South Korean Financial Institutions Target of AI-Assisted Cyberattacks
South Korean financial firms, including major commercial banks, capital lenders, and savings banks, are facing a wave of security breaches and data leaks stemming from cyberattacks suspected of utilizing artificial intelligence tools originating from domestic and international sources, fnnews.com reported.
The sequence of incidents has exposed the sensitive personal data of tens of thousands of customers across the country’s financial sector. Security analysts and financial regulators have identified suspicious external access patterns, pointing to automated probing methods that bypass traditional authentication layers.
Yegaram Savings Bank and Hyundai Capital Confirm Data Exposures
Yegaram Savings Bank discovered on Sept. 30 that an unidentified hacker accessed a server containing customer personal information, exposing names, birth dates, and contact numbers for approximately 40,000 customers, which accounts for roughly 20 percent of its total customer base of 200,000. In response, the company blocked external IP addresses and suspended related services. A company representative stated that while artificial intelligence tools are suspected in the attack vector, investigators have not yet found definitive AI infiltration markers.
Hyundai Capital encountered a separate security incident on Oct. 2 at 5:08 p.m., when unauthorized external internet protocol addresses targeted a webpage used for searching mortgage loan agents. Security checks revealed that the incident exposed the internal agent numbers, resident registration numbers, and public contact details of 146 mortgage loan agents. Hyundai Capital blocked the offending IP addresses and reported the breach to the Financial Supervisory Service and the Korea Internet & Security Agency at 3:30 p.m. the same day.
Commercial Banks Report Unauthorized System Access
Major commercial banks have also reported security breaches affecting separate internal or specialized operational networks. Shinhan은행 experienced an incident between Sept. 29 and Sept. 30 where unauthorized external parties bypassed authentication to access a loan solicitor inquiry service, exposing personal credit information for roughly 25,000 customers. The exposed data included names, phone numbers, annual incomes, and loan limits, along with 66 resident registration numbers and 97 linkage information entries. Shinhan Bank announced plans to fully compensate customers for any losses resulting from the breach.
Hana Bank reported that an external hacking agent gained abnormal access to its operational support system, compromising the records of 89 customers, including resident registration numbers, names, addresses, emails, and workplace titles. KB Kookmin Bank identified an external breach affecting 119 customers on a mobile business support system used by employees, leaking names, phone numbers, addresses, and encrypted resident registration numbers. Both banks confirmed that their core internet and mobile banking transaction systems remained unaffected.
Security Experts Point to AI Penetration Testing Software
Security analysts monitoring the attacks have identified technical markers suggesting the use of automated penetration testing tools. Moon Jong-hyun, director of the Genians Security Center, noted via LinkedIn that web servers used in several recent domestic attacks displayed the HTML title string “ARTEX – 自主渗透测试控制台,” indicating the potential involvement of an autonomous AI penetration testing console.
ARTEX AI is an open-source framework hosted on GitHub that utilizes large language models and multi-agent structures to automate reconnaissance, vulnerability scanning, and exploit path planning. While designed for authorized security testing, security specialists warn that such tools can be repurposed by malicious actors to scale automated cyber assaults.
Regulatory Responses and Systemic Audits
Following the string of breaches, the Financial Services Commission convened an emergency response meeting led by senior officials to review attack vectors and direct all financial institutions to conduct rigorous self-assessments of their security vulnerabilities and access control protocols. Regulators have distributed inspection checklists to verify the security posture of banking networks across the sector.
Frequently Asked Questions About the Financial Cyberattacks
Which financial institutions experienced confirmed data leaks?
Yegaram Savings Bank, Hyundai Capital, Shinhan Bank, Hana Bank, and KB Kookmin Bank all confirmed that customer or agent data was exposed during the September and October cyber incidents. Woori Bank and NH Nonghyup Bank faced similar attack patterns but reported no resulting personal information leaks.

Were core customer banking transactions disrupted by the breaches?
No. Financial institutions including Hana Bank and KB Kookmin Bank confirmed that the unauthorized access was confined to specialized administrative, support, or loan-solicitor query systems separate from main internet and mobile banking ledgers.
What specific software tool is suspected of driving the attacks?
Security researchers identified references to ARTEX AI, an open-source, large language model-based penetration testing framework, in web server logs associated with the recent intrusion attempts.