Skip to content

Korea Probes Shinhan And Six More Lenders Over Hacks

South Korea's financial regulator is investigating breaches at Shinhan, KB Kookmin, Hana and four other lenders, after analysts found traces of a Chinese open-source AI penetration testing tool.

Korea Probes Shinhan And Six More Lenders Over Hacks
Image courtesy: Unsplash

South Korea's Financial Supervisory Service is now examining intrusions at seven financial companies rather than one. Shinhan Bank disclosed a breach on 1 October, and within three days regulators had connected incidents at KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital into a single line of inquiry.

What ties them together is infrastructure. Park Sang-won, who heads the Financial Security Institute, said the attacker IP address is the same across the banking sector while differing in the savings bank cases, with the addresses rotating through the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand and the United Kingdom.

The breaches themselves stopped short of core banking. At Shinhan, attackers reached a service used by loan agents to check the status of applications, taking data on roughly 25,000 customers including names, phone numbers, annual income, borrowing amounts and limits. KB Kookmin reported a smaller incident affecting 119 customers through an employee mobile system, exposing names, addresses and encrypted resident registration numbers. Internet and mobile banking were not affected, and no customer losses have been reported.

The Evidence Pointing At An AI Tool

The detail drawing international attention came from a security researcher rather than the banks. Moon Jong-hyun, who runs the Genians Security Center, found the string "ARTEX — Autonomous Penetration Testing Console" in the HTML titles of servers linked to the attacks, and published the analysis through LinkedIn.

ARTEX is an open-source autonomous penetration testing system written largely in Chinese and published on GitHub, built on large language models combined with multi-agent coordination. It automates reconnaissance, vulnerability scanning, attack path planning, the deployment of security tools and the verification of what it finds, and it won an "Agent+" challenge run by Baidu's security response centre.

Whether the attackers actually used it remains unconfirmed. A tool's name appearing in a page title on an associated server establishes a connection to the infrastructure rather than to the intrusion itself, and Korean analysts have described the AI involvement as a reasonable suspicion rather than a finding.

The Same Name Appeared In Mexico Last Week

ARTEX surfaced in unrelated research published days earlier. The threat intelligence firm ThreatMon, documenting an intrusion linked to the Mexican airline Viva Aerobus, found the attackers' working directory on a compromised Windows machine named artex.

The overlap is a shared name rather than evidence of a shared operator, and the tool is publicly available to anyone who downloads it. What the two cases have in common is that both involved automation doing the work a human intruder would otherwise do by hand.

Credential Stuffing At Machine Speed

The method described in the Korean cases is old, and the scale is what has changed. Credential stuffing takes usernames and passwords leaked from somewhere else and tries them automatically against a new target, succeeding wherever people have reused them.

Korean security specialists have characterised what happened to Shinhan as opportunistic scanning rather than a campaign aimed at the bank, which is consistent with a system working through targets and acting on whatever it finds. Mun Chong-hyun of Genians put the wider concern in terms of availability, noting that source code is being shared freely and used for malicious attempts as AI technologies advance.

That pattern has recurred through this year's incidents, from an autonomous agent chaining two unknown flaws at a Dutch security nonprofit to OpenAI notifying more than 100 organisations that its models reached their systems, and the common thread is less about sophistication than about how little a system needs to be supervised once it has a goal and a network connection.

Regulators Moved Within Days

The response in Seoul has been quick by the standards of financial supervision. The Financial Supervisory Service began an emergency on-site inspection at Shinhan, the Financial Services Commission met local banks on Friday with a further meeting scheduled, and investigators have shared attacker IP addresses and intrusion details across agencies while setting up coordinated monitoring for the sector.

Police have opened a preliminary inquiry covering Shinhan, KB Kookmin, Hana and BNK Busan. Shin Jin-chang, the commission's secretary general, framed the official position around readiness, saying preventing data leaks requires financial institutions to maintain a high level of it.

Shinhan has said it cannot yet reasonably quantify the effect of the incident on its financial condition, results or business activities.

A Loan Agent Portal, Not A Banking System

The systems involved in both bank breaches sit at the edge of the institution: a status-checking service for loan brokers, a mobile system for staff. Neither carries the protections wrapped around transaction processing, and both hold enough customer information to be worth taking.

That is the shape the Korean investigation has settled into so far. Seven companies, a set of auxiliary systems, one set of addresses moving between countries, and a publicly available tool whose name appears nearby but whose role nobody has yet established.

Add Morning Tick on Google