Skip to content
Rush Commerce
Software & Dev3 min read

Korean bank breach: an AI pentest tool hit the side systems

An AI penetration-testing tool is linked to breaches at seven Korean financial firms. The attacker skipped core banking and hit sales systems. Audit yours.

A breach at seven South Korean financial firms is the clearest case yet of an AI penetration-testing tool used in a real attack. Investigators found one attacker's IP address at every firm, and traces of an LLM-based pentest platform on a server tied to the attack. The attacker did not break the core banking systems. They went around them, through sales-support and loan-recruiter platforms. That second part is the lesson for every small business.

What actually happened

The Korea Herald reports that the incidents surfaced last week. Shinhan Bank and Yegaram Savings Bank had the largest exposures, about 25,000 and 40,000 people. KB Kookmin, Hana, and Hyundai Capital reported smaller numbers. The stolen data came from loan applications: names, phone numbers, annual income, and calculated borrowing limits. The Korea Times adds resident registration numbers to the list.

The tool: traces point to ARTEX AI, which the Korea Times describes as an open-source autonomous penetration-testing system built on a large language model. Investigators have not said the tool did all the work. The Financial Services Commission chair said only that an AI attack could not be ruled out. We report that link as alleged, not proven.

The response was fast. The FSC ordered financial firms to block outside access to their systems unless that access is essential. The Financial Supervisory Service ordered emergency security inspections. President Lee Jae Myung ordered a full investigation. Bloomberg, via The Star says the attacker got into Shinhan's loan recruiter services.

Why an AI penetration-testing tool changes your risk

These banks spend tens of billions of won on security each year. They locked the vault. The attacker walked in through the side door: a partner portal for the people who sell loans.

An AI pentest agent makes that side-door search cheap. It runs reconnaissance, finds login endpoints, tries attacks, and checks the results, with no human at the keyboard. The forgotten system is no longer safe because nobody bothered to look. A machine now looks at all of it.

For a small business, your side doors look like this:

  1. The old lead form that writes straight to a database.
  2. The partner or wholesale portal a contractor built in 2021.
  3. The staging site with real customer data in it.
  4. The admin panel on a public URL with no MFA.

Do what the Korean regulator ordered. List every system that faces the internet. Take offline whatever does not need public access. Put MFA and rate limits on every login that stays.

Key takeaways

  • Seven Korean financial firms were breached; one attacker IP appeared at all of them
  • Traces of the ARTEX AI penetration-testing tool were found, but its role is not yet confirmed
  • The attacker skipped core banking and used sales-support and loan-recruiter systems
  • Regulators ordered firms to cut all non-essential outside access
  • Inventory your internet-facing systems, retire what you don't need, and lock down the rest

Your weakest system is the one you forgot you have. We map every public endpoint you run, shut down the dead ones, and rebuild the rest with auth you can audit. See how we work, or send us the list of things you're not sure about.

Sources: Korea Herald, Korea Times, Bloomberg via The Star.

  • #ai-security
  • #data-breach
  • #penetration-testing
  • #south-korea
  • #attack-surface
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.