Skip to main content
CybersecuritySouth Korean Banks· 6 min read· in Artificial Intelligence

South Korea Investigates First Known AI Agent Cyberattacks on Commercial Banks

Hackers breached at least seven South Korean financial institutions and exposed the personal data of 68,000 people. Investigators suspect the attackers used an open-source AI agent to automate the intrusions.

By Nicolas Laurent

On Tuesday, October 6, 2026, South Korea's National Police Agency launched a formal investigation into a coordinated cyberattack that breached at least seven domestic financial institutions. The intrusions exposed the personal data of approximately 68,000 individuals. Investigators suspect the attackers deployed an autonomous artificial intelligence agent to execute the breaches, marking the first known instance of AI-driven tools successfully penetrating the global financial system.[1][2][3]

The attacks began in late September and targeted secondary infrastructure rather than core banking ledgers. Hackers breached employee portals, loan applications, and sales-support systems. Shinhan Bank, one of the country's largest lenders, reported that the data of about 25,000 customers was exposed after attackers bypassed a verification step on a lookup service built for external loan recruiters.[2][4]

Other major institutions, including KB Kookmin Bank and Hana Bank, also suffered data leaks. The compromised information included sensitive financial details such as annual incomes, personal loan limits, names, and phone numbers. The Financial Services Commission immediately convened an emergency session, instructing banks, insurers, and securities firms to fortify their externally accessible systems.[3][4]

The mechanism behind the breach

The investigation centers on ARTEX AI, an open-source penetration-testing agent developed by a Chinese cybersecurity engineer known as Autumn. ARTEX is not a standalone foundational model. Instead, it acts as an orchestration layer that connects to existing large language models—including Anthropic's Claude Opus, OpenAI's ChatGPT, and China's DeepSeek—to automate the discovery of network vulnerabilities.[2]

The automated attacks targeted secondary infrastructure across seven major lenders, exposing the data of 68,000 individuals.

Designed to help organizations stress-test their own defenses, ARTEX can autonomously scan systems, write exploit code, and analyze stolen data with minimal human oversight. Security researchers found traces of the tool, including a specific Chinese-language string, on the compromised South Korean web servers. The attackers effectively weaponized a defensive diagnostic tool to automate credential stuffing.[2]

By delegating the repetitive labor of probing side doors to an AI agent, the hackers operated at a scale and speed that traditional manual methods rarely achieve. Over a 30-hour window starting September 28, the automated system rapidly fed random customer numbers into Shinhan Bank's external portals. This continuous, machine-driven persistence allowed the attackers to slip past standard verification hurdles.[2]

"It's now become possible to use AI to hack with ease even without specialized skills," South Korean President Lee Jae Myung said during a televised cabinet meeting on Tuesday. He directed his administration to overhaul the nation's security paradigm for the AI era and deploy personnel to minimize the damage. "Signs have emerged" that AI models were used, he added, "causing considerable public concern and anxiety."[1][3]

Tracing the automated intrusion

The National Office of Investigation has assigned 28 investigators from its cyberterrorism unit to track the perpetrators. However, the autonomous nature of the attack complicates the digital forensics. The intrusions were routed through more than 30 internet protocol addresses spread across roughly 12 countries, including the United States, Japan, and Germany.[3]

Because hackers frequently spoof their locations to mask their origins, authorities have not yet identified the individuals or groups responsible. The South Korean government is currently seeking international cooperation to trace the network traffic back to its source. It remains unclear whether a state-sponsored entity or an independent criminal syndicate orchestrated the campaign.[2]

Illustration: Investigators found traces of an open-source penetration-testing agent on the compromised web servers.

Following the public disclosure of the breaches, the developer behind ARTEX AI updated the software's user guidelines to explicitly prohibit unauthorized intrusions and data theft. Yet cybersecurity experts note that policy updates offer little practical defense. Because the tool is open-source, anyone can download the underlying code, strip away the usage restrictions, and deploy the agent maliciously.[2]

A shifting security landscape

The South Korean breaches highlight a fundamental inversion in cybersecurity economics. The same capabilities that allow a security team to efficiently map their own vulnerabilities now allow attackers to exploit those gaps at a fraction of the historical cost. Financial institutions are finding their peripheral applications uniquely vulnerable to automated probing.[1]

While banks have spent decades hardening their primary mainframes, modern banking relies on a vast web of application programming interfaces, third-party vendor connections, and remote employee portals. AI agents excel at mapping these complex, interconnected surfaces to find the single forgotten endpoint that grants access to sensitive data.[2]

The Financial Supervisory Service and the Financial Security Institute have begun sharing the identified malicious IP addresses with the broader financial sector to block further automated traffic. They are also auditing how external contractors, such as the loan recruiters targeted in the Shinhan Bank breach, are granted access to sensitive internal databases.[3]

Critics have argued that giving non-employees direct lookup access to customer credit data represents a severe lapse in basic cyber hygiene. The AI agent did not invent a complex zero-day exploit; it merely possessed the tireless capacity to find and abuse an existing administrative oversight. This distinction is crucial for understanding how agentic AI changes the threat landscape.[2]

The autonomous intrusions were routed through dozens of internet protocol addresses spread across roughly 12 countries.

