South Korean authorities have launched a major investigation after a wave of cyberattacks hit banks and other financial companies, exposing customer information and raising suspicions that artificial intelligence helped automate the attacks.
The incidents affected several major institutions, including Shinhan Bank, KB Kookmin Bank and Hana Bank. Other financial companies were also targeted, while Woori Bank and NH NongHyup Bank detected attacks but reportedly prevented customer information from being stolen.
Shinhan suffered one of the largest confirmed breaches, with information belonging to around 25,000 customers exposed. The compromised data included names, phone numbers, annual income, and other personal information associated with loan services.
Hana Bank discovered that attackers had accessed a sales-support system, exposing information belonging to 89 customers. The affected records included names, identification numbers, addresses, and contact information.
Authorities are now examining whether the incidents are connected. Investigators reportedly identified overlapping infrastructure associated with several attacks, increasing suspicions that one attacker or coordinated operation may have targeted multiple financial companies.
The possible use of artificial intelligence has attracted particular attention. Investigators found a Chinese-language reference associated with ARTEX AI on a server believed to have been involved in the campaign.
ARTEX AI is an open-source penetration-testing system capable of automating tasks such as gathering information, identifying vulnerabilities, planning attack paths, and testing weaknesses. Such technology is designed for legitimate security testing but could potentially be abused to accelerate attacks against poorly protected systems.
Its involvement has not been definitively established, however. Finding references to the software does not prove that ARTEX AI carried out the intrusions, nor does it identify the attackers or establish a connection to China.
South Korea’s Financial Services Commission has ordered financial companies to urgently inspect internet-facing systems, strengthen authentication and remove unnecessary external access. Authorities are also sharing indicators connected to the attacks across the financial sector.
President Lee Jae Myung has ordered a thorough investigation as police and financial regulators work to determine whether the breaches are connected and exactly how AI may have been used.
So far, authorities have not identified the attackers, and the investigation into the scale and methods of the campaign remains ongoing.
