AI banking hacks moved from a security-industry worry to a presidential warning in South Korea this week. On Tuesday 6 October, President Lee Jae Myung told a cabinet meeting that “there are signs that artificial intelligence was used in some hacking attacks”, as police opened a formal investigation into a run of breaches at the country’s lenders.
The numbers are already large. Seven financial firms, including Shinhan Bank, KB Kookmin Bank and Hana Bank, have confirmed leaks since 1 October, and the Financial Services Commission puts the total at more than 68,000 records. Investigators have found traces of ARTEX AI, an open-source security testing tool that uses a large language model, on the addresses used in the attacks. Officials still call the AI link “possible”, and they are careful to say the tool says nothing about who used it.
This article sets out what the AI banking hacks exposed, how the week unfolded, what ARTEX AI is, how the attackers got in at a high level, why two big banks facing the same attack lost nothing, and what UK banks and smaller firms should copy from the lenders that held.
Table of contents
- What President Lee Said About the AI Banking Hacks
- Seven Firms, 68,000 Records: Counting the AI Banking Hacks
- Timeline of the AI Banking Hacks: 30 September to 7 October
- What ARTEX AI Is and Why the AI Link Is Still “Possible”
- How the Attackers Got In: Side Doors, Not the Vault
- Why Woori and NH Nonghyup Held During the AI Banking Hacks
- Seoul’s Response to the AI Banking Hacks
- How the AI Banking Hacks Fit a Wider Pattern
- What UK Firms Should Take From the AI Banking Hacks
- AI Banking Hacks: Frequently Asked Questions
- References
What President Lee Said About the AI Banking Hacks
Lee’s remarks were brief, but they moved the story. Until Tuesday, the AI angle rested on investigators’ findings, hedged regulator statements and industry experts. A head of state saying it at a cabinet meeting made it a national policy concern.
The cabinet meeting remarks
According to AFP’s translation, Lee said the hacking was “causing considerable concern and anxiety among the public”, and warned that “AI can make (hacking) easy for even those without special skills”. He added that “hacking methods are becoming increasingly sophisticated, while the scope of the damage is spreading across all areas on a scale that is difficult to compare with the past.” A president speaking about AI banking hacks at a cabinet meeting signals that the response will be led from the top.
Reuters’ translation has him telling officials to “establish the circumstances swiftly and clearly, and concentrate personnel and resources on minimising the damage.” Two days earlier, on Sunday 4 October, he had already ordered a probe into data leaks across the financial industry.
Police open a formal investigation
On the same day, police launched a formal investigation into the banking sector hacks and formed a dedicated investigation team, according to ChosunBiz and Yonhap. The Korean National Police Agency’s Cyber Bureau is examining the attack routes and looking for the people behind them.
The investigation into the AI banking hacks is now a criminal one, not only a regulatory review, and it is harder than it sounds. The attacks came from addresses spread across many countries, and the tool involved is public. Neither fact points to a culprit.
Why officials still say “possible”
Every official statement on the AI banking hacks so far has been hedged. Financial Services Commission chairman Lee Eog-weon said the possibility that the attacks used artificial intelligence “cannot be ruled out”. A Financial Security Institute official went further but drew a firm line: “It is correct that AI was used in the attack, but the AI did not act autonomously without human involvement.”
That second point matters for how the AI banking hacks should be read. These were people using an automated tool, not an AI acting on its own.
Seven Firms, 68,000 Records: Counting the AI Banking Hacks
The AI banking hacks did not hit one bank. They spread from three commercial banks to a regional bank, two savings banks and a consumer finance company within four days. The table below gathers each firm’s disclosed figures, drawn mainly from Financial News and the savings-bank industry’s own sweep.
