cd /news/ai-safety/hackers-hit-four-south-korean-banks-… · home › topics › ai-safety › article
[ARTICLE · art-143847] src=madrobot.blog ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Hackers hit four South Korean banks in two days, and a Chinese AI hacking tool is suspected

Hackers stole customer data from four South Korean banks — Shinhan Bank, KB Kookmin Bank, Hana Bank and BNK Busan Bank — within two days, prompting South Korea's Financial Services Commission to hold an emergency meeting on Friday and order every bank and card company to audit all externally reachable systems. Shinhan reported about 25,000 customers' names, phone numbers, annual income, calculated loan limits and 66 resident registration numbers leaked; KB Kookmin reported 119 customers, Hana 89 customers and BNK 11 outsourced-staff records. Genians Security Center head Moon Jong-hyun wrote on LinkedIn that the string "ARTEX-" appeared in page titles on web servers used in the attacks and that the pages described themselves in Chinese as an "AI autonomous penetration test console," referring to the open-source Chinese-language ARTEX AI tool that uses a large language model to run penetration tests autonomously, though neither the banks nor regulators have confirmed AI was used.

by read4 min views2 publishedOct 2, 2026
Hackers hit four South Korean banks in two days, and a Chinese AI hacking tool is suspected
Image: Madrobot (auto-discovered)

Shinhan Bank’s headquarters in Seoul, June 2019. Image: Mobius6 / Wikimedia Commons, CC BY-SA 4.0, cropped

Hackers have stolen customer data from four South Korean banks in two days, and investigators are looking at whether AI tools did much of the work. South Korea’s Financial Services Commission held an emergency meeting on Friday and ordered every bank and card company to check all of its systems that can be reached from outside its network.

The breaches hit Shinhan Bank, KB Kookmin Bank, Hana Bank and BNK Busan Bank. In each case the attackers went in through a side door, not internet banking: a loan-agent inquiry service, an employee mobile app or a sales support system.

What was taken #

Shinhan said on Thursday that information on about 25,000 customers had leaked after an attacker bypassed identity checks on a mobile service loan agents use to track applications. The data included names, phone numbers, annual income and calculated loan limits, plus 66 resident registration numbers, South Korea’s national ID numbers. Shinhan confirmed the breach on Wednesday, blocked the outside IP addresses and suspended the service.

KB Kookmin said on Friday that data on 119 customers, including names, addresses and resident registration numbers, had leaked through an employee support system after it spotted a possible breach on Wednesday night. Hana said hackers got into its sales support system and exposed personal details on 89 customers, and BNK reported that 11 records on outsourced staff had leaked, according to the Korea Herald.

All four banks say customers’ banking transactions were not affected, and Shinhan, KB Kookmin and Hana have promised to compensate any losses.

An “AI autonomous penetration test console” #

What makes this more than another data breach is the evidence pointing at AI. Moon Jong-hyun, head of the Genians Security Center at the Korean security firm Genians, wrote on LinkedIn on Friday that the string “ARTEX-” appeared in page titles on web servers used in the attacks, and that the pages described themselves, in Chinese, as an “AI autonomous penetration test console”.

ARTEX AI is an open-source, Chinese-language tool on GitHub that uses a large language model to do a penetration tester’s job on its own: gather information about a target, look for weaknesses, plan a route in, run hacking tools and check what worked. It is sold as a way to test your own defences. Moon called the traces circumstantial evidence that the tool was run on the attackers’ servers, and said multiple analysts “reasonably suspect” AI attack tools were used, according to the Kyunghyang Shinmun.

Neither the banks nor the regulators have confirmed that AI was used, and no one has said who was behind the attacks. Moon warned that the shift is already happening:

The era when attackers carried out each command themselves is passing.

Moon Jong-hyun, Genians Security Center, via the Kyunghyang Shinmun

What the regulator wants #

At Friday’s emergency meeting, FSC Secretary General Shin Jin-chang told banks and card firms to list every IT system and service exposed to the outside world, check them for weaknesses and gaps in access controls, cut the amount of information they expose and close any route to internal data that doesn’t require proper authentication. The regulator will hand out a security checklist, collect the results and share attackers’ IP addresses and methods across the industry. The Financial Supervisory Service and Financial Security Institute have sent inspectors to all four banks.

“We will thoroughly analyze the causes and methods of the attacks and swiftly develop measures to strengthen the system,” Shin said.

Why it matters #

Banks spend heavily on protecting their front doors, and these attacks went through the forgotten back rooms instead, the kind of small, exposed systems an automated tool can find and probe far faster than a person. Central banks have started warning about AI-powered cyberattacks, including the Bank of England on Wednesday; if the ARTEX traces hold up, South Korea is an early real-world example, and defenders are already reaching for AI of their own, as Palo Alto Networks’ round-the-clock Mythos service shows.

Sources: Korea Herald (FSC emergency meeting, Oct 2); Korea Herald (Hana and BNK breaches, Oct 2); Kyunghyang Shinmun (Genians analysis of ARTEX AI, Oct 2).

── more in #ai-safety 4 stories · sorted by recency
── more on @shinhan bank 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/hackers-hit-four-sou…] indexed:0 read:4min 2026-10-02 · —