
Following Shinhan Bank's personal information leak, hacking attacks were confirmed at multiple banks one after another.
During a hacking attack targeting major domestic banks such as Shinhan Bank, traces of 'ARTEX AI', a Chinese-based open source tool in which an artificial intelligence (AI) agent automatically performs the hacking process, were discovered, putting the entire financial sector on a security alert.
AI-generated summary
Hacking and personal information leakage incidents occurred one after another at major domestic banks, including Shinhan Bank, KB Kookmin Bank, BNK Busan Bank, and Hana Bank.
‘AI Autonomous Penetration Test Console’ string on the suspected attack server
Circumstances related to open source ARTEX AI… Actual use is unconfirmed
Following KB Kookmin, Hana, and BNK Busan, Woori and Nonghyup were also attacked.
(Seoul = Yonhap News) Reporter Kwon Ha-young = While circumstances showing the possibility that a tool that automatically performs the hacking process by an artificial intelligence (AI) agent was used in the Shinhan Bank personal information leak incident were detected, a security emergency was put across the financial sector as hacking attacks were confirmed one after another at multiple banks around the same time.
On the server presumed to have been used in the attack, traces of a Chinese-based autonomous infiltration tool that uses AI to find vulnerabilities and plot attack routes on behalf of humans were discovered. It has not yet been confirmed whether this tool was used in the actual attack.
◇ ‘AI autonomous penetration testing console’ on the attack server… ARTEX AI related situation
According to the security industry on the 2nd, the string 'ARTEX-self-administered search engine' was confirmed in the HTML title of the web server used in the credential stuffing (random information substitution technique) attack believed to be targeting Shinhan Bank.
This is an expression meaning ‘AI autonomous penetration testing console,’ and can be interpreted as evidence showing the possibility that ‘ARTEX AI’ was operated in the relevant infrastructure or that a related environment was utilized.
Moon Jong-hyun, head of the Genius [263860] security center, made this diagnosis through his LinkedIn that day.
The HTML title is the page title displayed at the top of the web browser tab or window. Simply put, the phrase 'AI Autonomous Penetration Test Console' in Chinese is exposed as is in the title of the page of the web server used in the attack.
Credential stuffing is a hacking method in which an attacker brute-forces a combination of information, such as IDs and passwords, obtained in advance into multiple systems.
Typically, they illegally trade and collect ID and password data used for specific sites on information black markets such as the dark web, and then target users' practices of using the same ID and password on multiple sites.
In the past, attackers had to repeat these inputs manually, but recently, tools that automate this process with AI are increasingly being used.
ARTEX AI is a large-scale language model (LLM)-based autonomous penetration testing system released as open source on GitHub, focusing on Chinese.
It is designed to use LLM and a multi-agent structure to automate the process from information collection to vulnerability exploration, attack route planning, security tool execution, and vulnerability verification.
However, even technology developed for security checks can turn into a hacking tool if it falls into the hands of an attacker.
◇ Security AI becomes an automated hacking tool... It is not confirmed whether the attack is actually used or not.
Center Director Jonghyun Moon said, “Several threat analysts reasonably suspect that AI-based attack automation tools were used during this financial company attack.”
He pointed out, "On the surface, it is a tool developed to support security checks and penetration testing, but while it can be used as an efficient penetration testing tool in a permitted security verification environment, if abused by an attacker, it has the potential to be used as a means of increasing the automation and efficiency of actual cyber attacks."
As ARTEX AI is software (SW) released as open source, one of the concerns is that anyone can download and use it without separate approval.
One security expert mentioned this and said, "Although Chinese strings exist, the attacker's identity cannot be easily guessed as it is open source software that anyone can use. The biggest problem is that automation of attacks using open source software can become increasingly widespread."
ARTEX AI was introduced as the winning project in the 'Agent+' defense ability challenge led by China's Baidu BSRC this year.
However, it has not been confirmed by official agencies such as financial authorities whether ARTEX AI was actually used in the attack during the Shinhan Bank hacking process.
◇ Beyond Shinhan, to KB Kookmin, Hana, and BNK Busan… All-round damage to the banking sector
Since the Shinhan Bank incident first came to light, similar types of attacks appear to be spreading to other banks.
Shinhan Bank announced on the 30th of last month that it had confirmed that the personal information of about 25,000 customers had been leaked by an external unauthorized person who bypassed the identity verification process of the loan originator service. The leaked information included 66 resident registration numbers and 97 linked information (CI) of some customers, as well as customer names, phone numbers, annual income, and loan limits.
At KB Kookmin Bank, the personal (credit) information of 119 customers was leaked due to an external intrusion targeting the mobile work support system for employees on the night of the 30th of last month. The leaked information differed by customer, including customer name, phone number, address, and encrypted resident registration number.
BNK Busan Bank received an external web server attack attempt, believed to have used an AI agent, around 9 p.m. on the 1st.
The major attack was blocked, but during the follow-up inspection, it was confirmed that the names, phone numbers, dates of birth, and email addresses of 11 outsourced development employees were exposed through some web pages where session verification was not sufficient. Busan Bank said there was no customer information leak.
At Hana Bank, it was discovered that the resident registration numbers, names, addresses, email addresses, phone numbers, mobile phone numbers, and workplace names of 89 customers were leaked through an abnormal approach targeting the Sales Support System (ODS).
Hana Bank explained that the system is a separate channel from the internet and mobile banking transaction system, so it is not related to the leakage of customer financial transaction information.
It is reported that there were hacking attacks at Woori Bank and NH Nonghyup Bank, but there were no information leaks.
As similar types of attacks continue to occur at multiple banks in a short period of time, the security industry is focusing on the possibility that AI-based automation tools were behind the attacks.
Some are raising the possibility that ARTEX AI, which was pointed out as a means of hacking Shinhan Bank, was abused throughout the financial sector.
AI outlook — possibilities, not facts
Expansion of security checks by financial authorities and institutions
Very likely · Within weeks

Following Shinhan, Kookmin, and Hana Bank, the personal information of 11 outsourced development employees was leaked at BNK Busan Bank through external hacking using an AI agent. Busan Bank immediately blocked the web page and reported it to the financial authorities, and announced that there was no leak of customer information.

Samcheok City in Gangwon-do was selected by the Ministry of Science and ICT for the '2027 Smart Village Supply and Expansion Project' and will invest 3 billion won by 2029 to build an AIoT-based maritime safety management system.

KB Kookmin Bank announced that about 100 pieces of customer information were leaked due to an external intrusion through the mobile work support system for employees. This is the second commercial bank hacking incident following Shinhan Bank, and financial authorities are discussing response measures considering the possibility of further spread of damage.

In relation to the personal information leakage of about 25,000 Shinhan Bank customers, traces of 'ARTEX AI', a Chinese-based AI autonomous penetration testing console, were found on the suspected attack server, but it was not confirmed whether it was actually used, the security industry said.

As accidents caused by AI increase, there is a growing consensus that AI development companies should be held legally responsible, but it is pointed out that it is difficult to apply the existing legal system. The New York Times introduced related public opinion and legal academic opinions, and reported on cases where AI models such as Open AI and Antropic caused security incidents and the process of discussing responsibility.

Following Japan, Naver announced that it will strengthen overseas travel information search results in 45 major Asian regions, including Vietnam, Thailand, Indonesia, the Philippines, Taiwan, Hong Kong, and Macau, and provide weather, exchange rates, visas, entry guidance, safety notices, and AI-based popular restaurant and attraction recommendation services.