South Korea bank breaches probed amid AI attack suspicions
South Korea's Financial Services Commission (FSC), the country's top financial regulator, called an emergency meeting after a wave of cyberattacks hit financial institutions in the country. Officials confirmed a data breach at Shinhan Bank and said that other banks, including Kookmin Bank, were also affected by security incidents.
Shinhan Bank and KB Kookmin Bank are two of South Korea's large private commercial banks. Each holds more than $400 billion in assets.
On-site investigations and new orders for the sector
Authorities said they started on-site investigations once incident reports came in. They also passed all actionable information to the relevant agencies, including KISA, which the source describes as Korea's data protection agency.
The FSC has given financial companies in the country a list of tasks. They must:
- inspect every IT system and service reachable from the outside, not just the ones customers use
- cut unnecessary information exposure and look for missing or weak authentication and access controls
- share threat information quickly and coordinate their responses
- hand in the results of their internal security inspections as soon as possible
Regulators also promised to oversee consumer protection and compensation for affected customers. They plan to analyze the incidents to see which regulatory changes are needed.
Customer data leaked at several banks
The incidents have reached the top level of government. On Sunday, local media reported that South Korea's President Lee had ordered a thorough investigation into personal data leaks at financial and public institutions.
The same reports put numbers on the damage. Shinhan Bank leaked the details of 25,000 customers, and Kookmin Bank leaked credit card information belonging to 119,000 clients.
Hana Bank was also hit, though in a more limited way. Its sales-support system was compromised, according to the reports.
A Chinese-language string and an AI pentesting tool
Official channels have said nothing about who carried out the attacks. However, Korean news agency Yonhap reported that a server used in the attacks had an HTML page title with a Chinese-language string associated with ARTEX AI.
ARTEX AI is an open-source penetration-testing system. It uses agents to automate several stages of an attack:
- information gathering
- vulnerability discovery
- attack-path planning
- running security tools
- verifying vulnerabilities
Neither the bank nor the financial authorities have confirmed that ARTEX AI was used in the Shinhan breach. The Chinese-language string also does not tie the attacks to any specific threat actor.
Still, the suspicion is shared by people in the industry. Moon Jong-hyun, head of the Genian Security Center, wrote on LinkedIn that several threat analysts believe AI-based attack automation tools were involved in the breaches.
For now, that remains an assessment, not a finding. A page title on a server is a thin piece of evidence, and open-source tools can be picked up by anyone.
The Bigger Picture
Even without confirmation, the case fits a pattern we have been tracking for weeks. Researchers recently saw AI agents aimed at US and Canadian government sites, and the Dutch vulnerability disclosure group DIVD said it was breached by an autonomous AI agent. If AI tooling played a role in the Korean bank attacks, this would be one of the more serious examples so far, given the size of the institutions and the volume of customer data involved.
The FSC's instructions are also revealing. The focus on externally reachable systems that are not customer-facing, and on missing authentication, suggests regulators suspect the attackers found forgotten or poorly protected entry points. These are exactly the weaknesses that automated scanning and exploitation tools are good at finding at scale. The Hana Bank compromise through a sales-support system points in the same direction.
For banks elsewhere, the practical lesson does not depend on attribution. Internal tools and back-office services exposed to the internet deserve the same scrutiny as online banking portals. This applies even more if, as Microsoft has argued, attackers are currently ahead in using AI.
It is worth watching whether Korean investigators confirm the use of ARTEX AI or any other automation tool. Other points to follow are whether more institutions report incidents after the mandatory inspections, and what regulatory changes the FSC eventually proposes.
