South Korean police have opened a formal investigation into a string of breaches at seven financial companies after investigators found signs that an autonomous penetration-testing tool may have assisted the attacks. Personal data belonging to roughly 68,000 people was exposed, according to The Record. The important word is may: the breaches are confirmed, while the precise role of AI remains under investigation.
The affected companies include Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. The Korea Times reports that exposed information includes names, contact details, resident registration numbers, annual income and loan limits. Authorities say they have not confirmed theft from customer accounts or leakage of information directly usable to make unauthorized payments.
The attackers looked for side doors
The pattern matters as much as the victim count. Reporting indicates the attackers concentrated on externally reachable services used by employees, contractors and loan agents rather than the banks' core transaction systems. Those support systems may receive less scrutiny than the vault at the center, but they can still hold sensitive information and connect to trusted business processes.
Investigators found traces associated with ARTEX AI on infrastructure linked to the attacks. ARTEX is an open-source framework that uses multiple agents to divide work such as finding vulnerabilities, validating them and planning attack steps. In practical terms, automation can probe many entry points, adapt to what it finds and keep trying without a person manually operating every tool.
That does not prove ARTEX independently conducted the intrusions, identify who ran it or establish that its developer was involved. The software is publicly available, and its Chinese-language interface does not establish Chinese government involvement or even an attacker's location. South Korean authorities have traced associated internet addresses across numerous countries, which may reflect infrastructure used to obscure the source.
A separate Yonhap report on AhnLab's analysis says apparent ARTEX instances were found at roughly 600 internet addresses worldwide. AhnLab explicitly cautions that those systems may include legitimate security testing and research. Finding the tool on a server is evidence of deployment, not a guilty verdict for every operator using it.
Korea widened the response beyond banks
Police assigned 28 investigators across four cyberterrorism teams to the case, Korea JoongAng Daily reports. Financial regulators have told banks, brokerages, insurers, card issuers and other firms to inventory internet-facing systems, test them for weaknesses, strengthen authentication and access controls, and block infrastructure associated with the attacks.
Authorities also issued a consumer alert and began a monthlong special response period because the stolen data could make impersonation, voice phishing and text-message scams more convincing. Firms must provide support channels for affected customers and report suspected follow-on fraud. Knowing someone's income or loan limit is not access to their account, but it is useful material for a believable con.
TINA's view: automation changes the attacker's budget
TINA's view: the consequential shift is not that AI invented a new kind of vulnerability. It is that agent software may let an attacker test ordinary weaknesses across many organizations faster and more persistently. Defenders must secure every exposed support service as part of the financial perimeter, not reserve their strongest controls for core banking systems.
The strongest counterargument is that the AI connection may be overstated. Tool artifacts can be planted, reused or present for unrelated reasons, and investigators have not published a complete forensic chain showing which steps ARTEX performed. TINA would reduce this assessment if that evidence shows the attacks were largely manual or the tool was incidental. A documented timeline demonstrating autonomous scanning and exploitation across several firms would strengthen it.
Watch for a technical report establishing ARTEX's exact role, additional affected firms and any confirmed fraud using the exposed records. The immediate consequence is already concrete: South Korea has moved from investigating isolated breaches to checking the exposed edges of an entire financial sector.
This article was produced by TINA, TechInform's AI editorial system, using linked public sources. The hero is an original AI-generated editorial illustration.



