Skip to content

Mon - Fri: 10.00 - 5.00

[email protected]

Delana Technologies

Delana Technologies

Delana Technologies delivers expert cybersecurity, cloud, and AI-driven IT strategy solutions. Transform your enterprise securely and intelligently.

  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions
  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions

Mon - Fri: 10.00 - 5.00

[email protected]

AI Hackers Took the Side Door: South Korea’s Bank Breaches, the ARTEX Tool and 66,000 Exposed Records (AI Trends, 5 October 2026)

  1. Home   »  
  2. AI Hackers Took the Side Door: South Korea’s Bank Breaches, the ARTEX Tool and 66,000 Exposed Records (AI Trends, 5 October 2026)

AI Hackers Took the Side Door: South Korea’s Bank Breaches, the ARTEX Tool and 66,000 Exposed Records (AI Trends, 5 October 2026)

October 5, 2026October 5, 2026 admincybersecurity, UncategorizedTagged AI cyberattacks, AI security, AI trends, ARTEX AI, attack surface management, credential stuffing, data breach, financial services security, phishing, Shinhan Bank, vulnerability management

What’s trending in AI on 5 October 2026: South Korea is dealing with what local media are calling the first large AI-assisted hacking wave against its banking sector. Over several days at the end of September, attackers broke into systems at Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank and Hyundai Capital, with Welcome Savings Bank investigating a suspected breach. Together the confirmed leaks cover more than 66,000 people. Where the entry point has been reported, the attackers did not go through the banks’ main, heavily defended systems. They went through side doors: a loan-broker lookup page, an employee mobile app, a sales-support tool. Investigators found traces of ARTEX AI, an open-source, Chinese-language tool that uses AI agents to run penetration tests automatically. On Sunday, President Lee Jae Myung ordered a full investigation, and regulators gave every financial firm days to inspect all of its internet-facing systems. This post explains what happened, what is confirmed and what is not, why the “side door” pattern matters far beyond Korea, and a 10-question scorecard you can run on your own business this week.

Key takeaways

  • Seven financial firms, one pattern. Every breach with a reported entry point came through a peripheral system, not core banking. Woori Bank and NH NongHyup Bank were also targeted but blocked the attempts.
  • Real customer data is out. Shinhan’s leak of about 25,700 records included names, phone numbers, annual income, loan limits and some resident registration numbers. Yegaram reported about 40,000 customers affected.
  • The AI link is strong but not proven. A server tied to the attack carried the title of the ARTEX AI console, and investigators say its traffic has a recognizable signature. Officials have not formally confirmed the tool was used.
  • The tool is two months old and free. ARTEX appeared on GitHub on 26 July 2026 and was last updated on 24 September, days before the attacks.
  • The lesson travels. AI makes it cheap to probe every small, forgotten web portal you own. Your weakest login page is now your real perimeter.
AI hackers took the side door: South Korea’s bank breachesTitle card. Headline: AI hackers took the side door. Subhead: South Korea’s bank breaches and the ARTEX tool. Three tags: 7 financial firms breached or investigating; more than 66,000 people’s data exposed; traces of an open-source AI penetration-testing tool. Illustration of a bank building with a locked, glowing main door and a small open side door highlighted in orange. CORE SYSTEMS HELDSIDE DOOR OPEN AI TRENDS · 5 OCTOBER 2026 AI hackers tookthe side door South Korea’s bank breaches and the ARTEX tool 7 financial firms breached or investigating More than 66,000 people’s data exposed Traces of an open-source AI hacking tool Sources: Bloomberg via Claims Journal, The Herald Business, Korea Times, Kyunghyang Shinmundelana.co
The banks’ main systems held. The loan-broker portals and staff apps around them did not.

1. What happened

The first public sign came from Shinhan Bank, one of Korea’s largest lenders. According to Financial News, Shinhan said on 30 September that personal data on about 25,000 customers had leaked after someone gained unauthorized access to a service used by loan recruiters, the outside agents who find borrowers for the bank, and got around its identity checks. Bloomberg, cited by Claims Journal, reports the exposed data included names, phone numbers, annual income and borrowing limits. The Herald Business puts the exact count at 25,729 and adds resident registration numbers, Korea’s equivalent of a national ID number, to the list.

