Attackers used Artex AI, an open-source hacking agent built by a Chinese security engineer, to break into at least seven South Korean financial firms and steal personal data on about 68,000 people, The Wall Street Journal reported. The National Police Agency’s cyber terror unit opened an investigation the same day, in what officials describe as one of the first AI-assisted intrusions into the global banking system.
The breaches came to light over five days. Shinhan Bank disclosed on 1 October that data on about 25,000 customers leaked through a service loan brokers use to check application status, and the server linked to the attack is suspected of credential stuffing, the automated replay of stolen username-and-password pairs, The Korea Times reported. KB Kookmin Bank (119 customers, via an employee mobile work-support system), Hana Bank (89, via a sales-support system), and BNK Busan Bank reported breaches on 2 October, according to UPI.
The incident then spread beyond the big lenders. Yegaram Savings Bank put its customer count at about 40,000. Welcome Savings Bank also reported a breach, and Hyundai Capital said data on 146 housing-loan agents was exposed. Leaked records include names, phone numbers, annual income, and calculated loan limits, as well as some resident registration numbers and South Korea’s national ID.
Financial authorities said IP addresses associated with the same attacker appeared across all seven firms. Per the Journal, the attacks came from more than two dozen addresses in about a dozen countries, including the US, Japan, and Germany. No culprit has been named, and officials say they are seeking international cooperation.
How investigators tied the attacks to Artex
The Korea Financial Security Institute (FSI), which inspects the sector for regulators, traced attack IPs and server logs at Shinhan and found evidence pointing to Artex, an FSI official told The Herald Business. The official said the AI did not act independently without human involvement — a hacker used it as a tool.
Mun Chong-hyun, who heads Seoul-based Genians Security Center, flagged Artex’s possible role shortly after the Shinhan breach became public, the Journal reported. He told the paper he expects AI-agent attacks to keep rising in South Korea and worldwide.
Artex is published on GitHub by the account Autumn-27, which the Journal identifies as Li Puhua, a Chinese engineer. Its documentation describes a multi-agent autonomous penetration-testing system, with planner agents mapping an attack path and worker agents executing it.
Artex is not an AI model itself: users connect a model of their choice, such as Anthropic’s Opus, OpenAI’s GPT, or DeepSeek, and South Korean officials have not said which one the attackers used. The repository advertises a win in Baidu’s “Agent+” attack-and-defence challenge, the September contest that the Journal describes.
Li built the tool for organisations probing their own networks, and its launch notes describe pausing the agent for human approval before critical actions inside an authorised scope. Those gates are set on a self-hosted install, controlled by whoever runs it. After the first breach reports, Artex added usage guidelines banning unauthorised intrusion and data theft, the Journal reported.
Officials stress that the tool’s origin does not identify the attackers. A government official told AFP it was “highly likely” Artex was used, while other officials said that does not mean the hackers were Chinese. Police have not established whether Artex was the only software involved.
Seoul’s response
President Lee Jae Myung ordered a thorough investigation on 4 October and, at a cabinet meeting on 6 October, said, “Speed is of the essence,” directing ministers to act immediately. The Financial Services Commission (FSC) ordered banks and card companies to check every internet-facing system, and FSC Chairman Lee Eog-weon said there was no sign that data directly usable for fraudulent payments had leaked. Shinhan and KB Kookmin pledged to fully compensate for any losses. Shares of South Korean cybersecurity companies rose as much as 30% on Tuesday.
No payment credentials are known to be exposed, but income and loan-limit data is the raw material of loan-fraud phishing, so affected customers should treat unsolicited loan offers and calls citing their credit details with suspicion.
The case follows Anthropic’s disclosure that Chinese state-sponsored hackers used its AI to automate intrusions against roughly 30 targets, a claim Beijing rejected. There is one difference: Anthropic could cut off accounts on its own platform, while an open-source agent running on an attacker’s server has no vendor to switch it off.
Investigators have yet to say who was behind the attacks, which AI model powered them, or how the firms’ disclosures add up to the 68,000 total officials cite.



