Seven financial firms breached as investigation widens
South Korean police have expanded their investigation into a financial sector hacking campaign that reportedly exposed information on about 66,000 individuals and 2,200 corporate records. Investigators suspect attackers used ARTEX, an artificial intelligence tool designed for security testing, while its developer has announced an end to public distribution and updates.
Contents
- Seven financial firms breached as investigation widens
- How the campaign and response unfolded
- What ARTEX does and what investigators found
- AI assistance does not mean an independent attacker
- Evidence pointing to China remains contested
- A Telegram account opens another investigative route
- Ending public ARTEX development cannot recall existing copies
- Peripheral systems and a broader security review
- Fraud safeguards and decisions still pending
- Key Points
The police task force has grown from 28 investigators to 43, with 15 additional personnel assigned to digital forensics and international cooperation. The central questions remain unresolved: who carried out the attacks, how many people participated and precisely how AI contributed to the theft.
Seven institutions have reported breaches: Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. NH NongHyup Bank and Woori Bank were also reportedly targeted, but neither has confirmed a data leak. That distinction helps explain why some accounts describe seven breached institutions while others identify at least nine targets.
Shinhan disclosed that information belonging to 25,729 customers was stolen, including names, phone numbers and income information submitted with loan applications. Yegaram reported about 40,000 affected customers. Together, those two figures total 65,729, nearly the entire reported individual count of about 66,000. Hana reported 89 affected customers, while KB Kookmin reported 119.
Reports differ on the combined exposure. One puts the number at as many as 68,000 customers, while another separates about 66,000 individuals from 2,200 corporate records. Those categories cannot automatically be combined into a count of individual victims. Authorities have not published a reconciled total establishing how many distinct people were affected across all institutions.
The disclosed information varies by bank. Hana said names, personal identification numbers and phone numbers were stolen, but no financial information. Across the wider campaign, exposed records reportedly included annual income, loan limits and loan products. The theft of those details is not the same as the theft of deposits, although it can give fraudsters material for convincing impersonation attempts.
How the campaign and response unfolded
Authorities believe the main attacks occurred from approximately September 27 through October 1. Shinhan is believed to have been hacked on September 30 and disclosed its breach on October 1. Subsequent security findings and the withdrawal of ARTEX from public development have widened the investigation beyond the initial bank disclosures.
- July: ARTEX became freely available on GitHub.
- September: The tool won Baidu's Agent+ attack and defense challenge.
- September 27 to October 1: Investigators place the suspected financial sector attack campaign within this approximate period.
- September 30: Authorities believe the Shinhan breach occurred.
- October 1: Shinhan publicly disclosed the loss of customer information.
- October 8: Developer Autumn-27 announced that ARTEX would stop receiving public updates and move to a private format. A Telegram account under scrutiny was also deleted that day.
- October 11: New findings described possible connections between that account and a Chinese group selling attacks that overwhelm online services.
The initial police deployment comprised 28 investigators across four teams from the National Police Agency's Cyber Terror Investigation Unit. The later expansion to 43 represents an increase of about 54 percent, with the additional staff focused on recovering digital evidence and working across borders.
What ARTEX does and what investigators found
ARTEX is not a large language model itself. It is an automation platform that connects to external models, including ChatGPT, Claude and DeepSeek, and uses their outputs to coordinate security testing tasks. A penetration test is an authorized attempt to find weaknesses before a malicious attacker exploits them.
The tool was created by Chinese cybersecurity engineer Li Puhua, who uses the alias Autumn and the GitHub handle Autumn-27. Its design allows AI agents to gather information about targets, search for vulnerabilities, plan routes into systems, run security tools and verify weaknesses. The same sequence can serve legitimate testing or an unauthorized intrusion, depending on who directs it and whether permission exists.
Moon Jong-hyun, head of the security center at South Korean cybersecurity firm Genians, identified an ARTEX console label in HTML headers on servers believed to have controlled the attacks. The label read "ARTEX - 自主渗透测试控制台," identifying an autonomous penetration testing console. Such traces support an assessment that the software was present, but they do not establish the operator's identity.
