ARTEX AI, a Chinese-language, open-source penetration-testing tool, has been identified by South Korean investigators as having been used in the wave of data breaches that hit the country's banks in recent days. A Korea Financial Security Institute official told The Herald Business on Saturday 3 October 2026 that tracing attacker IP addresses and server logs from Shinhan Bank - the first institution to report an incident - turned up evidence pointing to ARTEX, confirming what the security industry had suspected.

The official was careful about what that means: "It is true that AI was used in the attacks, but the AI did not act independently without human involvement. A hacker used the AI as a tool."

What is ARTEX AI?

According to The Herald Business, Seoul Economic Daily and The Asia Business Daily, ARTEX AI is an open-source system, published on GitHub and aimed mainly at Chinese-speaking users, that uses a large language model and a multi-agent design to automate penetration testing. In practice that means gathering information on a target, scanning for vulnerabilities, planning attack paths, running security tools and verifying what it finds.

Such tools are built for defenders who are authorised to test their own systems. The concern, as Asia Business Daily put it, is that if attackers abuse them, they can automate and speed up cyberattacks. The first public clue came on 2 October, when security researchers reported that the HTML title of web servers linked to the attacks carried the Chinese string "ARTEX - autonomous penetration testing console". At that stage, both Seoul Economic Daily and Asia Business Daily stressed that actual use of the tool had not been confirmed. The Financial Security Institute's statement a day later moved the story from suspicion to evidence.

Which South Korean banks were breached?

Per The Herald Business, the attacks are believed to have been concentrated between Sunday and Thursday of the past week, and all targeted internal employee-facing or partner-facing systems rather than customer-facing internet or mobile banking. The confirmed figures reported so far:

Shinhan Bank: 25,729 people's data exposed through a loan-agent inquiry service. Seoul Economic Daily reported that the bank said an outsider bypassed identity verification in that service.

KB Kookmin Bank: 119 records leaked from an employee mobile work-support system.

Hana Bank: 89 records taken from an employee sales-support system known as ODS.

BNK Busan Bank: information on 11 contract workers exposed.

The institute said Woori Bank and NH NongHyup Bank were also targeted but suffered no breach, because the specific vulnerabilities the attacker sought were not present. The Herald Business reports that the confirmed number of affected individuals stood at just under 26,000 and could rise.

Is the breach spreading beyond banks?

Yes, according to the latest reporting. The institute official told The Herald Business that "far more institutions were attacked than those that ended up with actual incidents" and that organisations outside banking were hit. Two savings banks are under investigation; Yegaram Savings Bank had already posted a notice saying an unidentified hacker accessed its systems and caused a personal data leak.

Later reports widened the picture. Businesskorea and Chosun Biz reported on 4 October that financial authorities had confirmed intrusions at seven firms: the four banks plus Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. Businesskorea cited an estimated 2,200 or more pieces of corporate customer information at Welcome Savings Bank. Authorities said internet and mobile banking were not affected and no monetary loss had been confirmed.

Who is behind the ARTEX AI attacks?

That is not established. ARTEX is publicly available, and Chosun Biz reports that attacking IP addresses came from multiple countries, including South Korea, the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand and the United Kingdom. Financial authorities said it is difficult to point to a specific country or organisation as the actor, and the Korean National Police Agency's Cyber Bureau is investigating. The institute official added that the attackers keep switching IPs while the method stays identical, and that traffic from ARTEX carries a specific data signature that helps identify the attacker.

The official also noted that the timing is too far apart for investigators to link these attacks to an earlier reported hack of the Government24 portal, which they could not verify independently.

Are customers' funds at risk?

The institute believes the risk of direct financial loss is low. "The attacker did not take over the systems - they got in and extracted information by querying it," the official told The Herald Business, adding that the leaked data could be used for voice phishing and similar scams, but that direct transfers out of accounts are not expected. Customers of the affected banks should treat unexpected calls or messages about loans or accounts with caution.

What are regulators doing about it?

The Herald Business reports that the institute is drafting a recommendation for financial firms to audit internal employee-facing systems among their external access points, which the Financial Services Commission plans to issue to the sector. An FSC official called the simultaneous attacks on multiple institutions "a very extraordinary set of circumstances".

Per Yonhap-based reporting on the 4 October emergency meeting, the Financial Supervisory Service sent attacker IPs and security guidance to around 500 financial firms, with banks and card companies told to complete emergency checks by 6 October and others by 8 October. The Herald Business also notes the incidents could slow the push to relax network-separation rules, as regulators have been running an emergency relaxation for AI security testing since June, expanded this month to 75 firms.

Why ARTEX AI matters beyond Korea

The institute official's warning is the part that travels: attacks of this type "could be repeated at any time", and "there are a great many open-source AI tools like ARTEX", with currently no way to restrict everything being developed and distributed around the world. The institute's view is that customer-facing banking has been hardened heavily, while employee-facing systems were managed less rigorously and are now where attackers are looking. For security teams anywhere, the practical lesson is to inventory and test those internal and partner-facing systems the way attackers' automated tools now can.

Sources: The Herald Business (exclusive, 3 October 2026); Seoul Economic Daily (2 October 2026); The Asia Business Daily (2 October 2026); Businesskorea and Chosun Biz (4 October 2026). Details are as reported by those outlets and may change as investigations continue.