| Firm | Affected | What was exposed | System hit |
|---|---|---|---|
| Yegaram Savings Bank | About 40,300 customers | Names, dates of birth, contact details | Its own service website |
| Shinhan Bank | 25,729 customers | Names, phone numbers, annual income, loan limits; 66 resident registration numbers | Loan broker lookup service |
| Welcome Savings Bank | About 2,200 corporate records | Company names, contact names, emails, phone numbers | A separately run external system |
| Hyundai Capital | 146 loan brokers | Names, mobile numbers, emails, internal broker numbers, resident registration numbers | Broker lookup page |
| KB Kookmin Bank | 119 customers | Customer details | Staff mobile business support system |
| Hana Bank | 89 customers | Customer records | Operations support system |
| BNK Busan Bank | 11 contractor staff | Names and phone numbers | Outsourced developer access |
How the numbers add up
The six individual counts sum to 66,394 people (40,300 + 25,729 + 146 + 119 + 89 + 11). Add Welcome Savings Bank’s 2,200 corporate records and the total is about 68,600, which matches the regulator’s “more than 68,000”. Some outlets round it to 70,000.
The spread is lopsided. Two firms account for almost all of it, which the chart below shows to scale against the largest leak.
The four smallest leaks together (146 + 119 + 89 + 11 = 365) are under 1% of Yegaram’s. Their importance lies elsewhere: they prove the same approach reached the country’s biggest banks.
What was not exposed
Regulators stress what the attackers did not reach. Internet and mobile banking were not affected, no monetary loss has been confirmed, and an FSS official said passwords were not leaked. The data taken came from side systems used by staff and loan brokers, not from the core systems that move money.
That limits the damage from the AI banking hacks, but only partly. Names, phone numbers, incomes and loan limits are exactly what a fraudster needs to sound convincing on a call.
Timeline of the AI Banking Hacks: 30 September to 7 October
The pace is the story. In one week the count of breached firms went from one to seven, and the response moved from a single on-site inspection to a presidential order.
| Date (2026) | What happened |
|---|---|
| Wed 30 Sept | Shinhan Bank customer data is taken through a loan broker service |
| Thu 1 Oct | Shinhan discloses about 25,000 affected customers; the FSS sends an on-site inspection team |
| Fri 2 Oct | KB Kookmin reports 119 customers and Hana reports 89; the FSC meets the banks |
| Sat 3 Oct | Yegaram Savings Bank estimates about 40,000 customers; Welcome Savings Bank finds a breach in an internal review |
| Sun 4 Oct | Seven firms confirmed; FSC emergency meeting; attacker addresses sent to about 500 firms; President Lee orders a probe |
| Tue 6 Oct | Lee cites signs of AI use; police open a formal investigation; “caution” consumer alert issued; bank and card checks due |
| Wed 7 Oct | Planned selection for the second round of network separation easing is postponed |
| Thu 8 Oct | Deadline for brokers, insurers, savings banks and e-finance firms to finish their checks |
From one bank to seven firms in four days
Shinhan’s disclosure on 1 October looked like a single incident. Within a day, KB Kookmin and Hana reported their own leaks, and by the weekend the AI banking hacks had reached BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital.
Yonhap quoted an industry official on the day Shinhan disclosed: “The entire financial industry is vulnerable to AI agent-assisted attacks.” Experts told the agency Shinhan did not appear to have been singled out, and was more likely caught in broad, automated sweeps of weak online services.
Who was targeted but held
Woori Bank and NH Nonghyup Bank faced intrusion attempts in the same wave of AI banking hacks, as did the community credit co-operative federation Saemaul Geumgo. None has confirmed a leak. Their experience is the most useful part of this story, and we return to it below.
What ARTEX AI Is and Why the AI Link Is Still "Possible"
Most coverage of the AI banking hacks hinges on one name. ChosunBiz reported that traces of ARTEX AI were found on the addresses that attacked the banks.
An open-source testing tool turned on lenders
ChosunBiz describes ARTEX AI as an open-source tool that uses a large language model to find vulnerabilities and attempt intrusions, calling it “an open-source autonomous security inspection tool”. In other words, it belongs to a fast-growing class of automated penetration testing agents built to help defenders find holes before criminals do.
A government official told AFP it was “highly likely” that ARTEX AI was used, and described it as a tool believed to be a Chinese AI system. Officials were explicit that this does not mean the attackers were Chinese. Anyone can download an open-source tool.
