Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » AI-Assisted Cyberattacks Hit Seven South Korean Banks, Exposing 68,000 Customers

AI-Assisted Cyberattacks Hit Seven South Korean Banks, Exposing 68,000 Customers

Last updated:October 8, 2026
Human Written
  • Hackers broke into at least seven South Korean banks and exposed data linked to about 68,000 people.

  • Investigators found traces of ARTEX, an open-source AI hacking tool built in China, inside the attack systems.

  • Officials say a person used the AI as a tool. The AI did not act on its own.

Hackers Use AI Tool in Attacks on Seven South Korean Banks

South Korean officials are digging into a string of cyberattacks that hit the country’s banks. The attacks exposed personal data tied to roughly 68,000 people. Investigators later found traces of ARTEX inside systems used in some of the break-ins.

ARTEX is an open-source AI tool built for security testing. A Chinese engineer created it. Still, officials have not named the hackers. They also have not tied the attacks to China directly. According to Reuters, South Korean President Lee Jae Myung said signs point to AI use in the recent attacks. He told officials to find out what happened, and fast.

Seven Banks Lost Customer Records

The attacks reached at least seven financial firms. These include Shinhan Bank, KB Kookmin Bank, and Hana Bank. BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank, and Hyundai Capital got hit too.

According to the Financial Times, the hackers mostly went after support systems rather than main banking platforms. These support systems serve bank staff, loan brokers, and outside partners. Customers using the banks’ regular apps and websites were not the direct target.

Even so, the stolen data included names, contact details, income records, and loan limits. That kind of data can help scammers build believable fake messages. Other alleged banking data leaks have also surfaced recently, including a claim involving the sale of 638,000 federal bank records amid unverified breach reports. It can also help them guess answers to security questions.

Researchers Spot the ARTEX Trail

ARTEX sits at the center of the investigation now. Researchers found traces tied to the tool while checking servers linked to the attacks. South Korean broadcaster SBS reported that the name Artex showed up inside a server suspected of helping the bank hacks.

Yonhap also covered the tool. According to Yonhap, ARTEX is an open-source AI system built for penetration testing. Chinese cybersecurity engineer Li Puhua built the tool and released it publicly. Because it is open-source, anyone anywhere can download and run it. That detail matters a lot for the rest of this story.

Many headlines point toward China, but the proof does not reach that far. According to Cyber Kendra, the Financial Security Institute said a human hacker used the AI as a tool rather than letting it run the attack alone.

Officials also warned that IP address locations cannot reliably show where the real attackers are based. Since ARTEX is open-source, its Chinese origin does not identify who actually used it. A tool built in one country can be downloaded and used by someone in a completely different country.

The distinction shows up in online reactions too. On X, Adrian Bertino-Clarke argued that investigators are being more careful than the headlines suggest. He noted that the tool, the person who used it, and the country where it was built are three separate claims.

Sanwal Zia raised a different point. He said AI does not need to hack systems on its own to change the threat. It can simply make existing hackers faster and more capable, he said.

Other users focused on what the hacks could mean going forward. Suhel Shaikh said attackers can now move at machine speed while defenders still respond at human speed. Max Zakharchenko pointed to outside security reviews as a possible weak spot, since automated attacks can move faster than those checks. Migel Tissera asked a sharper question.

He wondered how much real access the hackers actually gained. That question touches something important. An attempted or AI-assisted break-in is not the same as AI taking full control of a bank.

South Korean authorities are still working through the case. For now, one point looks clear. AI appears to have played some role in the attacks, according to Reuters. The exact role ARTEX played, the identity of the hackers, and any wider ties remain under review. Officials say more details should come as the investigation moves forward.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.