South Korea probes string of bank data leaks as AI tools surface in attack trail

South Korea probes string of bank data leaks as AI tools surface in attack trail

N
News Editor
2026-10-08 10:29:26
South Korea is investigating a wave of data breaches that hit at least seven financial institutions from late September to early October, including Shinhan Bank, KB Kookmin Bank and Hana Bank. Known victim counts include about 25,000 customers at Shinhan Bank and roughly 40,000 at Yegaram Savings Bank. Exposed data included names, phone numbers, annual income and loan limits, while no theft of funds has been identified so far. Authorities suspect the incidents may be linked because several attacks shared overlapping IP addresses. On Oct. 6, South Korean President Lee Jae-myung said the attacks may have involved AI. A day later, CrowdStrike said the threat actor used one server in Hong Kong to control the operation and another to run the open-source AI penetration testing system ARTEX. Investigators reportedly obtained ARTEX configuration files, Claude Code chat logs and AI memory files. According to CrowdStrike, the configuration showed ARTEX was mainly powered by DeepSeek v4.1-flash. The attacker also used Claude Code and, in other sessions, called GLM-5.3 and Grok 4.6. Chat records showed queries about where stolen South Korean data could be sold and which Telegram groups were used for trading. CrowdStrike said the actor may be a Chinese-language user with a profit motive, but the person’s real identity remains unconfirmed.

At least seven financial institutions in South Korea suffered data breaches from late September to early October, including Shinhan Bank, KB Kookmin Bank and Hana Bank.

Among the disclosed cases, about 25,000 Shinhan Bank customers and roughly 40,000 Yegaram Savings Bank customers were affected. The leaked information included names, phone numbers, annual income and loan limits. No theft of funds has been identified so far.

Attacks targeted peripheral banking systems

The attacks mainly hit peripheral business systems, including loan inquiry services used by loan brokers and mobile work systems for bank employees.

Because several incidents involved overlapping IP addresses, South Korean regulators suspect the breaches may have been carried out by the same attacker.

President and security firm pointed to possible AI use

On Oct. 6, South Korean President Lee Jae-myung said the attacks may have used AI.

On Oct. 7, CrowdStrike said the attacker used one server located in Hong Kong to control the campaign, while another ran ARTEX, an open-source AI penetration testing system. Investigators also obtained ARTEX configuration files, Claude Code chat records and AI memory files.

Configuration files and chats revealed tool usage

CrowdStrike said the configuration showed the attacker mainly used DeepSeek v4.1-flash to power ARTEX. The actor also used Claude Code and, in other sessions, called GLM-5.3 and Grok 4.6.

Chat logs showed the attacker asked about channels for selling leaked South Korean data and related Telegram trading groups. The actor also asked AI to draft a security researcher résumé to be written into ARTEX penetration testing results. Prompts included details such as age 26, Maoming in Guangdong, South China University of Technology and contact information, though the date of birth did not match the stated age.

CrowdStrike said the attacker may have been a Chinese-language user and may have been financially motivated, but the real identity has not been confirmed.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.