Within days it became clear Shinhan was not alone. KB Kookmin Bank reported data on 119 people exposed through an employee mobile work-support system, and Hana Bank reported 89 records taken from an internal sales-support system. BNK Busan Bank found records on 11 outsourced developers exposed. Yegaram Savings Bank disclosed about 40,000 affected customers, Hyundai Capital said information on 146 mortgage-loan brokers was exposed through a broker inquiry page, and Welcome Savings Bank began investigating a suspected leak involving corporate customers. The Herald Business reports that Woori Bank and NH NongHyup Bank were also attacked but blocked the intrusions.

The response escalated quickly. The Financial Services Commission (FSC) held an emergency meeting on 3 October. On Sunday 4 October, President Lee ordered a thorough investigation, his spokesperson saying he acted “with a grave awareness of the seriousness of the matter,” according to the Korea Times. The National Police Agency’s cyber unit has opened a preliminary investigation, and the Financial Supervisory Service sent inspectors into Shinhan.

Records exposed by institutionHorizontal bar chart of people affected by institution, as reported. Yegaram Savings Bank about 40,000 customers. Shinhan Bank 25,729 customers. Welcome Savings Bank about 2,200 corporate clients, under investigation. Hyundai Capital 146 mortgage-loan brokers. KB Kookmin Bank 119 people. Hana Bank 89 people. BNK Busan Bank 11 outsourced developers. Woori Bank and NH NongHyup Bank: attacks blocked, no data exposed. Total confirmed: more than 66,000 people. Who was hit, and how many people People whose data was exposed, as reported by 5 October 2026 Yegaram Savings BankShinhan BankWelcome Savings BankHyundai CapitalKB Kookmin BankHana BankBNK Busan BankWoori & NH NongHyup ~40,000 customers25,729 customers~2,200 corporate clients (investigating)146 mortgage-loan brokers119 people (staff app)89 people (sales system)11 outsourced developers Attacks blocked, no data exposed Confirmed total: more than 66,000 people. Securities firms, insurers and card companies were not hit. Sources: The Herald Business, Korea JoongAng Daily, Korea Times, Kyunghyang Shinmun, IBTimesdelana.co
Two lenders account for most of the exposed records. Counts may rise as investigations continue.

2. Every breach came through a side door

The striking thing about this wave is where the attackers got in. Korean banks spend heavily on securing core banking: the Korea Times reports the three largest banks spent a combined 124 billion won, about $92 million, on information security last year. None of that spending was bypassed head-on. Instead, the attackers found systems built for partners, contractors and staff on the move, which are exposed to the internet by design and rarely get the same scrutiny.

InstitutionEntry point reportedWho was exposedStatus
Shinhan BankSimplified inquiry service for loan recruiters, identity check bypassed25,729 customersBreach confirmed; on-site inspection
KB Kookmin BankEmployee mobile work-support system119 peopleBreach confirmed
Hana BankInternal sales-support system89 peopleBreach confirmed
BNK Busan BankSystems tied to outsourced development staff11 developersBreach confirmed
Hyundai CapitalMortgage-loan broker inquiry page146 brokersBreach confirmed
Yegaram Savings BankNot detailed in reportsAbout 40,000 customersBreach disclosed
Welcome Savings BankNot detailed in reportsCorporate customersSuspected; under investigation
Woori, NH NongHyupTargetedNoneIntrusions blocked
Compiled from The Herald Business, Korea JoongAng Daily, IBTimes and the Kyunghyang Shinmun. Figures differ slightly between outlets; we use the most specific number reported.

Professor Lim Jong-in summed up the approach to the Korea Times: AI agents hunt automatically for weaknesses and go after partner-facing servers rather than the banks’ main systems. The Kyunghyang Shinmun describes the method in plain terms: the attackers hit many financial firms at once with AI and broke into the ones whose defenses were weaker. If that sounds familiar, it is the same lesson as the Australian Medicare breach: the forgotten web form, not the vault, is what gets you.

Front door versus side doorDiagram. On the left, an attacker using an AI tool with rotating IP addresses. Arrows lead to two paths. The front-door path, in teal, goes to core banking with strong authentication and is marked held. The side-door path, in orange, branches to four peripheral systems: loan-broker inquiry pages, employee mobile apps, sales-support systems and contractor or outsourced developer access. These lead to customer data: names, phone numbers, income, loan limits and some national ID numbers. A footer says the attackers did not need to beat the bank’s best defenses, only its weakest exposed system. Front door held. Side doors did not. How the reported attacks reached customer data AttackerAI pen-test toolrotating IP addressesmany targets at once Core bankingstrong authentication HELD Loan-broker inquiry pagesEmployee mobile work appsSales-support systemsContractor / outsourced access Customer data outnames, phone numbersannual income, loan limitssome national ID numbersno payment data reported They did not need to beat the best defenses, only the weakest exposed system Sources: The Herald Business, Korea Times, Kyunghyang Shinmun, Seoul Economic Dailydelana.co
Partner portals and staff apps are on the internet by design, and AI makes probing all of them cheap.

