Threat intel
ARTEX AI and the Korean bank breaches: side doors first
Seven Korean lenders lost data through loan-agent and staff systems, with an open-source AI pentest tool in the frame. What happened and what to harden.
Between September 27 and 30, an attacker pulled customer and staff data out of seven South Korean financial firms: Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. None of the intrusions touched internet or mobile banking. Each went through an auxiliary system with an outside door, such as a lookup service for loan agents, an employee mobile app or a sales support tool. Regulators say they found the same attacker IP addresses across all seven.
Servers linked to the attacks ran ARTEX AI, an open-source autonomous penetration testing tool published on GitHub by a Chinese security engineer, and that is why the case is being read as an early AI-assisted campaign against banks. How firmly ARTEX is tied to the break-ins is disputed, and so is the victim count. If you run partner portals, broker lookups or staff apps that reach customer data from the internet, the pattern applies to you whether or not an AI drove it.
How it works
The best documented case is Shinhan. Its mobile site, M Shinhan, has a service that lets loan agents (brokers who sell loans for the bank but are not its employees) track the applications they submitted. According to The Herald Business, the attacker studied how that service was built, found a way past its identity verification, and then repeatedly cycled randomised customer identification numbers and other query values to pull records one at a time. Shinhan says about 25,000 customers were exposed (The Herald Business reports 25,729), including names, phone numbers, annual income and calculated loan limits, plus 66 resident registration numbers.
No exotic exploit was needed. Once a lookup endpoint stops checking who is asking and whether they may see that record, enumeration does the rest. Critics quoted by Newsis also argued that agents should never have been able to see credit data at that level.
Yegaram Savings Bank found an unknown intruder on a server holding customer personal data from September 30. Elsewhere, the reported entry was credential stuffing: automated logins with username and password pairs leaked from other sites. Reports note that banks lock customer accounts after a few failed attempts, but systems built for staff and partners often have looser limits. KB Kookmin lost data on 119 customers through an employee mobile support tool. Hana lost 89 through its sales support system, ODS. BNK Busan exposed 11 outsourced developers through an internal mobile sales system, and Hyundai Capital exposed some of its 146 housing-loan agents through a page used to check agent credentials.
What ARTEX is, and how sure anyone is
ARTEX chains large language models into a multi-agent setup that automates reconnaissance, vulnerability searching, attack-path planning and verification. Its GitHub page says it is for personal learning and local testing. After the breaches its guidelines were updated to forbid malicious use.
The link to the attacks came from Moon Jong-hyun, head of the Genians Security Center, who wrote on October 2 that the HTML title "ARTEX, autonomous penetration testing console" appeared on web servers tied to credential stuffing and API probing against Korean sites. He called it circumstantial evidence.
Accounts then split:
- The Herald Business quoted a Financial Security Institute official saying tracing of attack IPs and Shinhan server logs confirmed ARTEX use, adding that "the AI did not act independently without human involvement."
- The banks and the financial regulators have not confirmed it, and police say attribution is unclear because the tool is public and the addresses were spread across many countries.
- In a report released October 7, CrowdStrike said with moderate confidence that a Chinese-speaking, financially motivated actor used ARTEX alongside large language models, based on the tool and on Chinese-language prompts it observed.
The infrastructure counts also differ. The Herald Business reported more than 20 addresses in over 10 countries, including the United States, Japan and Germany. Other reporting on the Financial Supervisory Service's work cites 28 unique addresses in 12 countries.
How many people
Police put the total at about 68,000 people, a figure the Wall Street Journal also reported. Tech Times reported 65,000, and other outlets say more than 67,000. Two of the inputs are soft: Yegaram's roughly 40,000 is an estimate the bank was still checking, and Shinhan's 25,000 appears as 25,729 in The Herald Business. Treat any single number as provisional.
What an AI-driven scanner looks like in your logs
An agentic tool is fast, patient and rotates addresses, so hunt for the signals of a scripted attacker at higher volume:
- One endpoint, many object IDs. On a lookup or status API, count distinct customer or application IDs per session token and per source IP each hour. A loan agent checks a handful of applications; an enumerator walks hundreds, often with a high share of "not found" or 403 responses.
- Low and wide credential stuffing. In the identity provider or web server logs, group failed logins by source autonomous system (ASN) and by user agent instead of by account. Stuffing tries each username once or twice from many addresses, so per-account lockouts never fire.
- API discovery before the attack. Requests for
/swagger,/api-docs,/openapi.json,/graphqland old version paths, followed by calls to parameters the mobile app never sends, show someone mapping the application. - Hosting and VPN addresses where partners should be. Staff and broker traffic normally comes from domestic consumer or corporate networks. Bursts from cloud providers across many countries in one night are worth an alert.
- Inhumanly steady timing. Regular intervals between requests, at hours your agents do not work.
What to harden on staff and loan-sales systems
Korea's Financial Services Commission ordered every bank and card company to list all systems reachable from outside and check them for unauthenticated paths to internal data.
- List every outside-facing system that is not your main banking channel: broker portals, agent lookups, field-sales and employee mobile apps, and outsourced development servers. Include web pages that only a mobile app calls.
- Enforce object-level authorisation on the server. Each lookup must check that this agent submitted this application; a valid session alone should never be enough. Use random, non-sequential identifiers, and never let a request reach a record without passing identity verification.
- Return only what the role needs. A broker tracking status does not need income, loan limits or resident registration numbers.
- Put phishing-resistant multi-factor authentication on partner and staff logins, and block passwords that appear in breach corpuses at enrolment.
- Rate-limit per account and per device as well as per IP, and add a daily cap on distinct records each partner account can view.
- Shut what you cannot fix. Shinhan, KB Kookmin and Hana each blocked the attacking addresses and suspended or isolated the service; doing that early is cheaper than a second notification round.
If you find enumeration in your logs, reset every partner and staff credential for the affected system, revoke active sessions and API tokens, and work out from the logs exactly which records were returned, since that is what your notification has to cover.
Our web penetration testing and mobile penetration testing work tests the authorisation checks on broker, partner and staff apps, record by record. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would run the test.
Sources: The Herald Business, ARTEX exclusive, The Herald Business, Shinhan method, Korea Herald, Korea JoongAng Daily, CrowdStrike, Korea JoongAng Daily, Shinhan, Korea Times explainer, Kyunghyang Shinmun, Digital Today, Hana Bank, Digital Today, KB Kookmin, American Banker, Quartz, Tech Times, Insurance Journal, Technology.org, OECD AI incident record.