AI attack hits 7 S Korean financial institutions, exposing over 65,000 records
Seven South Korean financial institutions, including three major commercial banks, were hit by seemingly coordinated cyber attacks within days of one another, exposing more than 65,000 customer and employee records between 28 September and 3 October.
Financial regulators say the attackers appear to have used artificial intelligence to automate attempts to penetrate one institution after another. Investigators also found that the same internet protocol (IP) addresses were used in attacks on multiple institutions, providing strong evidence that the incidents may have been carried out by the same attacker or group.
The attacks offer a striking real-world example of the threat researchers have warned about in the emerging age of “agentic AI” — systems capable of planning and carrying out sequences of tasks with limited human intervention.
Where the data was exposed
The seven affected institutions include Shinhan Bank, KB Kookmin Bank, Hana Bank, regional lender BNK Busan Bank, two savings banks and a consumer-finance company. The largest volumes of data were exposed at Shinhan Bank and Yegaram Savings Bank.
Shinhan Bank said unauthorised access to its systems occurred from the early hours of 29 September until 30 September. Customer names, telephone numbers, annual incomes and credit limits were taken from an auxiliary system used by debt-collection staff and employees. The records of 66 customers also contained national registration numbers.
The bank said its customer services and transactions were not affected and that there was no evidence of financial losses. It has blocked access from external IP addresses and temporarily suspended the affected service.
The trail leading to ‘ARTEX’
Investigators found evidence of an AI-based penetration tool at IP addresses used in the attacks.
Park Sang-won, director of South Korea's Financial Security Institute, said investigators had found signs of a tool called ARTEX at the common IP addresses.
Moon Jong-hyun, head of the security centre at South Korean cybersecurity company Genians, said a server used in recent attacks on domestic organisations contained the string “ARTEX — 自主渗透测试控制台”. The Chinese-language phrase means “automated penetration-testing console”.
According to Moon, the presence of the string suggests that ARTEX was either being operated on the infrastructure or that the environment was being used to run the tool.
ARTEX is described as an automated penetration-testing system based on large language models. Instead of manually directing each stage of a test, a user sets the target and scope and the system can handle much of what follows — developing a plan, identifying vulnerabilities and attempting exploitation. It can also use the results of one stage to select its next course of action.
The tool was developed in Chinese and is reportedly publicly available. There is, however, no confirmation that it is linked to any Chinese group or state actor.
The attackers used IP addresses associated with South Korea, the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand and Britain. They repeatedly changed addresses while attempting to access several institutions at the same time. Investigators suspect the attackers were operating from overseas.
Emergency meeting and presidential orders
As the scale of the attacks became clearer, South Korea's Financial Services Commission convened an emergency meeting on Sunday, 4 October, at the Seoul Government Complex. The meeting was chaired by FSC chairman Lee Eok-won.
Lee said there was strong evidence that AI may have been used in the attacks and that the same attacker-related IP addresses had appeared at multiple institutions. He urged the entire financial sector to treat the situation with the highest level of vigilance.
President Lee Jae-myung has ordered a full investigation and a coordinated response.
Following the meeting, regulators ordered a series of measures:
About 500 financial institutions were sent lists of the IP addresses used in the attacks, along with security alerts.
All institutions were instructed to conduct emergency inspections based on a 12-point security checklist.
Banks and card companies must complete their inspections by 6 October, while securities firms, insurers, savings banks and electronic financial-service providers have until 8 October.
Institutions were ordered to tighten device-access controls and urgently patch vulnerabilities on their websites.
The attacks have been divided into three categories, with separate response strategies assigned to each.
The Financial Supervisory Service has already begun an emergency on-site inspection at Shinhan Bank. The investigation could take several months to complete.
When defensive technology becomes an offensive weapon
For cybersecurity specialists, perhaps the most troubling aspect of the attacks is that technology developed for defence is now being used offensively.
Moon Jong-hyun said several recent attacks have involved AI tools originally developed and shared for defensive purposes. As the source code of such tools spreads freely, he said, they can become a double-edged sword.
Several sources in South Korea's banking industry believe Shinhan Bank may not have been specifically targeted. Instead, it may have been caught up in random, AI-driven attacks searching the internet for vulnerable platforms.
One banking official warned that the entire financial sector is exposed to attacks driven by AI agents.
The irony is that South Korean banks had already begun using similar technology for their own defence. An AI penetration-testing platform developed by Woori Financial Group had reduced a security assessment that previously took about two weeks to less than 12 hours. Shinhan Bank has also been using generative AI for penetration testing since June.
The same technology is now being used by attackers — and potentially allowing them to move faster than the institutions they are targeting.
A warning for Bangladesh
South Korea's financial sector is among the world's most technologically advanced, with sophisticated systems for cybersecurity and surveillance. Yet seven institutions were penetrated within a single week.
That reality should prompt uncomfortable questions about the preparedness of Bangladesh's banks and financial institutions.
The 2016 theft of $81m from Bangladesh Bank's reserves demonstrated how a weakness in one part of a financial system can be exploited to cause enormous damage. In the age of AI agents, that risk has multiplied.
An attacker no longer necessarily needs to sit at a computer and manually search for vulnerabilities. Machines can perform that work continuously, around the clock.
For cybersecurity specialists, the lesson is clear. Regular AI-assisted penetration testing, rapid sharing of intelligence on suspicious IP addresses among financial institutions, and centralised monitoring by regulators are no longer optional safeguards.
They are becoming essential defences in a financial system where the attackers, increasingly, may have machines working for them.
Leave A Comment