At least seven financial institutions in South Korea suffered data breaches from late September to early October, including Shinhan Bank, KB Kookmin Bank and Hana Bank.
Among the disclosed cases, about 25,000 Shinhan Bank customers and roughly 40,000 Yegaram Savings Bank customers were affected. The leaked information included names, phone numbers, annual income and loan limits. No theft of funds has been identified so far.
Attacks targeted peripheral banking systems
The attacks mainly hit peripheral business systems, including loan inquiry services used by loan brokers and mobile work systems for bank employees.
Because several incidents involved overlapping IP addresses, South Korean regulators suspect the breaches may have been carried out by the same attacker.
President and security firm pointed to possible AI use
On Oct. 6, South Korean President Lee Jae-myung said the attacks may have used AI.
On Oct. 7, CrowdStrike said the attacker used one server located in Hong Kong to control the campaign, while another ran ARTEX, an open-source AI penetration testing system. Investigators also obtained ARTEX configuration files, Claude Code chat records and AI memory files.
Configuration files and chats revealed tool usage
CrowdStrike said the configuration showed the attacker mainly used DeepSeek v4.1-flash to power ARTEX. The actor also used Claude Code and, in other sessions, called GLM-5.3 and Grok 4.6.
Chat logs showed the attacker asked about channels for selling leaked South Korean data and related Telegram trading groups. The actor also asked AI to draft a security researcher résumé to be written into ARTEX penetration testing results. Prompts included details such as age 26, Maoming in Guangdong, South China University of Technology and contact information, though the date of birth did not match the stated age.
CrowdStrike said the attacker may have been a Chinese-language user and may have been financially motivated, but the real identity has not been confirmed.