Spread addresses, no clear culprit
Reuters reported that the regulators shared 28 unique IP addresses linked to the AI banking hacks with the financial sector. The FSS’s later count was about 30, spread across 12 countries including the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, Sweden, Germany and Korea itself.
Park Sang-won, head of the Financial Security Institute, explained the limits: “Attackers can move between and use IP addresses in multiple locations, so it is impossible to identify an attacker based on an IP address alone.”
A “double-edged sword” for defenders
Mun Chong-hyun, a director at the security firm Genians, told Bloomberg that several recent attacks in Korea “have featured such AI tools that have been developed and shared for defensive purposes.” He called them a “double-edged sword”.
“As AI-related technologies advance, source codes are being shared indiscriminately and used for malicious AI hacking attempts,” he said. The AI banking hacks are what that warning looks like in practice: tools written for testing, pointed at real customer data.
How the Attackers Got In: Side Doors, Not the Vault
Korean reporting gives a clear, high-level picture of the entry points. None of them was the core banking system. Every one was a supporting service that faced the internet.
Broker and staff portals
At Shinhan, ChosunBiz reports that the attacker got past the login on a mobile lookup service used by loan brokers, then used customer numbers found there to query a personal-customer lookup service. Herald Business described the same pattern as cycling through customer identification numbers to pull records one by one.
At KB Kookmin, the target was a staff mobile business support system, attacked for about 42 hours. At Hana, it was an operations support system. In all three, the AI banking hacks went for internal tools reachable from outside, built for convenience rather than for hostile traffic.
Missing checks and unpatched servers
ChosunBiz’s account of the wider pattern is blunt. Some lookup services let anyone view loan application histories or company representative details without identity checks. Mobile device access controls did not work properly in some staff systems. In other cases, attackers planted malware through known flaws in web servers and took log files containing customer data.
The AI banking hacks exploited textbook weaknesses. Broken access control has topped the OWASP Top 10 for years, and missed patches are the oldest problem in the field.
Why AI changes the economics
None of those flaws is new. What an AI tool changes is the cost of finding them. A model that can read a page, guess how a lookup works and try variations can test hundreds of services at a speed and scale that once needed a skilled team.
That is the point Lee made: AI lowers the skill floor. Kwon Tae-kyung, a Yonsei University professor, put it more vividly to Herald Business: “the front door was well-guarded but the side door was left open.” The AI banking hacks found the side doors faster than the banks did.
Why Woori and NH Nonghyup Held During the AI Banking Hacks
The most useful finding from the AI banking hacks is not about AI. ChosunBiz reports that the lenders that suffered no damage under the same attack had basic access controls that worked, not newer or costlier technology.
Basic controls, not bigger budgets
Woori Bank only lets loan applications from brokers be viewed on designated tablet devices, and requires a separate certificate plus biometric checks to reach business systems. An ID and password alone will not get anyone in.
NH Nonghyup Bank gave loan brokers no internal network access at all. Branches took over broker-sourced applications and processed them themselves. Its system that automatically blocks repeated logins from the same address also fired during this attack.
The table sets the controls that held beside the gaps found elsewhere.
| Control | What held at Woori or NH Nonghyup | Gap reported at breached firms |
|---|---|---|
| Device allow-listing | Broker applications viewable only on designated tablets | Staff mobile access controls not working |
| Multi-factor sign-in | Certificate plus biometrics; no ID-and-password-only route | Login bypassed on a broker lookup service |
| Third-party access | No internal access for brokers; branches process their files | Broker and contractor portals open to the internet |
| Repeat-request blocking | Repeated logins from one address blocked automatically | Customer numbers cycled to pull records in bulk |
| Identity checks on lookups | Lookups tied to a verified user and device | Loan histories viewable without identity checks |
Spending did not predict the outcome
The four big commercial banks spend similar sums on information security. Their 2025 disclosures to the Korea Internet and Security Agency, reported by Seoul Economic Daily and ChosunBiz, show the only one with no confirmed leak was the smallest spender.
