Seven South Korean financial firms. One week. More than 66,000 people exposed. Bad as the data theft is, the bigger worry for security teams outside Korea is a free AI agent on GitHub called ARTEX. Investigators found traces of it on IPs tied to the breaches.
Attackers walked through internet-facing internal tools with weak or bypassable authentication, including a loan-broker lookup service at Shinhan Bank and an employee app at KB Kookmin Bank.
Last year, AI-run attacks needed a state hacking crew. In November 2025, Anthropic said a Chinese state-sponsored group had used Claude Code to automate most of an espionage campaign against about 30 targets. This year, that kind of tooling is a free download, and it surfaced in attacks on Korea’s biggest banks.
Its developers describe ARTEX as an autonomous penetration-testing system built on multiple LLM agents. A planner breaks a target into tasks. Worker agents run them with real tools (shell commands, HTTP requests, port scans) and search each other’s logs for leads. The GitHub page bills ARTEX as the winner of a Baidu-run AI agent attack-and-defense challenge.
Mun Jong-hyun, who heads the Security Center at South Korean security firm Genians, first flagged Chinese-language ARTEX strings on a server tied to the Shinhan attack, according to SBS Biz. He expects more of the same.
AI-agent cyberattacks “will surge worldwide, not just in Korea,” Mun told Financial News.
Microsoft sees the same shift, with a caveat. Its Digital Defense Report, released Oct. 1, found attackers using AI across the intrusion lifecycle, but said the way in hasn’t changed. “People, identities, exposed systems, and trusted access continue to feature prominently,” wrote deputy CISO Terrell Cox.
South Korean President Lee Jae-myung said Tuesday that “signs have emerged” AI agents were used in at least some of the attacks. “It’s now become possible to use AI to hack with ease even without specialized skills,” according to a report by the New York Times.
Ten Releases in a Month
ARTEX is under active development, and its developers ship fast. The GitHub repo, which has about 1,300 stars and more than 200 forks, pushed ten releases between Aug. 25 and Sept. 24. On Sept. 9, the developers added a proxy feature that, according to the release notes, keeps the operator’s source IP from leaking.
Four days later, they added DeepSeek as a web-search source. On Sept. 19 came a default blocklist that keeps the agent off government and university sites. Bank domains aren’t on the default list. The same release added a disclaimer users must accept before logging in. The README says the tool is for authorized testing and research only.
None of that stops anyone. Those guardrails are defaults, not locks. ARTEX is self-hosted, its blocklist can be edited or switched off, and its disclaimer is a checkbox. There’s no vendor to revoke access. The model behind the agent is the last possible chokepoint, and it leaks too.
Nahman Khayet, co-founder and CEO of Alt Security, which sells AI-driven offensive security testing, said ARTEX’s restrictions are only as strong as code anyone can edit. Because the tool is open source, “a threat actor could relatively easily re-construct the code to remove those restrictions,” he said.
Model providers can’t fully close that gap, Khayet said. Guardrails on commercial models are imperfect but help. Attackers can self-host open-weight models, though, and then the model’s developer sees none of the inputs or outputs. “Given that open-weight models are very close in offensive capabilities and can already do a lot of damage at a fraction of the cost, frontier model guardrails are not enough,” he said.
What Was Taken
Yegaram Savings Bank took the biggest hit, with roughly 40,000 people exposed, followed by Shinhan at 25,729, according to a tally by Law TV News. The rest were small: 146 loan brokers at Hyundai Capital, 119 people at KB Kookmin, 89 at Hana Bank and 11 contract workers at BNK Busan Bank. Welcome Savings Bank lost up to 2,200 records on corporate clients. Woori Bank and NH NongHyup Bank were hit but reported no losses.
What was taken matters more than how much. Shinhan’s stolen data included annual income and calculated loan limits, which legal analysts quoted by Law TV News warn is prime material for targeted refinancing scams. No firm has reported losing account passwords, digital certificates or one-time-password credentials.
