Skip to content
Finance

AI Tools Used in Cyberattacks on South Korean Banks

By Rajiv MenonKorea
2 min read
IronNet Cybersecurity
IronNet Cybersecurity
In this article (9)

Hackers used artificial intelligence agents to breach at least nine South Korean financial institutions in October 2026. The attack compromised personal data from more than 25,000 banking customers.

Major domestic lenders bore the brunt of the intrusions. Shinhan Bank reported 25,000 compromised customer records, while KB Kookmin Bank confirmed 119 leaked customer profiles.

Automated Penetration Tools In Action

Running from late September to early October, the campaign relied on an open-source security tool named ARTEX paired with Anthropic’s Claude Code. A Chinese security researcher using the alias Autumn published ARTEX on GitHub earlier this year. The software functions as an automated penetration agent. It links directly into external large language models including ChatGPT, Claude and DeepSeek to run vulnerability tests across target servers.

The software repository explicitly restricts use to local testing and research. Even so, the attacker weaponised the framework against live online banking infrastructure. Cybersecurity firm CrowdStrike tracked the interactive sessions. The firm found that the operator fed target environments directly into AI coding interfaces to accelerate intrusion paths and system mapping.

Traces Left In Model Prompts

During the operation, the operative inadvertently leaked personal information directly into model prompt logs. Session records show queries asking where threat actors sell compromised Korean databases and requesting specific Korean data-trading channels on Telegram. In a separate prompt, the attacker instructed Claude to compile a curriculum vitae. That document contained a personal Telegram handle, educational background, age and an address in Maoming, Guangdong province.

“While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated,”

Digital infrastructure and Chinese-language prompts pointed investigators toward a 26-year-old individual operating out of southern China. “While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated,” CrowdStrike stated in its findings.

Operational Risks For Retail Banking

Automated AI penetration shifts the economics of perimeter defense for financial institutions and retail digital banking platforms across the Asia-Pacific region. Attackers no longer need deep bespoke code writing. Open-source agents can autonomously test attack surfaces and parse enterprise firewalls around the clock at negligible cost. Traditional web application filters now face automated scanning that iterates faster than standard manual patch schedules.

Commercial banks face compounding costs from consumer notification mandates, regulatory fines and identity theft remediation. Containment protocols must now focus on rapid API throttling and continuous identity verification rather than static perimeter defenses. Retail platforms managing high volumes of consumer payments and stored credentials represent immediate targets as autonomous agent frameworks lower execution barriers.

Escalating AI Incursions In Asia-Pacific

Earlier incursions set the stage. In June, an autonomous AI agent breached a government health portal in Australia in one of the region’s earliest documented cases of autonomous agent exploitation. Financial regulators in Japan and South Korea had heightened network surveillance earlier this year as code-generation tools expanded the volume of automated attack scripts circulating in private forums.

Police in South Korea opened a formal criminal investigation into the nine targeted institutions this week following directives from President Lee Jae Myung for immediate security interventions. Regulatory authorities in Seoul are auditing network logs across commercial lenders to determine if secondary data exfiltration occurred before defensive patches took effect.

Questions & Answers

Q.

Which financial institutions were most affected by these cyberattacks?

A.

Shinhan Bank reported 25,000 compromised customer records, while KB Kookmin Bank confirmed 119 leaked customer profiles. Major domestic lenders generally bore the brunt of the intrusions across the nine targeted institutions.

Q.

What tools did the hackers use to carry out these cyberattacks?

A.

The attackers used an open-source security tool called ARTEX, published by a researcher named Autumn. This was paired with Anthropic's Claude Code and linked to external large language models like ChatGPT and DeepSeek for vulnerability tests.

Q.

What evidence suggested the attacker's identity or origin?

A.

The attacker inadvertently leaked personal information, including a Telegram handle, educational background, age, and an address in Maoming, Guangdong province, into model prompt logs. Digital infrastructure and Chinese-language prompts also pointed to southern China.

Q.

What measures are authorities taking in response to the attacks?

A.

Police in South Korea have opened a formal criminal investigation into the nine targeted institutions. Regulatory authorities in Seoul are also auditing network logs across commercial lenders to check for secondary data exfiltration before defensive patches were applied.

Weekly Briefing

Asia's retail intelligence, in your inbox

Monday, Wednesday and a Friday Weekly Wrap: the retail stories, numbers and moves that mattered across Asia. Nothing else, and you can unsubscribe in one click.

  • Top industry moves and market shifts
  • Weekly data-driven analysis from across Asia
  • Monday, Wednesday and the Friday Weekly Wrap

Read by retail operators, investors and brand teams across Asia.

Protected by a quick human check. No spam, ever. Unsubscribe in one click.

SecureGDPR ready