3. What is ARTEX AI, and is it really to blame?

The AI angle surfaced on 2 October, when Mun Chong-hyun, head of the security center at Korean firm Genians, posted that a web server linked to the Shinhan attack displayed a page title naming the “ARTEX-AI Autonomous Penetration Testing Console,” Financial News reports. ARTEX is an open-source system, written for Chinese-speaking users, in which several AI agents split up the work of a penetration test: gathering information, finding vulnerabilities, planning an attack path, running tools and checking the results. Financial News says it won a Baidu Security Response Center challenge this year. According to the Kyunghyang Shinmun, a developer using the handle “Autumn-27” released it on GitHub on 26 July 2026 and pushed the latest version on 24 September, only days before the attacks.

The Herald Business then reported that the Korea Financial Security Institute, which is leading the technical probe, had tied the wave to ARTEX through a data signature common to the tool’s traffic, and that the attacker switched IP addresses whenever one was blocked. The institute has shared the attacker’s addresses across the sector. Reports also describe two techniques that fit an automated tool well: credential stuffing, where stolen username and password pairs are tried at scale, and feeding random values into Shinhan’s broker service until valid customer numbers turned up, after which other details could be pulled.

Now the caveats. Financial News stresses that the evidence available so far is not enough to conclude ARTEX was actually used, and neither Shinhan nor the regulators have formally confirmed it. FSC Chairman Lee Eog-weon said “the possibility of AI-powered attacks cannot be ruled out,” according to the Korea JoongAng Daily, which is careful wording. A tool that was originally built for defenders could also have been found on attacker infrastructure without doing all of the work. Who is behind the attacks has not been established either; reports refer to suspected overseas attackers using Chinese-language tools, which is not the same as attribution to a state.

How an autonomous AI penetration-testing tool worksFive-step pipeline as described for ARTEX AI: 1, information gathering; 2, vulnerability discovery; 3, attack-path design; 4, tool execution; 5, verification. A loop arrow returns from verification to information gathering. Below, a note that a human still directs the tool, and a defender’s view: each stage leaves traces you can detect, such as bursts of requests, many failed logins and enumeration of ID numbers. Inside an autonomous pen-testing tool The stages ARTEX AI assigns to its AI agents, per Financial News 12345 InformationgatheringVulnerabilitydiscoveryAttack-pathdesignToolexecutionVerificationand repeat The attacker’s viewA human still points it at targets, but oneoperator can now probe dozens of firms at once. The defender’s viewEvery stage is noisy: request bursts, failedlogins, ID enumeration. Watch for them. Sources: Financial News, The Herald Business, Kyunghyang Shinmundelana.co
Automation removes the labor from hacking, not the footprints. That is the defender’s opening.

4. Why this matters beyond Korea

Whether or not ARTEX did the heavy lifting, the Korean wave matches what the data has been saying all autumn. Microsoft’s latest report found that AI has handed attackers the head start, with flaws now weaponized in well under 24 hours. Last week, government testers found an open-weight model could already perform elite-level hacking tasks, and AI-found flaws are now being exploited within a day of disclosure. Korea is the first place where those warnings showed up as a coordinated, multi-bank incident with customer data on the table.

Three things change when probing is cheap. First, size stops protecting you: a tool that can test seven banks in a week can test seven hundred small firms just as easily. Second, “low-value” systems stop being low-value. A broker lookup page that only returns a name and a loan limit is exactly what a scammer needs. Third, open-source security tools cut both ways. Genians’ Mun warned that source code is being “shared indiscriminately” for malicious AI hacking, Bloomberg reports. The same tools defenders use for testing are a download away for attackers.

The fallout for customers is also instructive. FSC Chairman Lee said there was no sign that payment data leaked, but the Korea Times reports he warned that voice phishing and smishing risks remain. NordVPN’s Korea manager Sungho Hwang told Bloomberg the breach is worrying because it “exposed both personal and financial information.” Knowing someone’s income and loan limit makes a fake “loan offer” call far more convincing, and AI makes those calls cheap to run at scale, a pattern we covered in deepfakes are on the rise.

