What changed
2026-10-02 04:25 UTC → 2026-10-03 00:23 UTC ·
added
removed
Security experts identified The cyberattack against Shinhan Bank has been further linked to traces of a Chinese-language, AI-based autonomous penetration testing tool, known tool identified as ‘ARTEX AI’, on a web server suspected of being used in a cyberattack against Shinhan Bank. ‘ARTEX-自主渗透試控制台’ (AI Autonomous Penetration Test Console). The tool is tool, an open-source system based on Large Language Models designed to automate vulnerability scanning and attack path planning. While Models, was detected via Chinese strings in the specific use HTML title of this tool a suspected web server. While official confirmation of its use in the breach has not been officially confirmed, is pending, analysts suggest the attack may have utilized employed ‘credential stuffing’ to gain unauthorized access. Shinhan Bank confirmed that the breach resulted bypass identity verification procedures in Shinhan’s loan solicitor service. The scope of the security incidents has expanded, revealing a series of coordinated attacks targeting multiple South Korean financial institutions. Beyond Shinhan Bank’s leak of personal and credit information data for approximately 25,000 customers, including names, phone numbers, and resident registration numbers. In a related incident, additional breaches have been confirmed at KB Kookmin Bank reported a data leak affecting approximately 100 customers through unauthorized access (roughly 119 customers), Hana Bank (89 victims), and BNK Busan Bank (11 outsourced employees). Experts note that attackers appear to an be targeting secondary channels—such as loan recruitment services, employee mobile business support system. The systems, and sales support platforms—which may possess less stringent authentication protocols than core banking systems. In response, the Financial Supervisory Service Services Commission has convened emergency meetings and ordered comprehensive security audits of all externally exposed IT assets. The National Police Agency has also launched investigations an investigation into both banks to determine the scope of the leaks and the entry points used by attackers. incidents. Both Shinhan Bank’s CEO has issued an apology and KB Kookmin Bank have pledged to provide full compensation in the event of to customers if actual financial damage. damages are confirmed.