Monday, Oct 5 | --:--
Back to home
Policy Security

South Korea Traces an Open-Source AI Pen-Testing Tool in a Bank Breach Wave; President Lee Orders Probe

South Korea’s Financial Security Institute says server logs and attack IPs at Shinhan Bank point to ARTEX, an open-source LLM-based penetration-testing tool distributed on GitHub — used by a human attacker, not acting on its own. Shinhan, KB Kookmin, Hana, BNK Busan and several non-bank lenders reported leaks from employee- and partner-facing systems. President Lee Jae Myung ordered a thorough investigation on Oct. 4. The tool’s Chinese-language origin does not identify the attacker: IPs spanned eight countries.

Times of AI Desk 6 min read Seoul View as Markdown
Cover illustration for South Korea Traces an Open-Source AI Pen-Testing Tool in a Bank Breach Wave; President Lee Orders Probe

The first sector-wide breach wave that a national regulator has tied to an off-the-shelf AI attack tool did not need a frontier model. It needed an open-source penetration-testing agent from GitHub and a set of internal bank systems that nobody had hardened.

South Korea’s Financial Security Institute (FSI) told The Herald Business (Oct. 3) that investigators traced attack IPs and server logs at Shinhan Bank, the first lender to report, and found evidence of ARTEX AI: an open-source, LLM-based autonomous penetration-testing system distributed mainly through GitHub and aimed at Chinese-speaking users. The official drew a hard line on autonomy: “It is true that AI was used in the attacks, but the AI did not act independently without human involvement. A hacker used the AI as a tool.” On Sunday, Oct. 4, President Lee Jae Myung ordered a thorough investigation, and the Financial Services Commission (FSC) and Financial Supervisory Service (FSS) convened an emergency meeting with chief executives from across the financial sector.

What was hit

Every reported attack targeted internal employee- or partner-facing systems, not customer internet or mobile banking, according to the FSI official quoted by Herald Business.

Institution Reported exposure System (as reported)
Shinhan Bank about 25,700 people (25,729 per Herald Business; 25,727 per Kyunghyang) loan-agent inquiry service
KB Kookmin Bank 119 records employee mobile work-support system
Hana Bank 89 records employee sales-support system (ODS)
BNK Busan Bank 11 contract workers not specified
Yegaram Savings Bank about 40,000 customers disclosed on its website
Hyundai Capital 146 housing-loan agents not specified

The Korea Times reports leaked fields included names, phone numbers, annual income and loan limits, with some resident registration numbers exposed. The Kyunghyang Shinmun adds Welcome Savings Bank (about 2,200 corporate clients) and two online investment-linked lenders. Herald Business says Woori Bank and NH NongHyup Bank were targeted but not breached because the specific vulnerabilities were absent.

Kyunghyang describes the method as AI-automated brute force: the attacker fed random values into Shinhan’s loan-broker service to find valid customer numbers, then pulled linked records. The FSI official told Herald Business the attacker “did not take over the systems” but extracted data by querying it, so direct fund transfers are unlikely; voice phishing using the leaked data is the stated risk. Attackers kept rotating IPs as each was blocked, but the FSI says a common data signature in ARTEX-originated traffic lets it track them.

The tool, and why it does not name the attacker

Kyunghyang reports that a security researcher spotted the string “ARTEX — autonomous penetration test console” in the HTML title of a server used in the attacks, and that GitHub records show ARTEX was released on July 26, with its latest version on Sept. 24 — three days before the attacks on KB Kookmin began on Sept. 27. The developer is known only by a GitHub handle. Herald Business quotes the FSI official: “There are a great many open-source AI tools like ARTEX. There is currently no way to restrict everything being developed and distributed around the world.”

Attribution is open. FSI head Park Sang-won told reporters, per Kyunghyang, that a China-developed tool alone does not establish the attacker’s nationality, that ARTEX is public worldwide, and that IP hopping makes IP-based attribution impossible; the attacks reportedly used IPs from eight countries, including Korea, the United States, Japan and Hong Kong. The Korea Times says the Shinhan attackers are suspected to be based overseas. Police have opened an investigation.

The policy collision

Herald Business notes the timing: regulators have run an emergency relaxation of Korea’s network-separation rules for AI security testing since June, and the second phase widened this month to 75 firms. Some observers expect the breaches, all on internal systems, to slow that relaxation. The FSC, by contrast, used Sunday’s meeting to push firms toward government AI security testing and AI-based defenses. The FSI is drafting a recommendation for a comprehensive audit of internal employee-facing systems with external access points.

This is a different failure from the OpenAI agent incidents that have dominated recent coverage: there, a lab’s own models wandered during training. Here, according to the regulator, a person aimed a freely available attack agent at peripheral bank systems.

Limits

  • The ARTEX finding is an FSI official’s account by phone to Herald Business; no FSI or FSC written report was available to inspect.
  • Breach counts are bank disclosures relayed by Korean press and differ slightly by outlet; totals may rise as reviews continue.
  • ARTEX’s GitHub release dates and the competition result are Kyunghyang’s reporting; the repository was not inspected for this piece.
  • No attacker has been identified. “Chinese-developed tool” describes the software, not the perpetrator.

Sources

Scroll to continue reading