was used in the attacks, but the AI did not act independently without human involvement, a hacker used the AI as a tool.

Where the infrastructure points is now well mapped. Oasis Security said its AGATHA threat-intelligence platform identified 359 unique ARTEX-related IP addresses across 14 countries and regions from data collected September 23 to October 3. The distribution is heavily concentrated: United States 236 servers (65.7%), China 53 (14.8%), Hong Kong 39 (10.9%), Singapore 12 (3.3%), Japan 5 (1.4%) and South Korea 4 (1.1%), with 328 servers, 91.4% of the total, in the United States, China and Hong Kong combined. That distribution is exactly why the expert caution against over-reading geography holds: the 359 ARTEX-related IPs spread across 14 countries are infrastructure, and the 91.4% concentration in three jurisdictions tells you where servers were rented, not who gave the order.

Two named experts put the limits on the record. Korea Financial Security Institute head Park Sang-won said the attack IPs used against the banks were almost identical while savings-bank IPs differed, and that ARTEX being open-source worldwide makes IP-based attribution impossible, with attacks leveraging IPs from 8 countries. Korea University professor Kim Seung-joo cautioned that it has not been confirmed whether ARTEX was the only tool used, so no one should conclude at this point that Chinese AI did the hacking. The origin of a tool and the identity of its operator are separate facts, and only the first is established.

The Numbers: Who Lost What

The fact that every attack landed on internal employee and partner systems is what caps the confirmed toll at about 66,000 people rather than the banks' entire customer bases: peripheral targeting explains the scale. The tables below unpack that toll three ways, institution by institution, day by day across the campaign window, and infrastructure by country, before the headline figures that regulators are working from.

InstitutionConfirmed exposureSystem reached
Yegaram Savings Bank40,000savings-account inquiry service
Shinhan Bank25,729loan-agent inquiry service
Welcome Savings Bank2,200corporate-customer records
Hyundai Capital146mortgage loan solicitor records
KB Kookmin Bank119employee mobile work-support system
Hana Bank89ODS employee sales-support system
BNK Busan Bank11contractor records via web servers

Two observations survive the arithmetic. Yegaram's roughly 40,000 is nearly twice Shinhan's 25,729 even though Shinhan is the far larger bank, because the savings bank's internal inquiry service exposed a wider personal-data set per record. And the corporate-only loss at Welcome, up to 2,200 records of business customers, sits outside the individual count entirely, which is why the combined figure is always quoted as about 66,000 individuals plus 2,200 corporate records rather than a single number.

DateEvent
September 27Campaign begins (Sunday to Thursday window)
September 28Shinhan initial intrusion, detected next morning
October 1Campaign window closes
October 2ARTEX console string first reported on attack server
October 4Combined exposure reaches 66,000 individuals
October 6Police probe launched, 28 investigators assigned

The chronology shows how fast the whole operation ran: first access to full public confirmation inside ten days, with the bulk of the intrusions compressed into a single working week. The dwell-time numbers from individual banks, about 30 hours at Shinhan and roughly 43 hours at KB Kookmin, fit inside that window and show the attacker moving between firms rather than living inside one.

Country or regionUnique IPs
United States236
China53
Hong Kong39
Singapore12
Japan5
South Korea4
MeasureFigure
Financial institutions breached7
Individuals affected66,000
Corporate records2,200
ARTEX-related unique IPs359

The infrastructure table is the campaign's clearest fingerprint: 236 of 359 unique ARTEX-related IPs in the United States, with 91.4% of the total sitting in the United States, China and Hong Kong combined, and only 4 in South Korea itself. Attack origins and server rentals are different things, and the regulators who circulated 28 attack IP addresses for bank checks said the same. What the four tables establish without interpretation is the shape of the event: one campaign, seven firms, a ten-day arc, and infrastructure scattered across 14 countries while the data walked out through employee doors.

Why the Money Did Not Hold the Perimeter

The most uncomfortable number in this episode is not a leaked record count. Shinhan Bank, KB Kookmin Bank and Hana Bank together spent nearly 124 billion won, about $92 million, on information security last year, and all three were still breached through internal systems. The money was real and the outcome was real at the same time, which is only contradictory if the spending and the exposure were aimed at the same target. They were not.

The fact that nearly 124 billion won of annual security spend at the three biggest banks coexisted with the neglected employee-facing systems the attacker actually used is the whole lesson: spend did not equal coverage. Korean banks hardened customer-facing electronic financial services under years of regulatory pressure, from one-time passwords to device binding, while internal employee and partner portals, the systems behind loan-agent inquiries and sales-support consoles, had been managed less rigorously. Attackers read that asymmetry instantly. The credential-stuffing wave did not test the hardened door; it walked around the building.

