Listen to a Summary of This Article
A series of breaches at South Korean financial institutions is providing an early test of what artificial intelligence may mean for cybercrime. The methods used appear largely familiar. What may be changing is the amount of human labour required to find a weakness, test it and exploit it across many targets.
The attackers who reached systems belonging to several South Korean banks did not, on the evidence so far, defeat the heavily defended networks through which deposits and payments are processed. They found less protected systems around them.
At Shinhan Bank, one of the country’s largest lenders, the breach appears to have involved a mobile service used by loan recruiters to follow applications. An attacker found a way around its identification process and gained access to information relating to about 25,000 customers, including names, telephone numbers, annual income and calculated loan limits.
Other institutions reported similar problems. KB Kookmin disclosed an intrusion into a mobile business support service rather than its main banking platform. Hana Bank reported access to a sales support system. BNK Busan Bank said it had blocked most of an attempted attack but acknowledged weaknesses in the way some web pages checked user sessions.
Incidents were also reported at savings banks and finance companies. Welcome Savings Bank was reportedly subjected to an intrusion lasting almost two hours, yet the breach was not identified until nearly five days later.
South Korean President Lee Jae Myung has said that evidence from some of the attacks suggests artificial intelligence may have been involved. Investigators have not publicly established that an autonomous system selected the banks, discovered each weakness and carried out the intrusions without substantial human direction. That distinction is important because much of what has happened in South Korea can be explained without invoking a new form of cyber attack.
The more significant possibility is that artificial intelligence made familiar techniques easier to use at greater speed and across more targets.
The systems around the bank
The pattern emerging from the Korean cases is less about the strength of a bank’s central network than about the number of systems that now surround it. A large financial institution depends on employee portals, loan applications, outside contractors, sales systems, software suppliers, databases and services that have to communicate with the public internet.
Those systems do not necessarily receive the same degree of protection as the infrastructure that moves money.
South Korean security researchers examining the attacks have described activity involving searches of publicly accessible services, attempts to bypass authentication and repeated queries once a weakness had been identified. These are familiar techniques. Security teams have dealt with automated scanning, manipulated requests and attempts to conceal activity behind different internet addresses for years.
What artificial intelligence adds is the possibility that more of the process can be joined together. A software agent can inspect what it finds, choose another test, invoke a tool, read the response and continue without requiring a person to make every decision.
That does not make the method sophisticated in itself. It changes how much work one attacker may be able to undertake.
What ARTEX tells us
Attention has focused on ARTEX, an open source penetration testing system whose name appeared in infrastructure examined during the investigation. The software was designed for security testing and uses large language models together with software agents that can gather information about a target, identify possible weaknesses, plan further investigation and call security tools.
Its presence does not establish that ARTEX carried out every attack, nor does it identify whoever was responsible. The software can be obtained openly and used by legitimate security teams as well as by attackers.
Its Chinese origins have also generated claims that the breaches were connected to China. There is no public evidence for that conclusion. South Korea’s Financial Services Commission has rejected reports that bank account information was stolen and transmitted to China, saying it had found no evidence to support them.
Investigators have identified 28 internet addresses associated with recent attacks across 12 countries. Such addresses are weak evidence of origin because attackers can route traffic through infrastructure elsewhere. Attribution remains unresolved, as does the question of whether every breach belongs to the same campaign.
The most useful evidence about what a system such as ARTEX can do comes from a controlled test by South Korean security company Everspin. Using a deliberately vulnerable application, the software was able to bypass the need for a person operating a browser, communicate directly with an application interface and complete its assigned task after six rounds in 22 seconds.
The figure needs care. It does not mean a bank was hacked in 22 seconds, and Everspin has not claimed that it was. The experiment shows that once a weakness is present, part of the work involved in probing and exploiting it can be automated.
That is a less dramatic finding than the idea of an autonomous artificial intelligence breaking into a bank. It may also be more important.
Cheaper attacks
Microsoft’s latest Digital Defense Report describes artificial intelligence as changing cyber security through speed, scale, economics and autonomy. Attackers are already using AI for reconnaissance, vulnerability discovery, phishing, code generation and analysis after access has been obtained.
Microsoft also cautions against treating fully autonomous attacks as the new norm. Complex intrusions still tend to involve substantial human direction. The technology is not replacing the attacker so much as allowing parts of the work to be delegated.
Anthropic has reported a similar pattern after examining hundreds of accounts associated with malicious cyber activity. It found artificial intelligence being used across a wide range of established attack techniques rather than producing a wholly new category of cybercrime.
The economic consequence may matter more than the technical novelty. Until now, finding an obscure service, learning how it behaves, testing its authentication and working out which requests can be manipulated has consumed time and skill. There are far more vulnerable systems connected to the internet than skilled attackers can examine individually.
If software can perform more of that reconnaissance, repeat tests without tiring and alter its next attempt in response to what it finds, the calculation changes. A weakness does not have to become easier to exploit. It may simply become cheaper to discover.
That is why South Korea deserves attention. The issue is not whether artificial intelligence has become an exceptional hacker. It is whether it can make competent hacking available at a scale that was previously uneconomic.
An old security problem
The focus on AI should not obscure the failures that made the attacks possible.
Several of the affected institutions appear to have protected their central banking systems more effectively than the applications around them. In some cases authentication or session controls were inadequate. In others the weakness appears to have been found in outside software. Some institutions also took days to recognise that an intrusion had occurred.
Those are conventional security problems. Artificial intelligence did not create them.
But automation can make them harder to live with. An obscure system once benefited from a degree of practical anonymity. Discovering it, understanding it and testing it required somebody to spend time doing so. If machines can perform more of that work continuously, obscurity offers less protection.
This may explain why the Korean incidents matter beyond the data already exposed.
South Korea has one of the world’s most digitised economies. Its banks are large, technically sophisticated institutions operating under extensive regulation. Yet modern financial infrastructure consists of far more than the systems that hold deposits or execute payments. It includes a growing perimeter of applications, interfaces, contractors and services, each of which can create another route into information held by the institution.
The early evidence from South Korea does not show artificial intelligence defeating secure banks through some new and extraordinary method. It shows something more ordinary: familiar weaknesses being found in systems connected to organisations that believed their important infrastructure was well defended.
If artificial intelligence changes that process by allowing attackers to search more widely, test more quickly and repeat the work at low cost, cyber security faces a different problem from the one suggested by stories of machines becoming brilliant hackers.
The banks may still be able to protect the vault. They will also have to account for every other way into the building.