Attack on at least 7 South Korean institutions exposed data of about 68.000 people
The Wall Street Journal reports that attackers used Artex in incidents at at least seven South Korean financial institutions, with access to data on about 68,000 people. Artex is an open-source automated penetration-testing tool, not an AI model. After the disclosures, its terms were changed to explicitly prohibit unauthorized intrusion and data theft. The newspaper describes the case as one of…
A recent attack on seven South Korean financial institutions has exposed sensitive data belonging to approximately 68,000 individuals, according to The Wall Street Journal. This data includes personal details such as names, contact information, identification numbers, annual incomes, and borrowing limits. The attack was carried out using Artex, an open-source automated penetration-testing tool, which is not an AI model but acts as an "agent" for other AI models to identify vulnerabilities in systems.
Upon the disclosure of these security breaches, the terms of Artex were amended to explicitly forbid unauthorized intrusion and data theft. The attack involved at least seven South Korean banks, namely Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank, and Hyundai Capital. Notably, around 40,000 Yegaram customers and 25,000 Shinhan Bank customers were affected by the breach.
South Korean authorities have issued a warning about a potential second wave of phishing and smishing attacks, which are deceptive emails or SMS messages that aim to trick recipients into divulging sensitive information. Artex operates by scanning systems for vulnerabilities, enabling organizations to bolster their security. It functions autonomously, minimizing the need for human intervention and allowing it to search for weaknesses and determine potential entry points.
The tool was developed by Chinese cybersecurity engineer Li Puhua, also known as Autumn. Following the revelations, Artex updated its terms of use, explicitly prohibiting unauthorized intrusion, data theft, and other malicious activities. Researchers identified over 24 IP addresses associated with the attacks across approximately 12 countries, including the US, Japan, and Germany. Subsequently, South Korean cybersecurity firm AhnLab discovered traces of Artex on nearly 600 IP addresses worldwide.
While the origin of the perpetrators has not been definitively determined, researchers caution that tools like Artex can lower the technical knowledge required for complex attacks by taking on sequential steps without ongoing guidance. This empowers less experienced attackers to attempt more intricate actions, while seasoned hackers can execute them more swiftly and on a larger scale.
Anthropic, a prominent AI company, reported in 2025 that Chinese state-backed hackers had employed its technology in attacks against approximately 30 organizations.
Additionally, incidents or attempts at autonomous attacks using AI agents have also been documented in Australia and Canada. South Korean President Lee Jae-myung has called for a swift investigation and enhanced security measures, with police investigating the case and seeking international cooperation to identify the perpetrators. The regulator has also urged the financial industry to develop defenses that incorporate artificial intelligence.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.