News

Seven Korean Banks and Lenders Were Breached in One Week, and Investigators Found a Chinese AI Hacking Tool

South Korea's banks locked the vault and an AI-assisted intruder walked in through the side doors staff and loan brokers use, hitting seven firms in five days.

Seven Korean Banks and Lenders Were Breached in One Week, and Investigators Found a Chinese AI Hacking Tool

Between 27 September and 1 October, intruders got into seven South Korean financial firms, and investigators now believe they had an AI penetration-testing tool doing part of the work. Nobody broke into internet or mobile banking. The attackers went around it, through the less-protected systems that employees, outsourced staff and loan brokers use every day.

Shinhan Bank took the biggest hit among the major banks. Loan application data on about 25,000 people leaked through a loan-agent inquiry service, including names, phone numbers, annual income and calculated borrowing limits. The bank disclosed it on Wednesday, 30 September.

The list grew fast. The Korea Herald counts 153 people at KB Kookmin, 89 cases at Hana Bank through an employee sales-support system, 11 outsourced workers at BNK Busan Bank, about 40,000 people at Yegaram Savings Bank, 2,200 corporate clients at Welcome Savings Bank and 146 people at Hyundai Capital. Woori Bank and NH NongHyup spotted attempts and blocked them. No monetary losses have been confirmed.

The AI angle surfaced when the Korea Financial Security Institute went through Shinhan's attacker IPs and logs and found traces of ARTEX AI, an open-source, LLM-based autonomous penetration-testing platform distributed on GitHub for Chinese-speaking users. It picks its next move based on what worked before, and it won a Baidu-led "Agent+" offense and defense challenge this year. Genians Security Center's Moon Jong-hyun found the string "ARTEX-自主渗透試控制台" in the HTML titles of a server believed to have been used in the attack, and the FSI's own probe backed up that suspicion.

Officials are careful on two points. A human attacker drove the tool; it was not hacking on its own. And because ARTEX is public and the traffic hopped through IPs in Korea, the US, Japan, Hong Kong, Singapore, Vietnam, Thailand and the UK, they say attribution to any country is impossible.

The most uncomfortable detail is how the other victims found out. The FSI shared Shinhan's attacker IPs across the sector, and several firms only discovered their own intrusions after checking their logs against that list. Accounts differ on whether a single IP touched all seven or the banks and the savings lenders saw different addresses with similar methods, but the playbook looked the same.

Financial Services Commission chair Lee Eok-won convened an emergency meeting on Sunday. "We cannot rule out the possibility of attacks using AI," he said. He added that nothing seen so far could be used for payments, but the stolen data could feed voice phishing and fraudulent texts, and he ordered firms to cut external access to systems unless it is essential. The Financial Supervisory Service wants emergency inspections finished by Thursday, 8 October, President Lee Jae Myung ordered a thorough investigation, and the police Cyber Bureau is on the case.

Money is already part of the argument. Shinhan's 2026 security budget of 40.59 billion won (about $30.2 million) is the lowest of the big four, against 86.07 billion at KB, 63.63 billion at Hana and 61.56 billion at Woori.

Agentic tools keep showing up on the wrong side of these incidents, from the OpenAI agent at the center of Australia's Medicare hack to the AI agents that walked off with 600,000 credit cards from online stores. Korea's week shows what that looks like against banks: not a smash on the front door, but a patient machine trying every side entrance until one opens.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free