← All posts / Meta

The Hacker Was Average. The Tool Wasn't: Open-Source ARTEX AI Breached Seven Korean Banks

An open-source LLM-driven pentest tool did the recon, the attacks and the verification across seven South Korean financial firms — 65,000+ records exposed and a sector-wide emergency.

The Hacker Was Average. The Tool Wasn't: Open-Source ARTEX AI Breached Seven Korean Banks

What do you do when the attack tool outclasses the attacker? That is the uncomfortable question South Korea is wrestling with after a week-long hacking campaign that ran from September 28 through early October 2026 breached seven financial institutions, exposed the personal data of more than 65,000 customers, and forced President Lee Jae Myung to order a comprehensive investigation — with an open-source AI agent, not a state-sponsored elite unit, as the prime suspect weapon.

The tool is called ARTEX AI. It is an autonomous penetration-testing system built on large language models that can independently conduct reconnaissance, identify vulnerable login endpoints, launch attacks, and verify results — all without continuous human direction. It was not developed inside a classified military program. According to investigators, it was introduced as a winning entry in a challenge run by Baidu’s Security Response Center and distributed openly through GitHub, primarily to Chinese-speaking developers. Somewhere along the way, a threat actor picked it up and pointed it at internet-accessible banking portals.

What actually happened

The Korea Financial Security Institute traced the ARTEX connection after following attack IP addresses and server logs from Shinhan Bank, the first institution to report a breach. The smoking gun was almost mundane: the HTML title of a server believed to have been used in the campaign read “ARTEX-自主渗透测试控制台” — roughly, “autonomous penetration testing console.”

The victim list is a cross-section of Korean finance:

  • Shinhan Bank — heaviest confirmed toll. An attacker bypassed identity verification on a mobile portal used by loan solicitors, exfiltrating names, phone numbers, annual income and calculated loan limits of roughly 25,000 customers, plus 66 national ID numbers and 97 CI online-identity identifiers. First intrusion September 28; anomaly detected the following morning — more than 15 hours later; total dwell time around 30 hours.
  • KB Kookmin Bank — employee mobile support system accessed; 119 individuals’ records exposed, including encrypted national ID numbers. Detection took roughly 43 hours.
  • Hana Bank — sales support system breached; 89 customers’ national ID numbers, names, addresses, emails and phone numbers leaked.
  • BNK Busan Bank — 11 records of external development contractors exposed.
  • Yegaram Savings Bank — roughly 40,000 people’s names, dates of birth and contact information taken from a customer-records server.
  • Welcome Savings Bank — corporate client data leaked, full damage still being assessed.
  • Hyundai Capital — names, contact details, emails and national ID numbers of 146 mortgage loan solicitors taken.

At least two more institutions — Woori Bank and NH NongHyup — repelled the same attacks without confirmed data loss. Internet and mobile banking services were not affected, and no direct financial losses, unauthorized transfers or account withdrawals had been confirmed as of October 5. Authorities expect the 65,000+ figure to rise.

Why this attack is different

The technique at the core was credential stuffing — feeding massive volumes of username-and-password pairs from earlier breaches into login portals at high speed, exploiting password reuse. That is old news. What AI augmentation adds is adaptive execution: varying timing, rotating infrastructure across IPs in the US, Japan, Hong Kong, Singapore, Vietnam, Thailand and the UK, and adjusting attack parameters in response to defenses, without a human operator in the loop.

“A hacker used the AI as a tool,” a Korea Financial Security Institute official told The Herald Business — a phrasing that undersells how much of the attack loop the AI ran on the attacker’s behalf. Traditional credential-stuffing campaigns required a competent operator to manage bot infrastructure, rotate proxies, handle authentication challenges and analyze results. ARTEX-style tools automate the entire cycle. What previously required skill now requires only someone who knows enough to point the tool at a target and wait.

“Hackers have begun using AI agents, so the frequency and scale of attacks are bound to grow more severe,” said Kim Myeong-ju, head of the Barun AI Research Center. Son Kyu-sik, a professor in Hanyang Cyber University’s Department of Hacking and Security, put the structural issue plainly: systems connected to the external internet with relatively weak authentication are now exposed to automated AI attack.

Note the target selection, too. The attackers never touched consumer-facing banking apps or core transaction rails — the systems with the heaviest security investment and most aggressive monitoring. They hit the adjacent soft tissue: loan agent portals, employee mobile support platforms, sales support databases. Korean authorities found some information-lookup services let users view loan application histories without identity verification, and mobile device access controls that simply didn’t function in employee support systems. That architectural blind spot is not uniquely Korean; financial institutions worldwide harden the systems customers transact on while auxiliary business-support systems lag on authentication and monitoring.

Attribution is close to impossible — by design

This is where the story gets structurally worse. Threat intelligence firm Oasis Security, tracking exposed infrastructure through its AGATHA platform, identified 359 unique IP addresses globally associated with ARTEX-related activity. Over 91 percent sat on overseas servers — concentrated in the United States (65.7%), China (14.8%) and Hong Kong (10.9%) — with more than half the traffic routed through a single hosting network. A second AI attack framework, CyberStrikeAI, was observed running approximately 1,000 servers during the same period.

ARTEX is open-source and freely available. Its dominant hosting footprint was American, not Chinese. Investigators concede that attribution remains murky precisely because the tool is public and its infrastructure globally distributed. The dual-use nature of autonomous pentesting tools — legitimate for defenders, devastating in the wrong hands — means any assumption of state sponsorship collapses on contact with the evidence.

The regulatory aftershock

President Lee ordered a thorough investigation and response measures on Sunday, October 4. The Financial Services Commission held an emergency inspection meeting at the Government Complex Seoul the same day, with chair Lee Eog-weon telling the sector it must recognize the gravity of the situation. The Financial Supervisory Service shared attacking IPs and security advisories with roughly 500 financial firms. Banks and card companies must complete checks by October 6; securities firms, insurers, savings banks and electronic financial operators by October 8 — covering externally exposed IT assets, access controls and patch status. Voluntary remediation of basic IT controls continues sector-wide through November, with authorities promising stern action if large-scale breaches recur due to inadequate inspection.

Tellingly, among firms that faced similar intrusion attempts, those that had implemented multi-factor authentication or preemptively patched known vulnerabilities did not suffer actual breaches. The lesson officials keep repeating is almost embarrassing in its simplicity: the basics still decide outcomes.

The bigger picture

Strip away the specifics and the structural shift is this: agentic AI attack tools eliminate the skill floor. For thirty years, cyber defense could assume a rough correlation between attacker capability and attacker skill. Open-source autonomous agents break that assumption. A single mediocre operator with a GitHub URL now wields campaign-grade capability — reconnaissance, adaptation, infrastructure rotation, verification — that used to demand a competent team.

Expect three consequences. First, incident volume: if the marginal cost of running a sophisticated campaign falls to near zero, the number of campaigns rises toward the number of attackers, however unskilled. Second, perimeter inflation: every weakly authenticated auxiliary system — loan portals, partner databases, employee tools — becomes a viable entry point, vastly expanding the attack surface that actually matters. Third, policy pressure: when a G20 economy’s entire financial sector goes into emergency inspection mode over a tool anyone can download, the debate over governing dual-use offensive-security AI stops being theoretical. South Korea’s October 6 and 8 compliance deadlines are a live experiment in how fast a regulated sector can move when it has to.

The uncomfortable summary: South Korea’s banks were not beaten by a genius. They were beaten by a tool that behaves like one, operated by someone who isn’t — and that combination is now available to everyone.