A series of intrusions against financial institutions in South Korea has been linked to ARTEX, an open-source artificial intelligence agent developed in China for security testing. The attacks hit at least seven companies in the sector and exposed personal data of about 68,000 people, while police try to identify those responsible.
The link to ARTEX was revealed by the Wall Street Journal and reinforced by experts and investigators who found traces of the tool on servers related to the attacks. South Korean President Lee Jae Myung said on Tuesday (6) that there are signs of the use of artificial intelligence in the intrusions.
Among the affected institutions are Shinhan Bank, KB Kookmin Bank, and Hana Bank. Shinhan reported a leak involving approximately 25,000 customers, while Yegaram Savings Bank recorded about 40,000 people affected.
The South Korean Financial Services Commission said, however, that so far there is no evidence of leakage of passwords, OTP codes, or information directly usable to operate accounts. No cases of customer money being withdrawn as a result of the attacks have been identified either.

ARTEX automates stages of penetration testing
ARTEX is an autonomous penetration testing system based on multiple agents. The tool can receive objectives, plan stages, and execute vulnerability checks with support from external language models.
The system is not exactly an AI model, but a layer that coordinates models and security tools to automate activities that would normally require human intervention. The project was created for research and authorized testing and prohibits use against systems without permission.
The Chinese origin of the software does not indicate that the hackers are Chinese. Police have not yet attributed the operation to any group or country, and the accesses went through IP addresses distributed across several markets.
The National Police Agency assigned 28 investigators to the case and is working with foreign authorities to track the infrastructure used by the attackers.
Regulators also ordered banks, insurers, card companies, and fintechs to review systems exposed to the internet, access controls, and intrusion detection mechanisms.
Authorities also warned of possible fraud involving the already compromised data, including phishing, fraudulent messages, and personalized scams.



