Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
AI-powered cyberattacks breach seven South Korean banks, exposing 65,000 records
00

AI-powered cyberattacks breach seven South Korean banks, exposing 65,000 records

Oct 5, 2026

South Korea has placed its financial sector on maximum alert after a coordinated cyberattack campaign breached seven financial institutions, exposing over 65,000 customer records. The attacks utilized ARTEX AI, an open-source autonomous penetration-testing tool that automates complex attack loops. Rather than targeting heavily secured core transaction networks, the threat actors successfully exfiltrated sensitive data from weaker auxiliary systems. In response, President Lee Jae-myung has ordered an emergency probe, while regulators have mandated immediate security audits across the financial industry.

Targeted South Korean financial institutions

  • ▪Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank, and Hyundai Capital confirmed data breaches during the campaign.
  • ▪Woori Bank and NH NongHyup Bank detected and successfully repelled the intrusion attempts without suffering confirmed data breaches.
  • ▪The coordinated cyberattack campaign ran for approximately one week beginning September 28, 2026, and targeted seven South Korean financial institutions.

Extent and nature of exposed data

  • ▪The exfiltrated data included names, phone numbers, addresses, national ID numbers, annual income figures, and calculated loan limits, though no direct financial losses have been confirmed.
  • ▪The cyberattacks exposed the personal data of more than 65,000 customers across South Korean financial institutions, including approximately 40,000 at Yegaram Savings Bank and approximately 25,000 at Shinhan Bank.

Attack methodology and tactics

  • ▪The attackers bypassed tightly secured core transaction systems to target less-protected noncore auxiliary systems, such as loan solicitor portals, employee mobile support platforms, and sales support databases.
  • ▪The cyberattacks utilized credential stuffing, which was augmented by AI to adaptively execute the attacks by varying timing, rotating infrastructure, and adjusting parameters in response to defenses.

Use and origin of ARTEX AI

  • ▪The Korea Financial Security Institute confirmed the use of ARTEX AI after tracing attack IP addresses and server logs from Shinhan Bank, which was the first institution to report a breach.
  • ▪The cyberattacks against South Korean financial institutions utilized ARTEX AI, an open-source autonomous penetration-testing system built on large language models that independently conducts reconnaissance, identifies login endpoints, and executes attacks.
  • ▪ARTEX AI was originally introduced as a winning entry in a challenge run by Baidu's Security Response Center and distributed openly through GitHub primarily to Chinese-speaking developers.

Government and regulatory response

  • ▪The Ministry of Science and ICT and the Korea Internet & Security Agency jointly activated a 24-hour incident response posture and raised the national cyber alert level to 'Watch'.
  • ▪The Financial Supervisory Service ordered all South Korean financial companies to complete an emergency security inspection by October 8, 2026.
  • ▪South Korean President Lee Jae-myung ordered an immediate, high-level investigation into the hacking incidents and called for the development of cybersecurity methods suited to the AI era.
  • ▪Financial Services Commission Chairman Lee Eok-won convened an emergency meeting on October 4, 2026, ordering financial firms to block non-essential external access and maintain maximum vigilance.

Expert warnings on AI cyber threats

  • ▪Security experts state that agentic AI attack tools eliminate the skill floor for complex cyberattacks by automating the entire attack loop, including proxy rotation and authentication challenge handling.
  • ▪Kim Myeong-ju of the Barun AI Research Center warned that because hackers have begun using AI agents, the frequency and scale of cyberattacks are bound to grow more severe.

Information security budgets

  • ▪Shinhan Bank's information security budget of 40.59 billion won ($30.2 million) for 2026 was the lowest among South Korea's top four commercial banks, drawing scrutiny following its breach.
  • ▪In 2026, KB Kookmin Bank allocated the largest information security budget among South Korea's top four commercial banks at 86.07 billion won.

Debatable claims

  • ▪Developers should not openly distribute autonomous AI penetration-testing tools
  • ▪Low information security budgets are the primary cause of bank data breaches
  • ▪Mandating blocks on non-essential external access goes too far in disrupting banking operations

4 sources

Straitstimes
AI used in bank hacks prompts South Korea cybersecurity response
View source article
Techtimes
Open-Source AI Agent Hacked Seven South Korean Banks, Exposing 65,000 Records
View source article
Thenews
South Korea orders emergency probe after AI-powered cyberattacks target major banks
View source article
Koreaherald
Korean banks on high alert after wave of cyberattacks
View source article

Featured stories

View more in Open-source AI

Reflection AI unveils Beam open-weight model to compete with Chinese AI

Oct 5, 2026 · 5 sources

Meta releases Muse Gadgets as open-source DIY AI hardware project

Oct 2, 2026 · 2 sources

Apple tightens macOS Full Disk Access controls citing risks from AI agents

Oct 2, 2026 · 9 sources

Apple changes macOS permissions to limit AI agent data access

Oct 2, 2026 · 6 sources

Story comments

Loading comments…

Related entities

CybersecuritySouth Korea

People Involved

Lee Jae Myung

Topics

Open-source AIAI agentsData breachesAI security

Featured stories

View more in Open-source AI

Reflection AI unveils Beam open-weight model to compete with Chinese AI

Oct 5, 2026 · 5 sources

Meta releases Muse Gadgets as open-source DIY AI hardware project

Oct 2, 2026 · 2 sources

Apple tightens macOS Full Disk Access controls citing risks from AI agents

Oct 2, 2026 · 9 sources

Apple changes macOS permissions to limit AI agent data access

Oct 2, 2026 · 6 sources