This is the first bank breach wave we’ve seen where a regulator says, on the record, that an AI pentest agent did the legwork. The interesting part isn’t the AI. It’s where it went: straight past the hardened customer apps to the internal tools nobody was watching as closely.
What got hit. Per the FSI via The Herald Business: Shinhan exposed 25,729 people through a loan-agent inquiry service; KB Kookmin reported 119 records from an employee mobile work-support system (The Korea Herald says more than 100 customers); Hana lost 89 records from an employee sales-support system called ODS; BNK Busan exposed data on 11 contract workers. The Korea Times reports the leaked fields included names, phone numbers, annual income and loan limits, plus some resident registration numbers. Yonhap Infomax also lists Hyundai Capital among the affected firms, and the FSI is reviewing two savings banks, one of which (Yegaram Savings Bank) has already posted a leak notice. Confirmed victims stand at just under 26,000, and the FSI says that number could rise.
How it ran. Attacks clustered over roughly five days, Sunday through Thursday, per the FSI. Investigators traced attack IPs and server logs from Shinhan, the first bank to report, and found a traffic signature common to ARTEX. When the FSI shared those IPs, other banks searched their own logs and found breaches they’d missed. The attacker rotates IPs when one is blocked, with two or three overlapping at each bank, and the FSI says the activity is still ongoing. The official’s summary: the attacker didn’t take over systems, they got in and pulled data by querying it. Woori Bank and NH NongHyup Bank were targeted but weren’t breached, because the specific weaknesses the attacker looked for weren’t there.
The regulator’s response. The FSC held an emergency meeting on Oct 2 and a sector-wide one on Oct 4 chaired by FSC Chairman Lee Eog-weon, covering banks, insurers, brokers, card firms, savings banks and fintechs. Firms must inspect every externally reachable system, including ones that aren’t customer-facing, tighten authentication and access control, and report results. President Lee Jae-myung ordered a full probe. The Herald Business notes this lands while regulators are loosening Korea’s network-separation rules for AI security testing, with 75 firms in the second phase this month.
What we’d do this morning. Pull the list of every internet-reachable app that isn’t customer-facing: broker and agent portals, employee mobile work apps, sales-support tools, partner inquiry pages. Those got the leftover security budget, and an agent that tirelessly walks every endpoint finds them first. Check each for missing auth on API routes and query endpoints that return more rows than a single user should ever see. Then hunt the logs for one client walking parameter space fast across several hosts, rotating through a handful of IPs. That’s what tool-driven recon looks like. Blocking IPs, in the FSI’s words, is “little more than emergency first aid.” Fix the endpoint.
The market read. Last week AI offense was a funding story, with Armadin’s $255.5M Series B. This week it’s in a bank regulator’s incident findings. That’s a tailwind for anyone selling continuous exposure management, API security and AI-driven red teaming into banks, and it’s why Korea’s FSC is already telling firms to “defend against AI attacks with AI.”
Desk sheet: FSI via The Herald Business (Oct 3): ARTEX AI evidence in Shinhan attack IPs and logs; human-operated; Shinhan 25,729 via loan-agent inquiry service; KB 119 records via employee mobile work-support system; Hana 89 via ODS; BNK Busan 11 contract workers; Woori and NH targeted, not breached; just under 26,000 confirmed; attacks ongoing with IP rotation. FSC: emergency meetings Oct 2 and Oct 4; sector-wide inspection of external access points, authentication and access control. Attacker identity and initial access method: Undisclosed.
