South Korea Orders Investigation Into AI-Powered Cyberattacks on Major Banks
South Korea's president ordered an investigation into breaches at major banks exposing ~65,000 customers' data; infrastructure tied to AI pen-testing framework ARTEX AI.
President Lee Jae Myung ordered a comprehensive investigation after Shinhan Bank disclosed a breach affecting about 25,000 customers, with KB Kookmin, Hana Bank, BNK Busan Bank, Yegaram Savings Bank (~40,000 customers) and Hyundai Capital (146 loan agents) also reporting exposures. Leaked data included names, phone numbers, annual income, loan limits and some resident registration numbers, though no payment credentials or unauthorized transactions were found. Investigators found a Chinese-language string reading 'AI autonomous penetration testing console' on infrastructure linked to the Shinhan intrusion, associated with the open-source ARTEX AI framework, but actual use of the tool is unproven; reports tie the incident to credential stuffing. The Financial Services Commission held an emergency sector-wide meeting and regulators are pushing AI-driven detection, credential-stuffing monitoring, and phishing-resistant MFA.
- Shinhan breach hit ~25,000 customers; KB Kookmin, Hana, BNK Busan, Yegaram (~40,000) also affected
- Exposed data includes income, loan limits and resident registration numbers; no payment credentials leaked
- Intrusion infrastructure carried string linked to open-source ARTEX AI pen-testing framework; use unconfirmed
- Credential stuffing suspected at Shinhan; leaked profiles could enable voice phishing and fraud
- FSC emergency meeting; regulators demand AI-driven detection and phishing-resistant MFA
Full article538 words · extracted from gbhackers.com · click to collapse
South Korean President Lee Jae Myung has ordered a comprehensive investigation into a series of data breaches impacting major banks and other financial institutions. Concerns have been raised that attackers may have utilized AI-enabled offensive security tools.
These incidents have prompted emergency regulatory action and a sector-wide effort to strengthen defenses against increasingly automated intrusions.
The investigation began after Shinhan Bank disclosed a breach that affected about 25,000 customers. Following this, KB Kookmin Bank, Hana Bank, and BNK Busan Bank reported separate incidents of personal data exposure, widening the crisis across South Korea’s financial sector.
The exposed data reportedly included names, telephone numbers, annual income information, and loan limit details. In some cases, victims’ resident registration numbers were also compromised.
The breaches extended beyond commercial banks; Yegaram Savings Bank reported a breach involving around 40,000 customers, while Hyundai Capital revealed that personal information belonging to 146 housing-loan agents was exposed.
While authorities have not identified any leaked payment credentials or evidence of unauthorized transactions, they have cautioned that the stolen records could facilitate secondary fraud, particularly through targeted voice phishing and social engineering schemes.
Investigators are looking into whether AI-based attack automation played a role, especially in the Shinhan Bank incident. Security researchers found a Chinese-language string translated as “AI autonomous penetration testing console” in the HTML title of infrastructure believed to be linked to the intrusion.
This string has been linked to ARTEX AI, an open-source, large language model-based penetration testing framework.
ARTEX AI is designed to automate various stages of penetration testing, including reconnaissance, vulnerability discovery, attack-path planning, security tool execution, and validation.
However, the presence of the associated string does not definitively prove that the framework was used in the attacks or that AI autonomously conducted the intrusions. The tool is publicly available, and attribution is still under investigation.
Reports from KoreaTimes have also connected the Shinhan incident to credential stuffing, where attackers automate login attempts using previously compromised account credentials to find valid access points.
AI-assisted reconnaissance or orchestration could make such campaigns quicker, more adaptable, and harder to distinguish from legitimate user activity.
The Financial Services Commission and the Financial Supervisory Service held an emergency meeting with leaders from banks, securities firms, insurers, card issuers, savings banks, and fintech companies.
Chairman Lee Eog-weon of the Financial Services Commission urged the industry to remain vigilant, conduct internal security inspections, and promptly protect affected customers.
President Lee has instructed officials to thoroughly investigate the incidents and formulate countermeasures, emphasizing a serious awareness of their severity. The National Police Agency has also begun a preliminary investigation into the attacks affecting Shinhan, KB Kookmin, Hana, and BNK Busan banks.
Regulators are calling on financial institutions to expedite “AI attacks responding with AI” security initiatives.
These include AI security testing and AI-driven detection models. Immediate priorities include monitoring for credential stuffing, enforcing phishing-resistant multifactor authentication, identifying abnormal data access, and alerting customers who may be targeted using leaked financial profile information.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.