South Korean authorities are investigating whether AI helped attackers breach financial institutions through exposed loan and sales systems.
The breaches exposed personal and financial information, raising concerns about follow-on phishing and fraud.
Shinhan Bank reported that information belonging to about 25,000 customers was leaked, while Yegaram Savings Bank reported a breach affecting about 40,000 people. Other breaches have been reported at KB Kookmin Bank, Hana Bank, BNK Busan Bank, Welcome Savings Bank and Hyundai Capital, with some involving worker or loan-broker information rather than customer records.
Authorities have found identical or similar IP addresses across some incidents, raising the possibility that one attacker or group was probing multiple financial companies. The attacks largely focused on externally accessible, noncore systems used by loan brokers, sales staff and other third parties rather than core banking and payment networks.
ARTEX AI raises a bigger question
Yonhap reported on Oct. 2 that Moon Jong-hyun, head of Genians Security Center, identified a Chinese-language page title associated with ARTEX AI on a server suspected of involvement in a credential-stuffing attack targeting Shinhan Bank. The string, “ARTEX-自主渗透試控制台,” translates to “AI Autonomous Penetration Test Console,” according to Yonhap news agency.
The discovery does not prove ARTEX AI was used in the attack. The software is open source and can be downloaded by anyone, meaning the Chinese-language trace alone cannot identify who operated the server or where the attacker was based.
ARTEX AI is designed to automate much of the penetration-testing process, including reconnaissance, vulnerability discovery, attack-path planning, security-tool execution and vulnerability verification. That same automation can potentially be repurposed by criminals to speed up attacks.
The weak link may be outside the bank
The incidents expose a problem that goes beyond whether an attacker used AI: financial institutions can have heavily protected core systems while leaving peripheral services exposed to attack.
In the Shinhan case, the attacker reportedly bypassed identity checks on a loan-related service rather than breaking directly into the bank's core transaction infrastructure. That makes third-party portals, externally accessible applications and authentication systems important parts of a bank's security boundary, even when they do not handle payments themselves.
It also explains why simply increasing cybersecurity spending may not prevent similar incidents. Korea Herald reported that Shinhan's information-security budget was the lowest among the country's four largest commercial banks, but regulators said differences in damage cannot be explained by spending alone. They are examining how effectively each institution's security framework identified and closed weaknesses.
Rising phishing dangers for banking consumers
Financial Services Commission Chairman Lee Eog-weon said on Oct. 4 that authorities had not identified leaked information directly usable for fraudulent payments. He warned that the exposed data could nevertheless enable voice phishing, fraudulent text messages and further cyberattacks.
According to the Korea Herald, Shinhan’s exposed loan application data included names, phone numbers, annual incomes and calculated borrowing limits. These details could help criminals make voice-phishing calls and fraudulent text messages more convincing by impersonating bank representatives with accurate financial information.
Regulators have ordered financial institutions to block nonessential external access and review exposed IT assets, authentication, access controls and intrusion detection. Customers are advised to monitor account notifications closely, treat unsolicited loan calls with heightened skepticism, and verify outreach directly through verified branch channels.
For security teams, the takeaway is to include loan-broker portals, sales applications and other peripheral services in security reviews. Protected payment networks do not eliminate the risk of customer information being exposed through connected business systems.
Read more: Financial institutions also face threats through trusted communications, as a phone-based campaign targeting Wall Street firms shows how attackers use help-desk impersonation to steal credentials and intercept authentication codes.





