Seven South Korean banks and financial firms got hit by the same wave of data leaks within days of each other. Shinhan Bank, KB Kookmin, Hana Bank, Busan Bank, savings lenders Yegaram and Welcome, and auto-loan arm Hyundai Capital all reported exposed customer records — roughly 25,000 people at Shinhan, around 40,000 at Yegaram. President Lee Jae-myung ordered a full investigation, and Financial Services Commission chief Lee Eok-won called an emergency meeting of regulators.
The real story here is how it happened. Researchers combing through the Shinhan breach found a Chinese-language string referencing an "AI autonomous penetration-testing console." The tool in question is reportedly Artex AI, an open-source, LLM-based framework built to scan for weaknesses, plan an attack and carry it out largely on its own. Rather than a team of hackers probing the network by hand, something closer to a self-directed script may have done the legwork — learning from each failed attempt and picking the next move itself.
Whoever or whatever was behind it didn't bother storming the heavily guarded core banking systems. They went after the soft targets instead — sales-support platforms and partner-facing tools with weaker defenses. What leaked from there included names, phone numbers, income figures, loan limits, and in some cases national ID numbers, the kind of detail that makes a voice-phishing call sound convincing.
Regulators are choosing their words carefully. "We can't rule out an attack using AI," Lee Eok-won said — notably short of a confirmation. A Chinese-language string sitting in the breach data proves such a tool exists nearby, not that it ran the intrusion on its own. Worth noting too: Woori Bank and NongHyup fended off the same wave without losing data, suggesting uneven readiness between banks mattered as much as whatever tool the attacker used.
The response taking shape is "fight AI with AI" — credential-stuffing detection and a push toward phishing-resistant multi-factor authentication. But if a framework like Artex AI is sitting out there open-source, nothing stops the next attacker, in Korea or anywhere else, from picking it up.



