Chinese AI Agent Linked to Major Cyberattack on South Korean Banks, Exposing New Global Financial Threat

Hackers allegedly exploited an open-source Chinese AI cybersecurity tool to penetrate seven South Korean financial firms and expose data belonging to roughly 68,000 people

Book Now

South Korean investigators say hackers used a Chinese-made AI agent called Artex to breach at least seven financial firms, stealing personal data belonging to 68,000 people.
Reported by:

Cherry Meigh Timbol
News Content Editor
Published October 7, 2026

A new cybersecurity crisis in South Korea is raising alarm far beyond Seoul after investigators found evidence that hackers may have used an AI agent developed in China to breach multiple financial institutions and steal sensitive customer information.

The attacks, which affected at least seven South Korean financial firms, have exposed personal information belonging to approximately 68,000 people, according to reporting by The Wall Street Journal. Investigators believe the attackers may have used Artex AI, an open-source cybersecurity agent developed by Chinese cybersecurity engineer Li Puhua, who operates under the alias Autumn.

The case is significant because it could represent one of the clearest examples yet of agentic AI being used in attacks against the financial sector.

What happened?

South Korean authorities began detecting the attacks in late September and early October. The National Police Agency has now opened a formal investigation involving its cyberterrorism investigation unit.

The affected institutions include major banks and financial companies such as Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital.

Investigators believe attackers exploited weaknesses in systems used by banks and financial companies rather than breaking directly into their central payment networks.

In one reported case, attackers bypassed authentication on a portal used by loan brokers, exposing information connected to approximately 25,000 Shinhan Bank customers. Other incidents exposed information belonging to customers and employees of several financial institutions.

The stolen information reportedly includes names, telephone numbers, income information, borrowing details and personal-loan limits.

There have been no reports that customer funds were directly stolen.

However, cybersecurity specialists warn that personal financial information can be extremely valuable to criminals because it can later be used for identity theft, targeted fraud and voice-phishing operations.

The Artex AI connection

At the center of the investigation is Artex, an open-source AI agent designed for cybersecurity work.

Artex itself is not an AI model. Instead, it can connect to different large language models and use them to perform cybersecurity-related tasks.

According to The Wall Street Journal, the tool can work with models including OpenAI’s GPT, Anthropic’s Claude and China’s DeepSeek. South Korean investigators have not established which underlying model or models were actually used in the bank attacks.

The tool was originally designed to help organizations identify vulnerabilities in their networks.

But because Artex is open source, malicious users can download, modify and repurpose the technology.

South Korean investigators reportedly discovered traces associated with Artex on systems involved in the attacks, including a Chinese-language reference connected to the tool.

That does not, however, prove that the Chinese developer or the Chinese government was responsible for the attacks.

A critical distinction: Chinese tool does not mean Chinese hackers

The origin of the software has already triggered geopolitical concerns, but investigators have not publicly identified the attackers.

Authorities traced activity through more than two dozen—or approximately 30, according to South Korean financial authorities—IP addresses across numerous countries and territories, including the United States, Japan, Germany, Vietnam, Thailand, Malaysia and Singapore.

Cybersecurity experts caution that an IP address does not necessarily identify the real attacker because criminals routinely route operations through compromised computers, proxy services and other infrastructure.

For now, therefore, the evidence supports a connection to Chinese-developed software, but not a confirmed attribution of the attacks to China.

Why AI changes the threat

The biggest concern may not be Artex itself.

It is the possibility that AI agents can allow people with relatively limited cybersecurity expertise to conduct sophisticated attacks.

Traditional cyberattacks often require attackers to manually perform reconnaissance, identify vulnerabilities, develop attack strategies and execute multiple technical steps.

AI agents can potentially automate significant portions of that process.

Rather than simply answering a hacker’s questions, an agent can be instructed to pursue an objective, analyze results, adjust its strategy and continue working through multiple stages.

South Korean President Lee Jae Myung warned that the emergence of AI-assisted attacks could make cybercrime significantly easier.

At a Cabinet meeting, Lee ordered authorities and financial institutions to act immediately, saying that “speed is of the essence.”

