Hackers use Chinese AI tool Artex to breach seven South Korean financial firms
South Korean authorities launched a criminal investigation after cyberattacks compromised the personal records of over 68,000 bank customers using open-source AI software.
Scope of the banking breaches
Hackers targeted at least seven South Korean financial institutions between late September and early October 2026, compromising data belonging to over 68,000 individuals and corporate entities. According to South Korea's Financial Services Commission, the intrusions struck both commercial retail banks and secondary consumer lending firms. An attacker bypassed identity checks on an external digital portal used by loan brokers to track customer loan applications, exposing personal details for about 25,000 Shinhan Bank customers. The breach wave also compromised approximately 40,000 customer records at Yegaram Savings Bank and 2,200 corporate accounts at Welcome Savings Bank. Additional secondary data leaks involving external contractors or loan brokers affected KB Kookmin Bank, Hana Bank, BNK Busan Bank, and Hyundai Capital. Officials confirmed that no financial funds were reported stolen from accounts during the intrusions.
- Yegaram Savings Bank
- 40000 records
- Shinhan Bank
- 25000 records
- Welcome Savings Bank
- 2200 records
Suspected deployment of Artex AI
Technical analyses indicate the attackers compromised target networks using Artex, an open-source Chinese-language artificial intelligence security tool. The utility uses AI models to identify software vulnerabilities and test exploitable paths in computer systems. Rather than attacking core interbank payment networks directly, the perpetrators applied the tool to locate flaws in peripheral third-party infrastructure and intermediary portals. Moon Jong-hyun, head of the Genians Security Center, stated on Friday in a LinkedIn post that evidence pointed to Artex in several intrusions, noting the tool functions like a dual-use instrument that can serve legitimate security testing or malicious operations. South Korean President Lee Jae Myung addressed the cabinet in Seoul on Tuesday following initial security assessments, warning that AI tools lower the technical barrier for cyber intrusions.
There are signs that artificial intelligence was used in several cyberattacks, which causes considerable concern and anxiety among the population.
Regulatory and emergency countermeasures
South Korean financial regulators and state agencies initiated coordinated security protocols to protect banking infrastructure from automated intrusion tools. Financial Services Commission chair Lee Eog-weon convened an emergency meeting on Sunday, calling on institutions to maintain peak vigilance and develop defensive systems capable of countering AI attacks with AI. The Ministry of Science and ICT and its cybersecurity agency launched a 24-hour emergency response team and instructed cloud service providers to block activity from suspect overseas network addresses. The national police agency opened a formal investigation into the security breaches on Tuesday.
- Genians Security Center identifies evidence of Artex AI tool usage
- Financial Services Commission convenes an emergency cybersecurity meeting
- President Lee Jae Myung addresses the breaches as police open an investigation
Technical attribution and IP tracking
Forensic investigators observed identical or similar IP addresses across multiple breached institutions, indicating that a single actor or coordinated entity carried out several of the attacks. While government officials confirmed that the Artex software package originated in China, authorities cautioned that utilizing Chinese-developed open-source software does not establish that the attackers themselves were operating from China. Network routing obfuscation further complicates forensic identification. Park Sang-won, head of the Financial Security Institute, addressed the limits of digital tracking during a briefing with journalists.
Hackers can change their IP address, so it is impossible to identify a hacker based on their IP address alone.
