LATEST NEWS
SELECTED FOR YOU

AI-powered attacks hit South Korean financial institutions

ByMicah AbiodunMicah Abiodun 2 mins read
AI-powered attacks hit South Korean financial institutions
  • AI-assisted hackers used ARTEX and Claude Code to target South Korean financial institutions.
  • Seven firms reported breaches affecting tens of thousands of records, including customer and corporate data.
  • AI is helping attackers find and exploit vulnerabilities faster, reducing banks’ response time.

The recent attacks on South Korean financial institutions have revealed how hackers utilize AI technology to commit crimes faster than ever. An investigation conducted by CrowdStrike on October 7 revealed traces of AI-assisted hacking, raising fears that the impacts could spread throughout the financial system and not be limited to the banks under attack.

ARTEX and Claude Code left in the attackers’ own files

The attackers made mistakes by leaving behind valuable clues. CrowdStrike’s Ashley Campion discovered some publicly exposed server directories with Claude Code session records, memory files, and configurations related to ARTEX, an open-source penetration-testing tool developed in China.

In the time span from late September to the beginning of October, the hacker utilized ARTEX along with large language models for the purpose of attacking financial institutions.

CrowdStrike was unable to identify the group responsible for the attack nor the number of victims. It claims with moderate confidence that the hacker spoke Chinese and was motivated by financial gain. It didn’t find any indications of state involvement.

Seven firms, tens of thousands of records

According to a previous report by Cryptopolitan, seven banks were hacked.

Shinhan Bank reported 25,727 compromised records while KB Kookmin reported 119, Hana recorded 89 and BNK Busan reported data on 11 outsourced developers. Yegaram Savings Bank notified around 40,000 affected customers, Welcome Savings Bank reported 2,200 corporate records breaches, and Hyundai Capital reported 146 loan agents being affected.

It took a long time before the attacks were detected. According to reports, Shinhan managed to detect the intrusion within 15 hours, Hana required almost 42 hours, and KB Kookmin detected the breach in 68 hours.

South Korean Bank Data Breaches: Affected Records and Detection Times

The government of South Korea cancelled its plans to expand exemptions from its network-separation rules. In a meeting on October 4, FSC Chairman Lee Eog-weon advocated for increased vigilance. The regulators ordered security inspections of around 500 companies.

Reports from Korea pointed at the fact that the attackers used external services with a lower protection level rather than using the actual banking systems that were controlled by the banks.

Why faster attacks cost more

The IMF’s June report found that AI-enabled adversary activity rose 89% between 2024 and 2025. Average breakout time fell to 29 minutes.

AI can help attackers find vulnerabilities and exploit them faster, leaving banks less time to respond.

BIS researchers Juan Carlos Crisanto, Adrien Currat and Jeffery Yong warned in their September paper:

“This window to detect, decide on and respond to such attacks has narrowed dramatically.”

Meanwhile, PwC’s 2027 survey found that 84% of security and finance leaders expect larger cybersecurity budgets. Yet only 22% would allow AI to act fully autonomously in defense.

How one bank’s breach can reach the rest

The OECD warns that cyberattacks can spread through shared technology providers and financial networks. Breaches have also been linked to deposit withdrawals, weaker lending, falling valuations and higher borrowing costs.

The BIS raises similar concerns about banks relying on the same cloud and AI providers.

Still, the Korean breaches have not caused demonstrated financial contagion or direct theft of bank funds. Regulators are now tasked with making security more stringent, overseeing third-party vendors more closely, and ensuring financial institutions can quickly bounce back before the spread of a cyberattack occurs.

The smartest crypto minds already read our newsletter. Want in? Join them.

FAQs

What is ARTEX and how was it used against Korean banks?

ARTEX is a recently released open-source agentic penetration-testing tool developed in China, distributed on GitHub largely within Chinese-speaking circles. CrowdStrike found it was used alongside large language models in a campaign that exfiltrated data from South Korean financial organizations.

Has the attacker been identified?

No. CrowdStrike has not attributed the activity to any named adversary, assessing only with moderate confidence that the operator is likely a Chinese-speaking, financially motivated actor based on the Chinese-built tooling and Chinese-language prompts recovered.

Why do researchers say AI attacks threaten the wider financial system?

The BIS says frontier AI compresses the time between a vulnerability being found and exploited and makes breaches more likely, while the OECD warns that an incident at one firm can spread through shared providers and financial links, and PwC found 84% of surveyed leaders expect cyber budgets to rise.

Share this article

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Micah Abiodun

Micah Abiodun

Micah Abiodun makes good use of his Environmental Engineering and Management (MSc) at Tallinn University of Technology (TalTech) to polish content and price prediction news at Cryptopolitan. Now on his 7th year in the crypto media space, he covers major cryptos, altcoins, DeFi, stablecoins, macro trends, and emerging tech.​​​​​​​​​​​​​​

MORE … NEWS