South Korea Says AI Helped Hackers Into Seven Financial Firms. The Way In Was a Side Door.

On Tuesday, October 6, South Korea's president Lee Jae Myung told a cabinet meeting at Cheong Wa Dae something I had not yet heard from a head of state. "In some hacking cases, details have emerged of the possible use of artificial intelligence (AI), causing the people to feel great concern and anxiety," he said, according to Yonhap. In the Korean wording reported by Pressian, he added that with AI, people with no special skills can now hack easily.
He was talking about a wave of breaches that began at the end of September. The Financial Services Commission says Shinhan Bank reported its incident on September 30. By Sunday, October 4, according to Yonhap and the Korea Herald, seven firms had reported exposed data: Shinhan, KB Kookmin, Hana and BNK Busan banks, Yegaram and Welcome savings banks, and Hyundai Capital. The Korea Herald, citing reports, puts the combined exposure at about 66,000 people and 2,200 corporate records, including 25,729 people at Shinhan.
I build a LegalTech product on Claude, and client documents are the most sensitive thing it holds. So I read this story as a defender.
What "AI was used" actually means
The claim is narrower than the headlines.
On October 2, Seoul Economic Daily reported that analysts had found the title of an AI console, ARTEX, labelled in Chinese as an "autonomous penetration testing console", on web servers believed to be part of the attack infrastructure. ARTEX AI is an open-source system published on GitHub, mostly in Chinese, that combines a large language model with several agents to run a penetration test from reconnaissance to vulnerability verification.
The next day, the Herald Business quoted an official of the Financial Security Institute, the sector's security body, saying investigators had traced the attack IPs and server logs at Shinhan and found evidence pointing to ARTEX. The same official drew a clear line: "It is true that AI was used in the attacks, but the AI did not act independently without human involvement. A hacker used the AI as a tool." And on the outcome, the attacker "did not take over the systems"; they "got in and extracted information by querying it."
No rogue model, then. A person with an automated assistant, querying systems that answered.
Which doors were open
This is the part that should interest a CTO more than the AI. According to the institute, speaking on October 3, every attack hit internal employee or partner-facing systems, not customer-facing internet or mobile banking. At Shinhan, it was a loan-agent inquiry service, where an outsider bypassed the identity verification, the bank said. At KB Kookmin, a mobile work-support system for staff. At Hana, an employee sales-support system.
The official put it bluntly: security on customer-facing services "has been enormously strengthened, but internal employee-facing systems had been managed less rigorously." The FSC's written instructions from its October 4 emergency meeting say the same thing without names: systems used by loan recruiters, outsourcing contractors and staff were the cause of the recent incidents.
What leaked, per the Korea Herald: names, phone numbers, and in some cases resident registration numbers, annual income and loan limits. No passwords and no one-time codes, says the FSC. That is exactly what you need to call a stranger, quote their income back to them and sell them a fake refinancing. The regulator issued a consumer alert on October 6 for that kind of tailored loan fraud, while noting that no case of customer money lost to phishing had been confirmed so far.
What AI changes in the attacker's economics
The best primary data I know comes from a model vendor. In November 2025, Anthropic described a campaign in which attackers manipulated its Claude Code tool into performing 80 to 90 percent of the work, with humans stepping in at perhaps four to six decision points, against roughly thirty targets. At peak, the AI made "thousands of requests, often multiple per second."
Put next to the Korean case, three things change.
Coverage gets cheap. Reconnaissance used to be the slow, boring part. An agent never tires of checking every portal nobody remembers. The loan-agent page was not found because it was clever. It was found because checking it cost nothing.
One playbook runs across a whole industry. The institute says the attacker keeps switching IPs while the method and the targeted weaknesses stay the same, and that "far more institutions were attacked than those that ended up with actual incidents." Banks run similar systems and similar partner tools. A recipe that works once gets replayed everywhere within days.
The skill floor drops. That was Lee's point, and Kim Seung-joo, a professor at Korea University's School of Cybersecurity, told CBS radio, as quoted by the Korea Herald, that AI hacking tools are "making it easier for nonexperts to carry out attacks."
What it does not change
The model still needs an open door. Woori Bank and NH NongHyup Bank were targeted too. The Herald Business reports they had no breach because the specific vulnerabilities the attacker was looking for were not present in their systems. Same wave, different outcome. The difference was the door, not the AI.
Automated attacks are also noisy and fallible. Anthropic's own report says its model sometimes hallucinated credentials or claimed to have extracted secrets that were in fact public. The Korean institute says there is "a specific data signature common to traffic originating from ARTEX, which allows us to identify the attacker." Volume and repetition are fingerprints.
And sharing still works. Additional victims came to light after the institute circulated the IPs from its Shinhan investigation and other banks went back through their access logs. Blocking those IPs, the official warned, "is little more than emergency first aid." The logs were what found the breaches.
Seoul's orders read like a checklist
What strikes me in the FSC's October 4 instructions is how little they are about AI. Inventory every IT asset and service reachable from outside, customer-facing or not. Block, in principle, all external access that is not indispensable. Where a partner must get in, cut their access rights and the data they can look up to the strict minimum. Stop keeping personal credit data in partner systems that do not need it. Check that there is no path where authentication can be skipped or bypassed. Verify that threat information already shared actually reached your detection rules and patches. Only the fifth and last item, which I would translate as "defending against AI attacks with AI", mentions the technology at all, and it asks firms to rebuild on zero-trust principles.
There is a twist. Since June, Korea has been easing its network-separation rules so financial firms can use AI for security testing. On October 6, Etoday reported, the FSC postponed choosing the next group of firms, planned for October 7: its security staff were busy with the incidents, and it wanted more time to review the candidates' security. It says the policy is not being reversed.
What I am doing on Monday
The product I build exposes MCP servers. An MCP server is, by design, an interface a model can read and call quickly. It is also the exact profile of a loan-agent lookup page: a side door built for a trusted partner.
So, three things. I am listing every hostname and endpoint reachable from the internet, including partner tools, staging copies and MCP endpoints, and writing next to each one what a caller can read before and after authentication. I am putting a read budget per identity on anything that returns personal or client data, with an alert, because an agent's signature is its rate. And I am running an authorized automated scan of my own surface, because somebody else's agent will.
None of this is new. What changed is that the attacker's cost of finding a forgotten door went close to zero. My cost of closing it did not move.
Sources
- Yonhap via The Korea Times, "Lee orders dedication of personnel, resources to handling hacking attacks" (6 de octubre de 2026)
- Pressian, "李대통령 '금융기관 해킹에 AI 활용…사전 탐지·선제 차단해야'" (6 de octubre de 2026)
- Financial Services Commission, "全금융권이 비상한 경각심을 갖고 침해위협에 대응해 나가겠습니다" (meeting of 4 de octubre, published 6 de octubre de 2026)
- Financial Services Commission, "최근 금융권 개인정보 유출사고에 따른 보이스피싱·스미싱 등 피해에 주의하세요" (6 de octubre de 2026)
- The Korea Herald, "Police launch major probe as suspected AI hacks sweep through banks" (6 de octubre de 2026)
- The Herald Business, "Exclusive: Chinese AI tool ARTEX used in wave of bank hacks, probe finds" (3 de octubre de 2026)
- Seoul Economic Daily, "Traces of Chinese AI Hacking Tool Found on Server Tied to Shinhan Bank Breach" (2 de octubre de 2026)
- Etoday, "금융위, 해킹 사태에 2차 망분리 규제완화 기관 선정 보류" (6 de octubre de 2026)
- Anthropic, "Disrupting the first reported AI-orchestrated cyber espionage campaign" (13 de noviembre de 2025)