The regulatory environment then tilted the balance further, with the best of intentions. Regulators have run an emergency network-separation relaxation for AI security testing since June, and phase two expanded this month to 75 firms, up from 49 firms in the first phase, so that Korean institutions can actually run AI tools against their own perimeters. That policy concedes the central point: strict separation rules had made realistic testing so expensive that institutions could not measure the exposure they now have. The trade-off is speed versus coverage. Loosen the walls and defenders can finally test with the same tooling attackers use; keep them tight and the gap between customer-facing strength and internal weakness stays invisible until someone else finds it.

Scale of spending also does not fix detection latency. The Microsoft figure cited across Korean industry coverage, that 41% of security alerts are left unattended without investigation as AI-powered attacks ramp up, describes a triage problem no budget line solves by itself. Shinhan's roughly 30 hours of dwell time and KB Kookmin's 43 hours are consistent with teams that had the telemetry but processed it at human speed against an opponent compressing reconnaissance, exploitation and exfiltration into the same afternoon. Experts making the case for AI-speed defense are not arguing that more tools replace judgment; they are arguing that unattended alerts are now the most expensive line item in a security program.

The perimeter conclusion is therefore specific, not sweeping. Korean banking's customer-facing controls largely did their job, the money behind them was substantial, and the breach still happened because coverage, not budget, defines a perimeter. The institutions that repelled the campaign, Woori and NH NongHyup, did so because the vulnerabilities the attacker sought were absent, which is a coverage outcome, not a spending outcome.

The National Response

Korea's response now runs through five institutions, each with a distinct mandate and, for the first time this month, a shared timeline. The Korean National Police Agency assigned 28 investigators across four teams from its cyberterrorism investigation unit and launched a full-scale probe on October 6, the first time the campaign has been treated as a coordinated criminal investigation rather than a set of separate corporate incidents. President Lee Jae-myung ordered a thorough investigation and said the country should accelerate development and deployment of artificial intelligence technologies specialized in cybersecurity, calling it time to overhaul the society's security paradigm for the AI era.

On the regulatory side, the Financial Supervisory Service identified 28 IP addresses linked to the hacking attempts, shared them with financial firms and asked for internal checks by Thursday, while cautioning that IPs do not necessarily reveal where attackers are based. The alert level moved from Caution to Watch, and Korea's Internet and Security Agency activated round-the-clock response at its Internet Infringement Response Center, sending security-check advisories to 28,000 companies registered under the chief information security officer reporting regime. Threat intelligence including attacker IP addresses and malware signatures was shared through the C-TAS platform, which counts roughly 5,900 member organizations, giving the campaign's indicators a distribution channel that reaches beyond the seven breached firms.

The inspection schedule is the most concrete deadline in the response. The Financial Services Commission and the Financial Supervisory Service ordered emergency inspections on a 12-item checklist: banks and credit card companies must report results by October 6, and securities firms, insurers, savings banks and fintech companies by October 8. Savings banks are explicitly in scope, which matters because two of the seven breached firms were savings banks and their exposure, particularly Yegaram's roughly 40,000 individuals, is the largest per institution in the campaign.

What the response has not yet produced is attribution. No arrests, no named operator, and no official statement assigning the campaign to a country or a group. The police probe is structured to answer exactly that question, and the checklist exercise is structured to find how many more peripheral systems look like the seven already confirmed. Both deadlines land within days of each other, which makes the second half of October the point where this incident either stays a seven-firm story or becomes a broader audit of Korean finance's internal surface.

What Happens Next

The clearest window into how easily this class of attack repeats came from a laboratory. Soongsil University's AI Safety Research Center reproduced the attack class in a controlled virtual-bank lab: ARTEX with a local Qwen-series 27B model reached unauthenticated-access proof in about 6 minutes from a single one-line instruction, with no human intervention afterward, and the agent then viewed 100 records without authentication, all virtual customer records in the lab database. The reproduction worked through the same missing-authentication and broken-access-control class seen in the campaign, which links the lab result back to the real breaches.

Two qualifications keep that result honest. The center stressed that the 6-minute figure does not represent real financial institutions' defenses, because the target was a deliberately configured controlled test. And the demonstration's conditions, no expert skill, no frontier API model and no large-scale compute, cut both ways: they show how little an attacker needs, but also how little a defender can assume about where the next attempt comes from. Equalization is the working term in Korean security circles for this shift, and the bank campaign is its first large-scale financial-sector evidence.

The near-term risk to the people affected is fraud, not account takeover. Financial Services Commission chairman Lee Eog-weon said there is no indication that data directly usable for unauthorized payments was leaked, but secondary damage such as voice phishing and smishing using the leaked data cannot be ruled out. That is the standard post-breach profile for identity data: the records themselves do not move money, they lower the cost of convincing someone to move it for the attacker. Individuals at the seven firms should expect targeted pretext calls referencing real employer and account details, which is a reason the disclosure detail institutions released matters more than the headline counts.