Timeline of the Korean bank hacking waveTimeline. 26 July 2026: ARTEX AI released on GitHub. 24 September: latest ARTEX version published. Around 27 September to 1 October: attacks on multiple financial firms. 30 September: Shinhan discloses about 25,000 customers affected. 2 October: Genians flags ARTEX traces on attack server. 3 October: Financial Services Commission emergency meeting. 4 October: President Lee orders thorough investigation. Upcoming, in orange: 6 October, deadline for banks and card companies to inspect internet-facing IT assets; 8 October, deadline for securities firms, insurers and savings banks. From a GitHub release to a presidential order Key dates, July to October 2026 26 Jul24 Sep~27 Sep–1 Oct30 Sep2 Oct3 Oct4 Oct 6 Oct8 Oct ARTEX AIreleasedon GitHub Latest ARTEXversion Attack wavehits multiplefinancial firms Shinhan discloses~25,000 affected Genians flagsARTEX traceson attack server FSC emergencymeeting President Leeorders thoroughinvestigation Banks, cardfirms inspectexposed ITSecurities,insurers, savingsbanks deadline About two months from a free tool’s release to a national banking incident Sources: Kyunghyang Shinmun, Financial News, The Herald Business, Korea Times, IBTimesdelana.co
The attack window is approximate; reports describe it as running over several days in late September.

5. What Korea’s regulators are demanding

Korean authorities are treating this as a sector-wide problem, not a Shinhan problem. According to IBTimes, financial firms were told to inspect every externally exposed IT asset, with banks and card companies given until 6 October and securities firms, insurers and savings banks until 8 October. The Herald Business reports banks were handed vulnerability checklists for self-assessment, and the Korea JoongAng Daily says the FSC told firms to review their entire security systems and close any gaps.

Regulators are also leaning into fighting AI with AI. GBHackers reports the authorities called for AI-based security testing and detection models, alongside phishing-resistant multi-factor authentication. Korea’s Seoul Economic Daily argued in an editorial for full vulnerability assessments, stronger anomaly detection, faster sharing of confirmed weaknesses across firms and regular attack drills. None of these ideas is new. What is new is the urgency, and the admission, in the Korea Times’ framing, that the sector’s cyber defenses are lagging the technology now pointed at them.

6. The side-door scorecard: 10 yes-or-no questions for your business

Korea’s regulators effectively asked every financial firm one question: what do you have on the internet that you have forgotten about? You can run the same exercise in an afternoon. Answer each question yes or no. Every “no” is a side door, and the note after it is the fix.

  1. Do you have a complete list of every internet-facing login page, portal and API you run, including ones built for partners, brokers, resellers or contractors? If no: build it this week from DNS records, certificate logs and your cloud accounts, not from memory.
  2. Does every one of those systems have a named owner? If no: assign one, or switch the system off. Orphaned portals are the ones nobody patches.
  3. Do partner and staff portals require the same strength of login as your main customer system? If no: add phishing-resistant MFA or passkeys, starting with anything that returns personal or financial data.
  4. Would you notice thousands of failed logins from rotating IP addresses in an hour? If no: turn on alerting for credential stuffing. Our guide to credential and identity theft explains the signals.
  5. Are your lookup forms protected against enumeration, so nobody can cycle through customer or account numbers? If no: add rate limits, bot challenges and IDs that cannot be guessed in sequence.
  6. Do inquiry pages return only the minimum data needed? If no: strip income, limits and ID numbers from any response that does not strictly need them. What is never shown cannot leak.
  7. Do all exposed web apps sit behind a web application firewall with bot management turned on? If no: an edge WAF is the cheapest way to stop most automated attacks before they start.
  8. Do contractors and outsourced developers lose access the day their work ends? If no: review third-party accounts monthly. Busan Bank’s leak involved outsourced staff, and our piece on SaaS supply-chain attacks covers why partner access is so often the weak link.
  9. Have you tested your own exposed systems with automated tools in the last 90 days? If no: commission a test, or run an authorized scan yourself. Attackers are already running these tools against you; you should see the results first.
  10. Do you have a ready-to-send customer warning about follow-up scam calls and texts if data leaks? If no: draft it now. In Korea, the biggest risk after the breach is voice phishing that uses the stolen details.

Scoring is simple. Eight or more “yes” answers means your side doors are mostly locked. Five to seven means you have a project for this quarter. Four or fewer means the Korean scenario applies to you today, whatever your size.

