Papalocal
Loading…
← All news
Technology

South Korea probes AI-assisted bank hacks that exposed tens of thousands of customers' data

President Lee Jae Myung has ordered a national police investigation after traces of a Chinese-language AI hacking tool were found in breaches at five major financial institutions.

How does this story make you feel?

South Korean President Lee Jae Myung ordered a full police investigation on Tuesday after investigators found traces of an AI-powered hacking tool inside the networks of at least five major banks — a development that exposed the personal data of tens of thousands of customers and raised alarms about a new era of automated cyberattacks on financial infrastructure.

Signs have emerged of AI being used, causing considerable public concern and anxiety.— Lee Jae Myung, President of South Korea

The National Police Agency's cyber terror unit is leading the investigation. Banks have been ordered to strengthen their defenses quickly, according to Reuters. Authorities have shared suspect IP addresses with financial firms, but no perpetrators have been identified.

At the center of the investigation is a tool called ARTEX — an open-source, Chinese-language autonomous penetration-testing program, according to Korea Times. Unlike a human hacker who must manually probe networks, identify weaknesses, and map out attack paths, ARTEX is designed to automate all of those steps with little human input, allowing it to scan multiple institutions and exploit vulnerabilities at a speed no human team could match.

It would be difficult for humans to carry out attacks this fast and on such a large scale across the financial sector in just a matter of days. It is highly likely that AI was used.— Lim Jong-in, Professor, Korea University Graduate School of Information Security

Lim described the speed gap between conventional hackers and AI-powered attacks as the difference between a person running and a Ferrari, adding that it would take human hackers weeks or months to plan and execute attacks of this scale. He cautioned, however, that the presence of a Chinese-language tool does not point to China as the perpetrator — some Chinese AI models are released with weak safeguards, making them available for anyone worldwide to download and modify for malicious use.

The confirmed breaches hit Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank, and BNK Busan Bank. Woori Bank and NH NongHyup Bank detected signs of hacking attempts but reported no confirmed data leaks, according to Korea Times. Shinhan Bank was the hardest hit, with roughly 25,000 customers' names, phone numbers, annual income figures, and loan limits exposed. KB Kookmin reported 119 affected customers and Hana Bank reported 89. Yegaram Savings Bank also reported a substantial number of affected customers.

The relatively contained damage has a structural explanation. Hwang Suk-jin, a professor at Dongguk University's Graduate School of International Affairs and Information Security, said the attackers targeted banks' supporting networks rather than their core systems — which carry far stronger protections.

Banks have core networks and supporting networks. The supporting networks have relatively weaker security, and they were targeted in this attack. Rather than entering through the front door, the attackers came in through a window, using an indirect route to steal only some of the information.— Hwang Suk-jin, Professor, Dongguk University Graduate School of International Affairs and Information Security

Hwang added a warning that the limited damage may not reflect the attackers' ultimate ambitions. The recent intrusions, he said, may have been an initial test to map vulnerabilities — raising the possibility of larger follow-up attacks using the information already obtained.

South Korea has experienced large-scale data breaches before — incidents affecting nearly 40 million Tving users in June and 33 million Coupang users the prior year, according to Korea Times — but those were not linked to AI-powered tools. Experts say the financial sector's reliance on legacy supporting infrastructure creates persistent exposure that AI-driven tools are now well-positioned to exploit.

As attackers use AI to rapidly find vulnerabilities, defenders also need to use AI to detect weaknesses first and strengthen systems capable of responding automatically around the clock.— Lim Jong-in, Professor, Korea University Graduate School of Information Security

The investigation remains active and ongoing. Authorities have not named any suspects or attributed the attacks to any nation or group. The key question — whether ARTEX was merely present in the networks or was the primary instrument of the breaches — has not yet been answered publicly.

Why it matters — The alleged use of an AI tool to automate bank hacking at speed and scale — hitting seven institutions across days rather than months — signals a potential shift in the threat landscape that financial regulators and institutions worldwide will be watching closely.

⚠ Not yet confirmed

  • ARTEX was the primary instrument used to carry out the breaches, rather than merely being present in the affected networks.
  • The recent attacks may have been an initial test run ahead of larger follow-up attacks.
  • exact total of 68,000 customers
  • 28 suspect IP addresses spanning roughly a dozen countries as of October 7
  • no funds were stolen in any of the breaches
  • specific Yegaram customer count of approximately 40,000

Reported by thehill.com, nytimes.com, reuters.com, archive.is, koreatimes.co.kr

Community

Be the first to comment.

Share this story
Text Email