CrowdStrike assessed that the attacker likely used ARTEX with Anthropic's Claude and Claude Code. Other investigative accounts describe the use of multiple models, including DeepSeek, alongside ARTEX. These accounts point to a combination of tools rather than a single AI system acting alone; a complete account of which models performed which tasks has not been established.
AI assistance does not mean an independent attacker
The distinction between automation and human responsibility is central to the case. AI can shorten the time needed to inspect systems, interpret results and prepare code, while a person still chooses targets and directs the operation. Evidence of AI use does not establish that the entire intrusion proceeded without human decisions.
An official with the Korea Financial Security Institute described the role of human direction in the attacks:
It is true that AI was used in the attacks, but the AI did not act independently without human involvement. A hacker used the AI as a tool.
CrowdStrike said AI session records included questions about where stolen Korean breach information is usually sold and requests for help finding Korean Telegram groups used for data sales. Those requests contributed to its assessment that the activity was financially motivated. They do not, by themselves, establish that the stolen records were actually sold.
Kim Seung-joo, a professor at Korea University's School of Cybersecurity, warned that tools such as ARTEX could make attacks accessible to people with less technical experience:
AI hacking tools will continue to emerge, making it easier for nonexperts to carry out attacks. As a result, these attacks will become more frequent.
The practical concern is speed and scale. An operator can use agents to inspect several organizations in succession instead of performing every task manually. That does not remove the need for exploitable weaknesses, access routes or human judgment, but it can reduce the effort required to pursue them.
Evidence pointing to China remains contested
CrowdStrike assessed that the suspected operator was likely a Chinese speaker, financially motivated and based in Guangdong Province. It assigned moderate confidence to its assessment, rather than presenting the attribution as certain.
Part of the identification came from a Claude session requesting a security researcher resume. The session included an age of 26, a location in Maoming, educational details and a Telegram account. CrowdStrike considered those details likely to belong to the attacker. The person associated with the published phone number denied involvement and said personal information had been used without permission.
The Financial Supervisory Service identified 28 IP addresses linked to hacking attempts. Accounts differ on their geographical spread: one describes roughly a dozen countries, while another lists the United States, Japan, Germany and at least 10 other countries. Investigators also reportedly identified control servers in Hong Kong, separate attack servers and alternative access routes.
An IP address identifies an internet connection or server location, not necessarily the person controlling it. Likewise, using software made by a Chinese developer does not prove that an attacker is Chinese. Aditya Das, an analyst at Brave New Coin, cautioned against making that inference from ARTEX alone.
Chinese Foreign Ministry spokeswoman Mao Ning said the ministry was unfamiliar with the specific case and that China consistently opposed and combated hacking. No confirmed identity or finding of state involvement has been announced.
A Telegram account opens another investigative route
Separate security analysis connected the Telegram account YY520CN to GodNet, an online community created by Vitas, a Chinese group that sells distributed denial of service attacks. These attacks flood a service with traffic to make it unavailable. That activity differs from stealing bank records, so a community connection is an investigative lead, not proof that the group conducted the breaches.
The account appeared on a GodNet moderator list in September 2024. Analysis cross checked Telegram membership information, GitHub activity and credentials exposed by malware that steals passwords. YY520CN was deleted on October 8 after its name became public through analysis of AI usage records on a server linked to the attacks.
A new account subsequently appeared with the same username, and an associated channel posted a denial. It is unclear whether the same person controlled the original and replacement accounts. The phone number owner's denial creates a further identification problem that investigators have not resolved.
Analysis of a second GodNet member found an email address in GitHub editing history linked to credentials stolen in 2023. Those records included Microsoft and Oracle cloud login details, suggesting the account holder might have helped operate the group's technical systems.
The second member has not been directly linked to the bank intrusions. Comparing stolen credentials with cloud subscriber records could provide another route to identifying account operators, but the account connections do not establish who committed the theft or whether one person was responsible.
Ending public ARTEX development cannot recall existing copies
On October 8, Autumn-27 announced that ARTEX would become closed source, with no further public versions or maintenance support. The developer cited misuse of the tool, although the announcement did not directly name the South Korean financial sector attacks. Its GitHub page was subsequently reported to have disappeared.
The developer also said illegal use conflicted with the project's intended purpose and disclaimed responsibility for violations committed by users. Before its withdrawal, the project described its purpose as personal learning, code research and local technical verification, rather than testing online systems without authorization.