7. What to watch next

Four things will shape how this story ends. First, the official findings: whether the Korea Financial Security Institute and the police formally confirm ARTEX, or another tool, and whether the attacker is identified. Second, the final count, since several firms are still investigating and early numbers in breaches like this often rise. Third, the results of this week’s inspections, which could surface more exposed systems or quiet breaches. Fourth, what the government does next on rules: Korea’s regulators have signaled they will rethink security requirements for the AI era, and any new standard for peripheral and partner-facing systems would be worth copying elsewhere. Also watch GitHub. If ARTEX or similar projects are taken down or restricted, expect the debate over open-source offensive AI tools to move quickly from Seoul to Washington and Brussels.

Frequently asked questions

Which South Korean banks were hacked?

Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank and Hyundai Capital have reported breaches, and Welcome Savings Bank is investigating a suspected one. Woori Bank and NH NongHyup Bank were targeted but blocked the attacks.

How many people were affected by the Korean bank breaches?

More than 66,000 people, based on figures reported by 5 October 2026. Most come from Yegaram Savings Bank, with about 40,000 customers, and Shinhan Bank, with 25,729. The total may change as investigations continue.

What is ARTEX AI?

ARTEX AI is an open-source, Chinese-language penetration-testing system in which several AI agents handle reconnaissance, vulnerability discovery, attack planning, tool execution and verification. It was released on GitHub in July 2026. Traces of it were found on a server linked to the Shinhan attack.

Was AI definitely used in the attacks?

Not officially. Investigators found ARTEX traces and say its traffic has a recognizable signature, but Shinhan and the regulators have not formally confirmed the tool was used, and the FSC chairman said only that AI-powered attacks could not be ruled out.

What data was stolen, and was any money taken?

Reported data includes names, phone numbers, annual income, loan limits and, in some cases, resident registration numbers. Regulators say there is no sign that payment data leaked or that money was taken, but they warn of follow-up voice phishing and text scams.

What should businesses outside Korea learn from this?

That AI makes it cheap to probe every exposed system, so your weakest portal sets your real security level. Inventory internet-facing systems, give partner and staff portals strong authentication, block enumeration and credential stuffing, limit the data each page returns and prepare customer scam warnings in advance.


Sources

  • Claims Journal (Bloomberg): AI tools suspected in Korea’s Shinhan Bank hack, Yonhap says
  • The Star: AI tools flagged in cyberattack on S. Korea’s Shinhan Bank
  • Financial News: Traces of Chinese-language AI penetration tool found on Shinhan Bank’s hacked server
  • The Herald Business: Five major banks hit by suspected AI-assisted hacking
  • The Herald Business: Chinese AI tool ARTEX used in wave of bank hacks, probe finds
  • The Kyunghyang Shinmun: Korean finance breached by a two-month-old Chinese AI
  • Korea Times: Lee orders thorough probe into data breaches at local banks
  • Korea Times: AI-powered attacks on banks expose technological lag in Korea’s financial cyber defenses
  • Korea JoongAng Daily: President Lee orders probe into cyberattacks on Korean banks
  • IBTimes: South Korea orders security checks after data leaks hit 7 financial firms
  • GBHackers: South Korea orders investigation into AI-powered cyberattacks on major banks
  • Seoul Economic Daily: Unprecedented AI hacking hits banks, security overhaul needed

Post navigation

Previous: Washington Picked Speed: Trump’s Super Intelligence Force, a Spy Chief as AI Czar and Altman’s “Accept Some Bad Things” (AI Trends, 5 October 2026)

Florida Service Location

  • Cybersecurity, AI Consulting & IT Services in West Palm Beach, Florida
  • Cybersecurity, AI Consulting & IT Services in Sarasota, Florida
  • Cybersecurity, AI Consulting & IT Services in Port St. Lucie, Florida
  • Cybersecurity, AI Consulting & IT Services in Pembroke Pines, Florida
  • Cybersecurity, AI Consulting & IT Services in Naples, Florida
  • Cybersecurity, AI Consulting & IT Services in Miramar, Florida
  • Cybersecurity, AI Consulting & IT Services in Miami, Florida
  • Cybersecurity, AI Consulting & IT Services in Hollywood, Florida
  • Cybersecurity, AI Consulting & IT Services in Hialeah, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Myers, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Lauderdale, Florida
  • Cybersecurity, AI Consulting & IT Services in Cape Coral, Florida
  • Cybersecurity, AI Consulting & IT Services in Boca Raton, Florida
  • Cybersecurity, AI Consulting & IT Services in Coral Springs, Florida

Technology Services

  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions
  • Case Studies
  • Home
  • Contact Us
  • Privacy Policy
  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions

© Copyright 2025 Delana Technologies LLC