AI-Assisted Intrusions Hit South Korean Financial Support Systems
The campaign used the agentic penetration-testing tool ARTEX and multiple large language models. South Korean regulators ordered sector-wide inspections after reported breaches and data leaks.

AI-assisted intrusions targeted South Korean financial organizations from late September through early October, exposing data from support systems and prompting regulators to order sector-wide security inspections.
The activity involved ARTEX, an open-source agentic penetration-testing tool developed in China, used alongside large language models. Investigators found configurations for DeepSeek v4.1-flash, GLM-5.3 and Grok 4.6, along with Claude Code session records on exposed infrastructure.
The documented incidents involved a loan-progress inquiry service used by financial brokers and an employee mobile work-support system. The available findings do not establish that customer funds were stolen, that core banking transaction systems were compromised or that the incidents disrupted financial markets.
The activity has not been tied to a named adversary. Investigators assessed with moderate confidence that the operator was likely Chinese-speaking and financially motivated, based on Chinese-developed tooling and Chinese-language prompts. The assessment does not establish state involvement.
South Korea’s Financial Services Commission held an emergency financial-sector meeting Oct. 4 at 1 a.m. ET (5 a.m. UTC) after a series of cyberattacks and data leaks. An intrusion reported by Shinhan Bank on Sept. 30 prompted an immediate on-site investigation, followed by inquiries into additional reports from financial companies.
The commission ordered banks, card companies, insurers, securities firms, fintech companies and other financial institutions to inspect externally exposed assets and services, vulnerabilities, authentication and access controls, system entry routes and intrusion-detection systems.
Financial institutions were also directed to share attack IP addresses, methods and intrusion indicators across the sector. The measures include restricting external access and unnecessary access to personal credit information.
The response reflects concern that weaknesses in connected support systems could create broader risks across financial institutions. The incidents were not shown to have compromised core banking transaction systems.
The Financial Services Commission and Financial Supervisory Service warned Oct. 6 of potential phishing and loan scams using leaked personal information. They began a one-month special response period and urged financial institutions to inspect exposed systems and security controls.
“AI attacks are defended with AI,” Financial Services Commission Chairman Lee Eog-weon said. The commission is promoting stronger AI-based defenses as part of the sector’s response.