Ending public distribution limits future access through the original project and ends its public maintenance. It cannot delete copies that users have already downloaded or prevent those copies from continuing to operate. The announcement is therefore a change in the software's distribution, not evidence that the attack capability has disappeared.
The decision also leaves a distinction between the original developer and whoever allegedly used the software against banks. Investigators still need to connect infrastructure, accounts and actions to identifiable operators. A tool's origin and its developer's withdrawal do not resolve that task.
Peripheral systems and a broader security review
The suspected access routes point beyond core banking networks. Weak authentication in loan recruiter portals, employee mobile tools and sales support systems has been identified as a possible problem. Protecting payment systems does not necessarily protect every application that stores customer information or supports loan processing.
Hyobin Lee, a professor at Sogang University, identified auxiliary systems as an area receiving less attention:
Some auxiliary systems, such as loan agent information portals and internal mobile applications used by employees, appear to have received less security attention.
Continuous attack surface management is one proposed response. It means maintaining an inventory of systems reachable from outside an organization and checking them for exposed services, weak access controls and vulnerabilities. AI can assist that work, but the response also requires correcting the weaknesses it finds.
President Lee Jae Myung called for faster development and deployment of AI for cybersecurity, an immediate review of critical systems and stronger protection for national infrastructure. Describing the urgency of the response, Lee said:
Speed is of the essence.
Reports differ in their attribution of Cabinet warnings. Some identify President Lee as the speaker calling for an AI security overhaul; another attributes warnings about further leaks and risks beyond finance to Prime Minister Han Seong-sook. The reported policy direction is consistent: broader checks and action before another incident, rather than a response confined to repairing damage afterward.
Two major churches and Korea Electric Power Corp. also confirmed unauthorized access to online systems. Whether those incidents were connected to the bank campaign is unknown. Their disclosure broadens the immediate security concern without establishing a single attacker or common method.
Fraud safeguards and decisions still pending
The Financial Services Commission and Financial Supervisory Service said there were no confirmed cases of financial damage or stolen money resulting from phishing using the leaked data. They advised depositors not to be excessively concerned about the safety of their funds. That statement concerns confirmed losses at the time, not a guarantee against later fraud.
Names, phone numbers, income details and knowledge of a recent loan application can help a scammer impersonate a bank employee. Hyobin Lee also warned that stolen information can be combined with other leaked databases, extending the risk beyond the initial breach.
Regulators ordered banks to establish help desks for affected customers, use the AI based Anti-Phishing Sharing and Analysis Platform, temporarily increase fraud monitoring and provide remedies and compensation to customers who suffer fraud. Shinhan apologized and created a page where customers could check whether they were affected.
Financial firms agreed to review online loan applications, new account openings and large transfers involving information linked to breach victims. Additional identity checks are to be required when needed. Regulators are also reportedly considering more thorough audit requirements.
The Financial Supervisory Service shared the 28 suspicious IP addresses with financial firms and asked them to complete checks and correct weaknesses by Thursday following its announcement. No consolidated results from those checks have been reported, and no further dated public deadline has been identified.
Police have asked the Financial Services Commission whether the affected systems qualify as electronic financial infrastructure. That classification could trigger a requirement to notify the newly established Serious Crimes Investigation Agency and affect whether the case is transferred. A determination has not been announced.
The next substantive developments are therefore the identification of the operators, reconciliation of victim totals, findings on the entry routes and a decision on investigative responsibility. None is settled by the evidence of ARTEX use alone.
Key Points
- Seven financial institutions reported breaches; two more were reportedly targeted without confirmed data leaks.
- Reported exposure includes about 66,000 individuals and 2,200 corporate records, while another account gives as many as 68,000 customers.
- The police task force expanded from 28 to 43 investigators.
- Evidence points to human operators using ARTEX and external AI models, not an AI system acting independently.
- Identity claims and possible links to a Chinese attack community remain unconfirmed and disputed.
- ARTEX's developer ended public updates, but existing downloaded copies can still be used.
- Regulators reported no confirmed phishing losses from the leaked data and ordered stronger monitoring and identity checks.






