Data Exposures Hit at Least Seven Korean Financial Institutions, Affecting 65,000 Customers
At least seven financial institutions suffered data exposures from late September to early October, while no stolen funds have been identified.

At least seven South Korean financial institutions suffered data exposures in a suspected coordinated campaign that used artificial intelligence tools, raising concerns for banks and digital-asset firms that rely on peripheral systems.
About 25,000 Shinhan Bank customers and 40,000 Yegaram Savings Bank customers were affected. The exposed information included names, phone numbers, annual income and loan amounts. No stolen funds have been identified.
The attacks focused on systems used for loan inquiries by brokers and on employee mobile-work platforms rather than core banking infrastructure. Korean regulators found overlapping internet protocol addresses across several incidents and suspect a common attacker.
Investigators identified a Hong Kong-based server used to control the operation and another server running ARTEX, an open-source artificial intelligence penetration-testing system. The investigation also recovered ARTEX configuration files, Claude Code chat records and AI memory files.
The configuration showed ARTEX was primarily powered by DeepSeek v4.1-flash, with Claude Code also in use. Other sessions called GLM-5.3 and Grok 4.6. Chat records included questions about selling stolen Korean data and requests for a security researcher résumé containing biographical details that did not fully match.
Investigators assessed that the attacker may have used Chinese and was motivated by profit, but the person’s identity has not been confirmed.