Woori spent 6.9 billion won less than KB Kookmin (43.3 minus 36.4) and had the largest dedicated security team of the four, at 101 staff against Shinhan’s 97.8, KB’s 96.7 and Hana’s 71.9. Seoul Economic Daily adds that Woori’s 2025 spend was down 18.1% on the year. Budgets were broadly level; outcomes in the AI banking hacks were not.
Good grades, bad week
ChosunBiz also points out that the government’s own scoring missed the problem. Shinhan received an S grade for five consecutive years in the FSC’s assessment of personal credit information handling, and a commendation from the FSC chair for financial security work last year. Hana also held five straight S grades.
The lesson is uncomfortable for any regulator. Compliance scores measure whether a process exists. The AI banking hacks tested whether a forgotten side system actually checked who was asking.
Seoul's Response to the AI Banking Hacks
The government response came in layers: emergency checks across the sector, a consumer alert, a pause on a planned rule change and a push to answer AI attacks with AI defence.
Emergency checks across about 500 firms
After the AI banking hacks, the FSS circulated the attacker addresses and security advisories to about 500 financial firms. Banks and card companies had to finish checks by 6 October, and brokerages, insurers, savings banks and electronic finance firms by 8 October. The checks cover internet-facing IT assets, access controls and patch status.
All 79 savings banks have since completed self-checks and found no further damage beyond Yegaram and Welcome, according to Newspim. Authorities will run voluntary fixes of basic IT controls across the sector through November, and say they will take “stern action” if a large breach follows poor checking. Regulators’ data cited by Financial News counts 36 cyber incidents in the sector between January 2024 and August 2026.
A “caution” alert and a month of fraud watch
On 6 October, with follow-on fraud the likeliest next stage of the AI banking hacks, the regulators issued a consumer alert at “caution” level and began a one-month special response. Affected firms must open dedicated support channels, report any confirmed or suspected follow-on fraud straight away, and tighten their fraud detection systems.
An FSS official explained the risk to The Korea Times: “Although passwords were not leaked, scammers could piece together exposed personal details to impersonate loan advisers or lure victims with promises of compensation for the data breaches.” Sungho Hwang of NordVPN told Bloomberg the breach was worrying “because it exposed both personal and financial information.”
Network separation easing is postponed
Korea’s financial sector runs under network separation rules that physically wall internal systems off from the internet. In June, 10 firms, including Shinhan, Hana and Woori, were allowed to use high-performance external AI for security testing. A second round, with 75 applicants competing for up to 15 places, was due to be selected on 7 October.
The FSC has postponed that selection while staff deal with the AI banking hacks, and says the delay is not a halt. Korea University professor Lee Sang-geun told Seoul Economic Daily that the sector had been “digging a big moat to keep enemies out”, and that the belief they were cut off led firms to neglect internal defences.
“Defend AI attacks with AI”
At Sunday’s emergency meeting, FSC chairman Lee Eog-weon said “the entire financial sector must recognize the severity of the current situation and maintain the highest level of vigilance,” adding: “We must also quickly establish security systems that defend AI attacks with AI.”
Markets read the AI banking hacks as good news for security vendors. AhnLab shares jumped 21.3% to 93,300 won in pre-market trading on 6 October, Seoul Economic Daily reported, and were still up 12.6% at 86,700 won at 9:22 a.m., according to ChosunBiz.
How the AI Banking Hacks Fit a Wider Pattern
South Korea is not the first government to report AI tools in a breach, and this is not its largest leak. What sets the AI banking hacks apart is the combination of scale, speed and a named tool.
Earlier AI agent incidents
Reuters set the Korean news beside two recent cases. Australia reported that an OpenAI agent breached a government health data portal in June. An AI research firm also reported attempts against a Canadian government website, which Canada said did not compromise its systems.
Those followed a run of incidents in which training agents probed US government websites and agents tried to bruteforce a UN website. In each case, automated agents found weaknesses that humans had left in place. The AI banking hacks follow the same pattern, but against private lenders holding customer data.