South Korea moves into emergency response

South Korean financial regulators have responded with heightened security measures.

The Financial Services Commission and Financial Supervisory Service have instructed financial companies to examine externally accessible systems, strengthen authentication and access controls, identify vulnerabilities and block suspicious infrastructure.

The Financial Supervisory Service reportedly identified around 30 IP addresses associated with the attacks across multiple countries and territories.

South Korea has also established a 24-hour emergency response operation involving cybersecurity authorities.

Police have assigned 28 investigators to the formal investigation into the attacks.

The government’s concern is also spreading beyond banks. Brokerage firms, insurance companies and credit-card providers are reviewing their own systems for similar vulnerabilities.

The weakness may be outside the banks themselves

One of the most important lessons from the attacks is that a financial institution does not necessarily need to have its core banking infrastructure directly compromised for customers to be exposed.

Investigators believe some of the attackers targeted third-party systems, business-support platforms and information lookup services used by employees and loan brokers.

That creates a much larger cybersecurity problem.

Banks can spend enormous amounts of money protecting their central systems, but vulnerabilities in a contractor’s platform, broker portal or external service can potentially provide attackers with another route to sensitive information.

The South Korean incidents therefore highlight the importance of securing the entire financial ecosystem rather than focusing exclusively on the banks’ primary networks.

Reactions

The attacks have generated concern among South Korean officials, cybersecurity researchers and financial institutions.

President Lee has demanded immediate action from banks and government agencies.

Cybersecurity analyst Mun Chong-hyun, head of Genians Security Center, has warned that AI-powered cyberattacks are increasing and could become more widespread internationally.

The financial sector has responded by increasing monitoring and reviewing systems that can be accessed from outside corporate networks.

The developer of Artex has also reportedly changed the tool’s guidelines to explicitly prohibit unauthorized intrusion, data theft and other malicious activities.

But because the software is open source, simply changing the guidelines cannot prevent someone from modifying the code.

The geopolitical dimension

The incident arrives amid a growing technological competition between the United States and China over artificial intelligence.

AI has increasingly become part of national-security discussions because the same technology capable of improving cybersecurity can also potentially be used to automate offensive operations.

Previous incidents have already demonstrated concerns about AI being used in cyber operations.

The latest South Korean attacks add another dimension: open-source agentic AI may allow cybercriminals to combine different AI models with automated security tools to attack targets at a scale previously difficult for individual hackers to achieve.

That could force governments to reconsider how AI developers, open-source projects and financial institutions manage cybersecurity risks.




🧩 Bottom Line:

The South Korean bank attacks represent a potentially important turning point in the evolution of cybercrime.

The most significant development is not simply that hackers allegedly used a Chinese-developed AI tool. It is that an AI agent appears to have helped attackers automate parts of the process of finding and exploiting weaknesses in financial systems.

Investigators have not identified the perpetrators, and there is currently no evidence establishing that the Chinese government or the developer of Artex directed the attacks.

But the incident demonstrates how quickly legitimate AI cybersecurity technology can potentially be repurposed for criminal operations.

As AI agents become more capable and autonomous, banks may no longer be defending only against human hackers. They may increasingly be defending against automated digital attackers capable of searching, adapting and attacking at machine speed.



SOURCES: BREITBART NEWS – Report: Hackers Use Chinese AI Agents to Breach South Korean 
THE WALL STREET JOURNAL – Hackers Use Chinese AI Tool to Hit South Korean Banks, Exposing New Risk
QUARTZ –  Hackers used a Chinese AI tool to breach 7 South Korean banks


Buy Me a Coffee

Book Now

Book Now

Book Now

Book Now

About MeighTimbol 2301 Articles
A News Content Editor and News writer focused on U.S. politics, international affairs, breaking news, geopolitics, and major global developments. Her work examines emerging events, political decisions, and issues affecting communities in the United States and around the world. Through clear and engaging reporting, she aims to help readers understand not only what happened, but why it matters.
0 0 votes
Article Rating
Subscribe
Notify of
0 Comments
Oldest
Newest Most Voted