Troubling Trend
By Korean standards, the tally is modest. A single hack at Lotte Card last year exposed nearly 3 million customers, according to Newsis. The pattern is the familiar. In 2024, a financially motivated group that Mandiant tracks as UNC5537 used stolen passwords to pull data from the Snowflake cloud accounts of roughly 165 organizations. The accounts lacked multifactor authentication, some with credentials unchanged for four years, and Mandiant said the campaign was “not the result of any particularly novel or sophisticated” technique.
Korea’s breaches follow the same script of weak authentication on internet-facing systems, hit across many organizations at once. The new variable is the tool investigators found, an AI agent built to do the hunting.
The advantage is less raw speed than reach, Khayet said. A human tester has to ration time. An autonomous system can keep enumerating apps and APIs, chase several attack paths at once and use each result to decide what to try next. In Alt’s own testing, he said, agents compress a four-week engagement by an expert team into about five days, and reconnaissance that takes days by hand takes minutes. Deep exploitation still costs more, “but an attacker only has to get it right once,” Khayet said. By Alt’s estimate, a single critical attack chain can turn up within hours on open-weight models, for under $10,000.
That shifts the question defenders ask, he said, from “how many skilled testers can I put on this problem?” to “how much testing can I continuously apply across my attack surface?”
ARTEX isn’t the first pen-testing agent to cross over. In August 2025, Check Point found criminals discussing HexStrike-AI, an open-source red-team framework, to exploit Citrix flaws within hours of disclosure. Weeks later, Straiker flagged Villager, a DeepSeek-powered framework from China’s Cyberspike, after roughly 10,000 downloads. Last month, Google reported a crew using a multi-agent framework to harvest thousands of credentials in under six hours, though it has yet to see fully autonomous attacks in the wild.
What Happens Next
Korean police opened a criminal case Tuesday, assigning a 28-member cyber-terror team that is working with foreign agencies. No suspect has been named. Regulators have pushed the attacker IPs to about 500 financial institutions, and they have ordered banks to inventory every internet-facing system and close any path to internal data that skips authentication.
That order is the takeaway for banks everywhere else. Tools like ARTEX are free, fast and improving by the week, and they go looking for exactly what the Korean lenders left open. Whatever role ARTEX played in Seoul, the openings were already there.
Old Bugs, New Speed
Take AI out of the equation and the breaches are familiar. Shinhan’s attacker bypassed authentication on a loan-broker portal and cycled query values to pull record after record. This is a classic authorization flaw. KB Kookmin’s suspected brute-force attack is an identity failure. Experts quoted by Yonhap said Shinhan likely wasn’t singled out at all, just swept up in automated probing.
“Autonomous AI does not need a novel exploit to be dangerous,” Khayet said. Its edge is persistence, he said: searching again and again for the forgotten endpoint, the weak login or the unpatched app that leads inside.
Likewise, the defenses are known. Continuously test everything exposed to the internet. Enforce authorization on every API call. Put phishing-resistant MFA on back-office portals. Flag machine cadence, like uniform timing and IPs that rotate fast.
Khayet cautioned that there may be no definitive signature of an AI agent. Instead, he said, defenders should watch for unusually persistent reconnaissance, quick retries after failed attempts, activity across many endpoints at once, and tactics that shift quickly based on how the target responds.
One defense targets the AI itself. Researchers have shown that text hidden in a website’s responses can hijack an AI pen-testing agent that reads it, though the technique remains a research result rather than an off-the-shelf control.
Market Speed, Tackle Old Bugs
Vendors are selling agents to fight agents. CrowdStrike says it’s already seeing AI agents hit multiple systems at once, and Palo Alto Networks just launched an always-on service that points AI at customers’ own systems first.
Khayet’s advice for U.S. banks this week tracks Seoul’s order. Start with internet-facing applications and APIs, especially assets that have drifted outside normal security ownership or testing. Know exactly what is exposed, confirm that authentication and authorization work as intended, and find the legacy or forgotten services that could provide a way in.
Whatever role ARTEX played in Seoul, the openings were already there.
[This article was update on 10/7 at 2:30pm ET with insights from Nahman Khayet, Co-Founder & CEO, Alt Security.]