Smaller than Korea’s biggest breaches
By record count, the AI banking hacks are modest. Bloomberg notes that a Lotte Card hack exposed nearly 3 million customer records, and that a breach at Coupang’s Korean unit affected more than 33 million accounts and drew a record penalty from the privacy regulator.
The difference is breadth. The AI banking hacks hit seven firms across banking, savings and consumer credit in a single week, using similar methods.
What makes this wave different
Three things stand out. First, the regulators named a specific AI tool within days. Second, the entry points were the dull, forgotten corners of each firm, which an automated tool is well suited to sweep. Third, the firms that held did so with controls that are cheap and well understood.
The UK’s National Cyber Security Centre forecast this shift in its assessment Impact of AI on cyber threat from now to 2027, which judged that AI will “almost certainly” make intrusion operations more effective and widen a “digital divide” between organisations that keep pace and those that do not.
What UK Firms Should Take From the AI Banking Hacks
Nothing about the AI banking hacks is specific to Korea. Every UK bank, lender, broker and many smaller firms run the same kinds of side systems: broker portals, staff apps, contractor access and lookup pages. These are the steps that would have stopped this attack.
Map every internet-facing side system
Start with an inventory of every service reachable from the internet, not just the customer website. Broker portals, staff mobile apps, contractor tools and old lookup pages are where the AI banking hacks found their way in. A vulnerability assessment that covers only flagship apps would have missed them.
Remove password-only routes
Require multi-factor sign-in on every third-party and staff portal, and bind access to known devices where you can. Woori’s mix of a certificate, biometrics and designated tablets is a model. No external route should accept an ID and password alone.
Check who is asking on every lookup
Each lookup should confirm that the signed-in user is allowed to see that specific record. Cycling through customer numbers only works where this check is missing. Test it on purpose, with your own staff or an outside tester, before an AI tool does it for someone else.
Rate-limit and alert on bulk requests
NH Nonghyup’s automatic block on repeated logins worked. Apply the same idea to lookups: cap requests per user, device and address, and alert when one account suddenly reads hundreds of records. KB’s 42-hour exposure shows the cost of slow detection.
Patch the servers no one owns
Several Korean breaches came through known flaws in web servers. Give every internet-facing system a named owner and a patch deadline. The NCSC warns that the gap between disclosure and exploitation has shrunk to days.
Prepare customers for follow-on fraud
Plan the customer message before a breach. Korea’s response, with dedicated support lines, fraud reporting and stronger fraud detection, is a sound template, and a tested incident response plan makes it quick. UK firms should also watch the duties coming in the Cyber Security and Resilience Bill.
AI Banking Hacks: Frequently Asked Questions
These are the questions customers and boards are most likely to ask about the AI banking hacks, answered from what Korean authorities have confirmed so far.
Was any money stolen?
No monetary loss from the AI banking hacks has been confirmed. Regulators say internet and mobile banking were not affected. The main risk is follow-on fraud using the leaked personal details.
Were passwords leaked?
An FSS official said passwords were not leaked in the AI banking hacks. The exposed data includes names, phone numbers, dates of birth, incomes, loan limits and, in some cases, resident registration numbers.
Did an AI hack the banks by itself?
No. A Financial Security Institute official said AI was used but “did not act autonomously without human involvement.” People ran the attacks, using an AI tool to speed them up.
Who is behind the AI banking hacks?
No one has been named. The tool is public and the attacks came from addresses in about 12 countries, so officials say neither points to a specific country or group. Police are investigating.
Could this happen in the UK?
Yes. The weaknesses were ordinary ones: portals without identity checks, password-only access and unpatched servers. Any firm with internet-facing side systems should check them now.
References
South Korea warns of possible AI use in banking hacks (AFP via The Star)
South Korea’s Lee says AI appears to have been used in bank hacks (Reuters)
AI-aided hacks hit seven South Korea financial firms, expose security gaps (ChosunBiz)
Basic controls stop Korea bank hacks as AI attacks expose gaps at others (ChosunBiz)
Korean Banks Still Run 50-Year-Old COBOL as AI Hacks Mount (Seoul Economic Daily)
Impact of AI on cyber threat from now to 2027 (National Cyber Security Centre)