The Financial Services Commission (FSC) held an emergency meeting following incidents at multiple South Korean banks. Officials confirmed a data breach at Shinhan Bank and said other cybersecurity incidents affected Kookmin Bank. Hana Bank also suffered a limited-scope breach after its sales-support system was compromised.
According to local media reports, Shinhan Bank leaked the details of 25,000 customers, while Kookmin Bank leaked credit card information of 119,000 clients. The FSC said it shared all actionable information with relevant agencies, including the Korea Internet & Security Agency (KISA).
Financial companies have been instructed to inspect externally accessible IT systems, reduce unnecessary information exposure, check for missing authentication and access controls, and coordinate threat responses. Authorities also pledged to oversee consumer protection and compensation.
While official channels provided no details about the perpetrators, South Korean news agency Yonhap reported that a server used in the attacks had an HTML page title containing a Chinese-language string associated with ARTEX AI, an open-source penetration-testing system that uses agents to automate information gathering, vulnerability discovery, and attack-path planning. The banks and financial authorities have not confirmed the use of ARTEX AI in the breaches. The Chinese-language string does not link the attacks to any particular threat actor.
Moon Jong-hyun, head of the Genian Security Center, posted on LinkedIn that several threat analysts believe the breaches involved AI-based attack automation tools. Separately, President Lee ordered a thorough investigation into personal data leaks at financial and public institutions.