AI-Powered Hackers Hit Seven South Korean Banks

South Korea’s financial sector is reeling from a coordinated cyberattack campaign that breached at least seven institutions in under a week, with investigators pointing to an AI-powered penetration-testing tool as the force multiplier behind the assault. The crisis has escalated to the presidential level, with President Lee ordering a full-scale probe and regulators summoning bank CEOs for an emergency Sunday session.

What Happened

Starting around October 1, attackers systematically targeted peripheral systems at South Korea’s largest banks — not the hardened core banking platforms, but the auxiliary web portals and mobile tools used by loan brokers and employees. Shinhan Bank disclosed the first breach on October 1, followed in rapid succession by KB Kookmin Bank, Hana Bank, and BNK Busan Bank on October 2. By October 3 and 4, the breach had spread to Hyundai Capital, Yegaram Savings Bank, and Welcome Savings Bank, bringing the confirmed total to seven financial institutions.

Financial regulators confirmed that identical attacker IP addresses appeared across the banking-sector breaches, strongly suggesting a single threat actor or coordinated group behind all seven incidents. The attackers rotated through IP addresses based in South Korea, the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, and the United Kingdom to complicate attribution.

The AI Angle: ARTEX and Automated Exploitation

What sets this campaign apart is the suspected use of an AI-assisted attack tool. Investigators discovered traces of a Chinese-language string in HTML code on a server linked to the Shinhan Bank attack referencing “ARTEX 自主渗透测试控制台” — an autonomous penetration-testing console. ARTEX is described as an open-source AI penetration-testing system built on a large language model, designed to automate vulnerability scanning and exploitation at machine speed.

According to investigators and a Korea Financial Security Institute official, the AI tool did not operate independently. Rather, human operators directed the campaign while ARTEX handled the repetitive, trial-and-error probing — cycling through randomized customer ID numbers and query values thousands of times faster than any human could manage. In the Shinhan Bank breach, attackers exploited a weak authentication system on the bank’s loan-agent portal and used this automated approach to extract customer records en masse.

This represents a practical escalation in threat capability. As one analysis noted, the real danger is not the specter of rogue AI systems acting on their own, but the speed disparity between AI-assisted attacks and human-paced detection. Banks took between 15 and 67 hours to detect these breaches — attacks that AI-powered tools executed in a fraction of that time.

Scope of the Damage

The customer impact varied significantly across institutions. Shinhan Bank reported roughly 25,000 affected customers, while Yegaram Savings Bank disclosed approximately 40,000 records compromised. KB Kookmin Bank confirmed 119 customers affected, Hana Bank reported 89, BNK Busan Bank saw 11 outsourced workers’ data leaked, Welcome Savings Bank had around 2,200 corporate customer records exposed, and Hyundai Capital confirmed 146 mortgage loan brokers’ information was compromised. Woori Bank and NH NongHyup Bank were also targeted but reported no data exposure.

The stolen data included names, phone numbers, addresses, resident registration numbers (South Korea’s national ID equivalent), email addresses, workplace details, annual income figures, and borrowing limits. Critically, no direct financial transaction data or account credentials were accessed, meaning the immediate risk lies in secondary fraud — phishing, voice phishing (“vishing”), and smishing campaigns that could leverage the stolen personal information.

Government Response at the Highest Level

The scale of the breach triggered an unprecedented regulatory response. On October 3, FSC Chairman Lee Eog-weon and Financial Supervisory Service Governor Lee Chan-jin convened an emergency meeting at the Government Complex in Seoul, summoning the heads of financial sector associations spanning banking, insurance, credit, savings banks, mutual finance, and fintech. The presence of both of the nation’s top financial regulators signaled an all-out response.

On October 4, President Lee escalated the matter further, ordering officials to “conduct a thorough investigation and make every effort to devise measures, with a grave awareness of the seriousness of the matter,” according to a presidential spokesperson. Police launched formal inquiries covering all affected institutions.

Regulators issued alerts to approximately 500 financial firms with staggered security review deadlines through October 8, ordering institutions to patch vulnerabilities, eliminate unauthenticated services, and tighten access controls on mobile devices. Financial companies were also directed to participate in government-led AI security testing initiatives and adopt AI-based defensive security models.

A Warning Shot for the Global Financial Sector

This campaign exposes a vulnerability pattern that extends far beyond South Korea. The attackers did not need to breach heavily fortified core banking systems. Instead, they targeted the softer periphery: loan-agent portals, employee support systems, and third-party inquiry services — areas that security teams often deprioritize. In an era where banks operate sprawling ecosystems of web applications and partner portals, every endpoint becomes a potential entry point.

The AI component amplifies this risk. Open-source penetration-testing frameworks, now augmented with large language models, lower the barrier for attackers to conduct sophisticated, high-speed campaigns. While defensive AI tools exist, the South Korean case shows that detection systems are not yet keeping pace with the speed of AI-assisted exploitation.

What to Watch and What to Do

For security teams, the immediate takeaways are clear. First, audit auxiliary and partner-facing systems with the same rigor applied to core infrastructure — authentication gaps on employee portals and loan-agent tools were the entry point here, not sophisticated zero-days. Second, reassess detection timelines against AI-speed attacks; a 15-to-67-hour detection window is untenable when automated tools can exfiltrate data in minutes. Third, monitor for credential-stuffing patterns and anomalous API query volumes, especially on systems that return sensitive customer data.

The investigation is ongoing, with police tracing the rotating IP infrastructure across multiple countries and regulators pressing financial firms to report any additional compromises. Whether this campaign is linked to a nation-state actor or a sophisticated criminal group remains to be determined. What is already clear is that AI-augmented offensive tools are no longer theoretical — they are being deployed at scale against critical financial infrastructure, and the industry’s defensive posture will need to evolve accordingly.

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.