South Korea probes bank breaches amid suspected AI-powered attacks
South Korea investigates breaches at major banks amid suspected AI-powered automated attacks.
Summary
South Korea's Financial Services Commission held an emergency meeting after cyberattacks hit multiple major banks, including Shinhan Bank (25,000 customer records leaked) and Kookmin Bank (119,000 credit card records leaked). Authorities suspect AI-powered attack automation tools were used, with evidence pointing to ARTEX AI, an open-source penetration-testing system. The FSC has ordered financial institutions to inspect externally accessible systems, strengthen authentication controls, and share threat intelligence.
Full text
South Korea probes bank breaches amid suspected AI-powered attacks By Bill Toulas October 5, 2026 10:22 AM 0 South Korea's Financial Services Commission (FSC) held an emergency meeting following a series of cyberattacks targeting financial institutions in the country. During the meeting, officials confirmed a data breach at Shinhan Bank and said other cybersecurity incidents affected other South Korean banks, including Kookmin Bank. Shinhan Bank and KB Kookmin Bank are large private South Korean commercial banks, each holding more than $400 billion in assets. Authorities said they launched on-site investigations after receiving incident reports and shared all actionable information with relevant agencies, including KISA (Korea's data protection agency). Financial companies in the country are now instructed to: Inspect all externally accessible IT systems and services, including those that are not customer-facing. Reduce unnecessary information exposure and check for missing or inadequate authentication and access controls. Quickly share threat information and coordinate their responses. Submit their internal security inspection results as soon as possible. Authorities also pledged to oversee consumer protection and compensation, and analyze the incidents to identify necessary regulatory improvements. Yesterday, local media outlets reported that South Korea's President Lee ordered a thorough investigation into personal data leaks at financial and public institutions. At the same time, Hana Bank was also found to have suffered a limited-scope breach after its sales-support system was compromised. According to the same reports, Shinhan Bank leaked the details of 25,000 customers, while Kookmin Bank leaked credit card information of 119,000 clients. AI-powered attacks suspected While official channels provided no details about the perpetrators, Korean news agency Yonhap reported that a server used in the attacks had an HTML page title containing a Chinese-language string associated with ARTEX AI. ARTEX AI is an open-source penetration-testing system that uses agents to automate information gathering, vulnerability discovery, attack-path planning, security-tool execution, and vulnerability verification. The bank and financial authorities have not confirmed its use in the Shinhan breach, and the Chinese-language string doesn't link the attacks to any particular threat actor. However, Moon Jong-hyun, the head of the Genian Security Center, posted on LinkedIn that several threat analysts believe that the breaches involved AI-based attack automation tools. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: South Korean startup platform breach exposes key management failurestenfold CE: Our free Identity Governance tool just got 2 new featuresUS sanctions Tren de Aragua gang members in ATM hacks crackdownAutonomous AI agents tried to hack US, Canadian government websitesThe Day-One Hole in Zero Trust Architecture
Indicators of Compromise
- malware — ARTEX AI