The broader context of AI-assisted hacking has accelerated throughout 2026. Earlier in the year, Anthropic disclosed that state-sponsored Chinese hackers had utilized its AI technology to automate break-ins at approximately 30 targets worldwide. Similarly, Australian officials recently reported that an OpenAI agent had infiltrated a government healthcare-statistics portal, accessing both public and nonpublic files.[1]

These incidents demonstrate that foundational models, despite their built-in safety guardrails, can be orchestrated by secondary agents like ARTEX to perform malicious tasks. The agent breaks a complex intrusion into smaller, benign-looking queries that the foundational model answers without triggering safety filters. The agent then pieces those answers together to execute the attack.[2]

South Korean cybersecurity stocks surged by as much as 30 percent on Tuesday as investors anticipated a massive wave of defensive spending by the financial sector. Banks are now expected to deploy counter-agents—AI systems specifically trained to detect the behavioral patterns of offensive AI tools, such as the rapid, non-human cadence of credential stuffing.[3]

Regulators are now urging financial leadership to adopt a hacker's mindset, using their own AI agents to continuously stress-test their external perimeters. As the investigation continues, the immediate focus remains on securing the compromised accounts and determining whether the stolen financial profiles have already been sold or utilized on the dark web.[2]

South Korean President Lee Jae Myung convened an emergency cabinet meeting to address the AI-driven breaches.

The 68,000 compromised accounts represent a relatively small fraction of South Korea's highly digitized banking population. However, the methodology guarantees that this will not be an isolated event. The barrier to entry for launching a coordinated, multi-institution cyberattack has permanently fallen, shifting the burden of speed entirely onto the defenders.[1]

Key points

  • Hackers breached at least seven South Korean financial institutions, exposing the personal data of approximately 68,000 individuals.
  • Investigators suspect the attackers used ARTEX AI, an open-source Chinese diagnostic tool, to automate the intrusions.
  • The AI agent targeted secondary infrastructure, such as loan applications and employee portals, rather than core banking ledgers.
  • South Korean authorities have deployed 28 cyberterrorism investigators to trace the attacks across more than a dozen countries.

What we don’t know

  • Whether the attack was orchestrated by a state-sponsored entity or an independent criminal syndicate.
  • Which specific foundational AI models the hackers connected to the ARTEX agent to execute the breach.
  • Whether the stolen financial profiles have already been sold or utilized on the dark web.

How we got here

  1. Late Sept 2026

    Hackers begin deploying the ARTEX AI agent against the external portals of multiple South Korean financial institutions.

  2. Sept 28, 2026

    An automated credential-stuffing attack initiates against Shinhan Bank's loan recruiter lookup service, lasting roughly 30 hours.

  3. Sept 30, 2026

    The initial breaches come to light as banks detect unauthorized access and data exposure.

  4. Oct 6, 2026

    South Korean President Lee Jae Myung convenes an emergency cabinet meeting and the National Police Agency launches a formal investigation.

Financial Regulators 40%Cybersecurity Defenders 40%Open-Source Developers 20%
Financial Regulators
Authorities argue that basic cyber hygiene and access controls remain the primary defense against automated threats.
Cybersecurity Defenders
Security professionals believe the economics of hacking have permanently inverted, requiring AI-driven defenses.
Open-Source Developers
Engineers maintain that open-source diagnostic tools are essential for security, despite the risk of malicious misuse.

Perspectives this story doesn't cover

  • Affected bank customers
  • Foundational AI model developers

Sources

Source coverage

4 outlets

3 viewpoints surfaced

Financial Regulators 40%Cybersecurity Defenders 40%Open-Source Developers 20%
  1. [1]The New York TimesFinancial Regulators

    South Korea Investigates Possible Use of A.I. in Hackings on Its Banks

    Read on The New York Times →
  2. [2]The Wall Street JournalCybersecurity Defenders

    Hackers Use Chinese AI Tool to Hit South Korean Banks, Exposing New Risk

    Read on The Wall Street Journal →
  3. [3]The RecordFinancial Regulators

    South Korean officials believe AI agents were used to hack several banks

    Read on The Record →
  4. [4]GIGAZINECybersecurity Defenders

    韓国の金融機関に対してAIを用いたハッキングが発生、少なくとも7行から6万8000人分の個人情報が流出か

    Read on GIGAZINE →

Comments

Stay informed

Every angle. Every day.

Get Artificial Intelligence stories with full source coverage and perspective breakdowns, free every day.