South Korea Probes Suspected AI Use in Financial Sector Breaches

South Korea probes suspected AI use in financial-sector breaches, with exposed loan systems and leaked customer data raising phishing and fraud risks.

Oct 6, 2026
3 minute read
South Korea probes AI links to bank data breaches.

South Korea probes AI links to bank data breaches. Image: Shinhan Bank

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

South Korean authorities are investigating whether AI helped attackers breach financial institutions through exposed loan and sales systems.

The breaches exposed personal and financial information, raising concerns about follow-on phishing and fraud.

Shinhan Bank reported that information belonging to about 25,000 customers was leaked, while Yegaram Savings Bank reported a breach affecting about 40,000 people. Other breaches have been reported at KB Kookmin Bank, Hana Bank, BNK Busan Bank, Welcome Savings Bank and Hyundai Capital, with some involving worker or loan-broker information rather than customer records.

Authorities have found identical or similar IP addresses across some incidents, raising the possibility that one attacker or group was probing multiple financial companies. The attacks largely focused on externally accessible, noncore systems used by loan brokers, sales staff and other third parties rather than core banking and payment networks.

ARTEX AI raises a bigger question

Yonhap reported on Oct. 2 that Moon Jong-hyun, head of Genians Security Center, identified a Chinese-language page title associated with ARTEX AI on a server suspected of involvement in a credential-stuffing attack targeting Shinhan Bank. The string, “ARTEX-自主渗透試控制台,” translates to “AI Autonomous Penetration Test Console,” according to Yonhap news agency.

The discovery does not prove ARTEX AI was used in the attack. The software is open source and can be downloaded by anyone, meaning the Chinese-language trace alone cannot identify who operated the server or where the attacker was based.

ARTEX AI is designed to automate much of the penetration-testing process, including reconnaissance, vulnerability discovery, attack-path planning, security-tool execution and vulnerability verification. That same automation can potentially be repurposed by criminals to speed up attacks.

The incidents expose a problem that goes beyond whether an attacker used AI: financial institutions can have heavily protected core systems while leaving peripheral services exposed to attack.

In the Shinhan case, the attacker reportedly bypassed identity checks on a loan-related service rather than breaking directly into the bank's core transaction infrastructure. That makes third-party portals, externally accessible applications and authentication systems important parts of a bank's security boundary, even when they do not handle payments themselves. 

Advertisement

It also explains why simply increasing cybersecurity spending may not prevent similar incidents. Korea Herald reported that Shinhan's information-security budget was the lowest among the country's four largest commercial banks, but regulators said differences in damage cannot be explained by spending alone. They are examining how effectively each institution's security framework identified and closed weaknesses.

Rising phishing dangers for banking consumers

Financial Services Commission Chairman Lee Eog-weon said on Oct. 4 that authorities had not identified leaked information directly usable for fraudulent payments. He warned that the exposed data could nevertheless enable voice phishing, fraudulent text messages and further cyberattacks.

According to the Korea Herald, Shinhan’s exposed loan application data included names, phone numbers, annual incomes and calculated borrowing limits. These details could help criminals make voice-phishing calls and fraudulent text messages more convincing by impersonating bank representatives with accurate financial information.

Regulators have ordered financial institutions to block nonessential external access and review exposed IT assets, authentication, access controls and intrusion detection. Customers are advised to monitor account notifications closely, treat unsolicited loan calls with heightened skepticism, and verify outreach directly through verified branch channels.

For security teams, the takeaway is to include loan-broker portals, sales applications and other peripheral services in security reviews. Protected payment networks do not eliminate the risk of customer information being exposed through connected business systems.

Read more: Financial institutions also face threats through trusted communications, as a phone-based campaign targeting Wall Street firms shows how attackers use help-desk impersonation to steal credentials and intercept authentication codes.


Aminu Abdullahi

Aminu Abdullahi

Content Writer

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. His work has appeared in publications including TechRepublic, eWEEK, Channel Insider, Geekflare, Enterprise Networking Planet, eSecurity Planet, CIO Insight, and Webopedia. With a technical background in computer science, he specializes in translating complex technology topics into clear, accessible content for business leaders and decision-makers.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.