NEWS

Korea Probes AI-Tool Hacks at Seven Lenders, 67,000 Customers Hit

South Korean President Lee Jae Myung speaks at a podium during a government briefing in Seoul
President Lee Jae Myung ordered a thorough investigation on October 4 after attacks on seven South Korean lenders were traced to one source. Source: The Korea Times
Quick answer: On October 4, 2026, South Korea's Financial Services Commission ordered every financial institution in the country to review its security after one attacker breached seven lenders, including Shinhan Bank, KB Kookmin and Hana Bank, exposing data on more than 67,000 customers. Investigators found traces of ARTEX, an open-source AI penetration-testing tool, on a server tied to the attacks, and President Lee Jae Myung ordered a full investigation.
TLDR

South Korea's financial regulator on October 4 ordered every bank, insurer, card issuer and fintech in the country to review its security from scratch after a single attacker, using an open-source AI penetration-testing tool called ARTEX, breached seven lenders in a week and exposed data on more than 67,000 customers. President Lee Jae Myung ordered a full investigation the same day.

One attacker hit seven Korean lenders through side doors in a single week

The intrusions avoided the core systems that move deposits and payments. At Shinhan, the attacker went through a lookup service used by loan brokers; at KB Kookmin, through a mobile work app for employees. Investigators say the same IP addresses appeared across all seven firms, and that automated attacks fed large numbers of guessed customer numbers and reused credentials into these peripheral systems until valid records came back. The stolen fields included names, phone numbers, annual income, loan limits and, for some Shinhan customers, resident registration numbers.

InstitutionTypeReported exposure
Shinhan BankCommercial bankAbout 25,700 customer records
Yegaram Savings BankSavings bankAbout 40,000 customers
Welcome Savings BankSavings bankUp to 2,200 corporate clients
Hyundai CapitalConsumer finance146 housing-loan agents
KB Kookmin BankCommercial bank119 customers
Hana BankCommercial bank89 customers
BNK Busan BankRegional bank11 customers
Woori Bank, NH NongHyupCommercial banksAttempts blocked, no confirmed leak

Source: disclosures by the institutions and Financial Services Commission briefings, September 30 to October 4, 2026. Compiled by Santage.

FSC Chairman Lee Eok-won chaired an emergency meeting of financial-sector chiefs at the Government Complex Seoul on Sunday afternoon. The Korea Internet & Security Agency raised its threat level from “interest” to “caution.”

“Financial security is the foundation of trust and stability. We must review the entire information security system from square one.”

Lee Eok-won, Chairman, Financial Services Commission, October 4, 2026

ARTEX shows how quickly open-source attack agents reach real targets

ARTEX was published as a red-team tool, an AI agent built on a large language model that scans systems, chains together likely weaknesses and tries them without a human typing each step. Its latest version appeared on September 24. The first attacks on KB Kookmin began three days later.

Timeline showing the ARTEX AI penetration-testing tool released on GitHub July 26, 2026, updated September 24, attacks on Korean banks September 27 to 30, Shinhan Bank's disclosure October 1 and the government probe October 4
Nine weeks separated the tool's public release from the first breach. Chart: Santage. Source: Financial Services Commission and presidential office statements, October 4, 2026; investigators' findings on ARTEX.

A Korea Financial Security Institute official said the AI “did not act independently without human involvement,” and that a hacker used it as a tool. Investigators also said ARTEX traffic carries a recognizable data signature, which helped them link the seven intrusions to one source. That cuts both ways: the tool made a single operator fast enough to probe a whole banking sector at once, and it left fingerprints that defenders can now watch for.

Regulators are shrinking what Korean finance exposes to the internet

The FSC's order reads as an admission that the weak points sat outside the systems regulators traditionally police. Firms must now block external access by default unless a service cannot work without it, list every internet-facing asset and test it for vulnerabilities, and cut employee access rights to the minimum each role requires. The commission also told institutions to share attack indicators, including IP addresses and intrusion methods, across the sector, and to adopt AI-based monitoring that can match the speed of automated attacks. Officials have floated easing Korea's strict network-separation rules so that banks can run those defensive tools, a reversal of the long-held view that air gaps alone keep core systems safe.

Shinhan, KB Kookmin and Hana together spent close to 124 billion won, about $92 million, on information security last year. That budget protected the payment rails and left loan-broker portals and staff apps holding customer data they arguably never needed. Shinhan has pledged full compensation to affected customers, and regulators warned that the leaked income and loan-limit details give voice-phishing gangs a ready script.

The lesson extends well beyond Korea and matches last week's finding that the open-weight Chinese model GLM-5.3 could build a working exploit chain for $20.40: once capable attack agents are free to download, any forgotten system with real data behind it becomes a target within weeks of release, and the defender's job shifts from guarding the vault to finding every side door before an automated scanner does.

In short: Seven South Korean lenders were breached between September 30 and October 4, 2026 by an attacker linked to ARTEX, an open-source AI penetration-testing tool released on GitHub nine weeks earlier. The government's response, default blocking of outside access and a sector-wide asset inventory, treats every peripheral system holding customer data as a target for automated attack agents.

Santage is committed to independent, transparent journalism. This article is produced in accordance with Santage's Editorial Standards and aims to provide accurate and timely information. Readers are encouraged to verify information independently.