- Shinhan Bank, KB Kookmin, Hana, BNK Busan Bank, Welcome Savings Bank, Yegaram Savings Bank and Hyundai Capital reported breaches between September 30 and October 4, while Woori and NH NongHyup blocked attempts.
- Investigators found traces of ARTEX, a Chinese-language autonomous penetration-testing system posted to GitHub on July 26, on a server tied to the Shinhan intrusion.
- The Financial Services Commission now requires firms to block outside access by default, inventory every internet-facing system and adopt AI-based defenses.
South Korea's financial regulator on October 4 ordered every bank, insurer, card issuer and fintech in the country to review its security from scratch after a single attacker, using an open-source AI penetration-testing tool called ARTEX, breached seven lenders in a week and exposed data on more than 67,000 customers. President Lee Jae Myung ordered a full investigation the same day.
One attacker hit seven Korean lenders through side doors in a single week
The intrusions avoided the core systems that move deposits and payments. At Shinhan, the attacker went through a lookup service used by loan brokers; at KB Kookmin, through a mobile work app for employees. Investigators say the same IP addresses appeared across all seven firms, and that automated attacks fed large numbers of guessed customer numbers and reused credentials into these peripheral systems until valid records came back. The stolen fields included names, phone numbers, annual income, loan limits and, for some Shinhan customers, resident registration numbers.
| Institution | Type | Reported exposure |
|---|---|---|
| Shinhan Bank | Commercial bank | About 25,700 customer records |
| Yegaram Savings Bank | Savings bank | About 40,000 customers |
| Welcome Savings Bank | Savings bank | Up to 2,200 corporate clients |
| Hyundai Capital | Consumer finance | 146 housing-loan agents |
| KB Kookmin Bank | Commercial bank | 119 customers |
| Hana Bank | Commercial bank | 89 customers |
| BNK Busan Bank | Regional bank | 11 customers |
| Woori Bank, NH NongHyup | Commercial banks | Attempts blocked, no confirmed leak |
Source: disclosures by the institutions and Financial Services Commission briefings, September 30 to October 4, 2026. Compiled by Santage.
FSC Chairman Lee Eok-won chaired an emergency meeting of financial-sector chiefs at the Government Complex Seoul on Sunday afternoon. The Korea Internet & Security Agency raised its threat level from “interest” to “caution.”
“Financial security is the foundation of trust and stability. We must review the entire information security system from square one.”
Lee Eok-won, Chairman, Financial Services Commission, October 4, 2026
ARTEX shows how quickly open-source attack agents reach real targets
ARTEX was published as a red-team tool, an AI agent built on a large language model that scans systems, chains together likely weaknesses and tries them without a human typing each step. Its latest version appeared on September 24. The first attacks on KB Kookmin began three days later.
A Korea Financial Security Institute official said the AI “did not act independently without human involvement,” and that a hacker used it as a tool. Investigators also said ARTEX traffic carries a recognizable data signature, which helped them link the seven intrusions to one source. That cuts both ways: the tool made a single operator fast enough to probe a whole banking sector at once, and it left fingerprints that defenders can now watch for.
Regulators are shrinking what Korean finance exposes to the internet
The FSC's order reads as an admission that the weak points sat outside the systems regulators traditionally police. Firms must now block external access by default unless a service cannot work without it, list every internet-facing asset and test it for vulnerabilities, and cut employee access rights to the minimum each role requires. The commission also told institutions to share attack indicators, including IP addresses and intrusion methods, across the sector, and to adopt AI-based monitoring that can match the speed of automated attacks. Officials have floated easing Korea's strict network-separation rules so that banks can run those defensive tools, a reversal of the long-held view that air gaps alone keep core systems safe.
Shinhan, KB Kookmin and Hana together spent close to 124 billion won, about $92 million, on information security last year. That budget protected the payment rails and left loan-broker portals and staff apps holding customer data they arguably never needed. Shinhan has pledged full compensation to affected customers, and regulators warned that the leaked income and loan-limit details give voice-phishing gangs a ready script.
The lesson extends well beyond Korea and matches last week's finding that the open-weight Chinese model GLM-5.3 could build a working exploit chain for $20.40: once capable attack agents are free to download, any forgotten system with real data behind it becomes a target within weeks of release, and the defender's job shifts from guarding the vault to finding every side door before an automated scanner does.
Santage is committed to independent, transparent journalism. This article is produced in accordance with Santage's Editorial Standards and aims to provide accurate and timely information. Readers are encouraged to verify information independently.