Three questions decide whether this becomes a template or an outlier. First, whether the October 6 and October 8 inspection reports surface peripheral weaknesses at firms outside the seven, particularly at the fintech and securities firms filing in the second wave. Second, whether the police probe identifies an operator, which would shift the story from tool provenance back to conventional attribution. Third, whether Korean institutions convert the moment into lasting coverage of employee-facing systems, since the defense direction experts outline, behavior-based detection, autonomous defense at AI speed, and continuous testing with the same open tooling attackers used, only works if the systems being tested are the ones that actually get breached.

Key Takeaways

  • Seven South Korean financial institutions were breached between September 27 and October 1, 2026, exposing about 66,000 individuals plus 2,200 corporate records, with Yegaram (40,000) and Shinhan (25,729) carrying the largest tolls.
  • Every attack hit internal employee or partner portals rather than mobile banking, and dwell times of about 30 hours at Shinhan and 43 hours at KB Kookmin show detection running at human speed.
  • Investigators confirmed the open-source ARTEX AI penetration-testing tool was used, but experts stress a human directed it and that neither the tool's origin nor IP geography identifies the operator.
  • Police have assigned 28 investigators, inspections on a 12-item checklist are due October 6 and October 8, and the unresolved risk is secondary fraud using the leaked identity data.

FAQ

What exactly was exposed, and at which institutions?

Confirmed exposure covers about 66,000 individuals and 2,200 corporate records across seven firms: Yegaram Savings Bank (about 40,000), Shinhan Bank (25,729), Welcome Savings Bank (2,200 corporate records), Hyundai Capital (146 loan solicitors), KB Kookmin (119 records), Hana Bank (89 records) and BNK Busan Bank (11 contract workers). Woori and NH NongHyup were targeted but reported no data loss.

How did attackers get in without touching mobile banking?

They targeted internal employee and partner-facing portals, not customer channels. Credential stuffing and parameter manipulation reached systems like loan-agent inquiry services and employee sales-support consoles, which carry far weaker controls than the hardened mobile apps. That is why the confirmed losses sit in the tens of thousands instead of the banks' full customer bases.

What is ARTEX, and did AI really act on its own?

ARTEX is an open-source AI penetration-testing tool released in July 2026 that automates reconnaissance, vulnerability discovery and attack verification. The Korea Financial Security Institute confirmed its use in the campaign, while stating clearly that a human operated the tool: the AI did not act independently.

Sources

  1. Police launch major probe as suspected AI hacks sweep through banks (Korea Herald). https://www.koreaherald.com/article/10894542
  2. Exclusive: Chinese AI tool ARTEX used in wave of bank hacks, probe finds (Herald Business). https://biz.heraldcorp.com/article/10892497
  3. Ministry of Science and ICT, KISA mobilize against wave of financial sector hacks (Herald Business). https://biz.heraldcorp.com/article/10893672
  4. ARTEX hacking reproduction: 100 records in 6 minutes with a one-line command (ZDNet Korea). https://zdnet.co.kr/view/?no=20261006095704
  5. Open-Source AI Agent Hacked Seven South Korean Banks (TechTimes). https://www.techtimes.com/articles/328541/20261005/open-source-ai-agent-hacked-seven-south-korean-banks-exposing-65000-records.htm
  6. AI-powered attacks on banks expose technological lag in Korea's financial cyber defenses (Korea Times). https://www.koreatimes.co.kr/business/banking-finance/20261005/ai-powered-attacks-on-banks-expose-technological-lag-in-koreas-financial-cyber-defenses
  7. Korean finance breached by a two-month-old Chinese AI (Kyunghyang Shinmun). https://www.khan.co.kr/en/article/202610042320007
  8. AI-Powered Cyberattacks Hit Seven South Korean Financial Firms (Businesskorea). https://www.businesskorea.co.kr/news/articleView.html?idxno=278195
  9. 359 ARTEX-related unique IPs found across 14 countries and regions (DailySecu). https://www.dailysecu.com/news/articleView.html?idxno=208724
  10. Financial sector hacking spreads, signs of same attacker at seven firms (DigitalToday). https://www.digitaltoday.co.kr/en/view/110661/financial-sector-hacking-spreads-signs-of-same-attacker-at-seven-firms
  11. AI hacking armed with speed hits South Korea (DigitalToday). https://www.digitaltoday.co.kr/en/view/110775/ai-hacking-armed-with-speed-hits-south-korea-will-security-strategy-overhaul-gain-momentum
  12. South Korea probes bank breaches amid suspected AI-powered attacks (BleepingComputer). https://www.bleepingcomputer.com/news/security/south-korea-probes-bank-breaches-amid-suspected-ai-powered-attacks/
  13. AI-driven hacks on Korean banks, raising fears over customer data (Korea JoongAng Daily). https://www.koreajoongangdaily.com/korea/aidriven-hacks-on-banks-leave-customers-fearing-their-data-is-fair-game/12905416

Post a Comment

Previous Post Next Post