Same attacker IP found at seven South Korean financial firms in suspected AI hacks
Version 3: Later reporting added that the suspected Chinese-language AI penetration-testing tool trace was found at all four major banks and that the attacks reached mutual finance, while officials said they could not rule out a single attacker; the inspection deadlines and the alert to about 500 financial companies are now reported by more than one outlet.
In short
Financial authorities said the same attacker IP appeared in intrusion cases at seven South Korean companies — Shinhan, KB Kookmin, Hana, BNK Busan Bank, Yegaram and Welcome savings banks and Hyundai Capital — with AI tools suspected in large-scale automated attacks, according to multiple outlets. Authorities classified the incidents into three vulnerability types and sent attack IP addresses and advisories to about 500 financial companies, setting emergency inspection deadlines of Oct 6 for banks and card companies and Oct 8 for securities, insurers, savings banks and electronic financial businesses. Yonhap reported 25,727 pieces of personal information leaked from Shinhan Bank in an attack lasting about 30 hours, while Newsis reported about 25,000 Shinhan customers were affected alongside smaller numbers at KB Kookmin and Hana.
Read the full story 3 min read
Financial authorities said the same attacker IP appeared in intrusion cases at seven companies — Shinhan, KB Kookmin, Hana, BNK Busan Bank, Yegaram and Welcome savings banks and Hyundai Capital — with the attacker changing IPs to keep attacking, according to Asia Economy, Seoul Economic Daily and Newsis. Those outlets, along with Yonhap and CBS NoCut News, reported AI tools were suspected in large-scale automated attacks on multiple financial companies. Chosun Ilbo said the attacks spread from major banks to savings banks, capital companies and mutual finance. [ 4 , 5 , 6 , 7 , 8 , 9 ]
Authorities classified the incidents into three types. Information-inquiry services had been built so loan application records or corporate representative information could be viewed without identity verification, and services missing authentication procedures were corrected or blocked. Employee support services such as the PB and RM systems lacked mobile device access controls or had unpatched web vulnerabilities, and companies were told to allow connections only from pre-registered devices. Homepages were exploited through already known vulnerabilities to install malware and steal log files containing customer data. [ 4 , 5 , 9 ]
Shinhan Bank data submitted to the National Assembly showed the attacker IP first entered on Sept 28 at 18:04 and the attack lasted until Sept 30 at 00:15, about 30 hours, with 25,727 pieces of personal information leaked, Yonhap reported. Seoul Economic Daily and CBS said the data came from auxiliary systems for employees and loan recruiters, with no impact on internet and mobile banking services and no financial damage so far. Newsis reported about 25,000 Shinhan customers' personal and credit information leaked, plus 119 KB Kookmin customers and 89 Hana Bank customers. [ 1 , 2 , 5 , 9 ]
The Financial Services Commission and the Financial Supervisory Service held an emergency inspection meeting at the Government Complex Seoul on Oct 4 with industry association heads and the CEOs of affected companies, Yonhap reported, the third emergency response meeting since the incidents began. Authorities sent attack IP addresses and advisories to about 500 financial companies, and the Financial Supervisory Service set inspection deadlines of Oct 6 for banks and card companies and Oct 8 for securities, insurers, savings banks and electronic financial businesses, Seoul Economic Daily and CBS reported. Lee Eok-won said the sector must treat the situation with the highest level of alertness and re-examine its security from the basics; Newsis reported he said AI-enabled hacking could not be ruled out, urged blocking external access in principle and building a pre-emptive “AI against AI” system, and warned of strict accountability for repeat breaches. [ 1 , 4 , 5 , 7 , 9 ]
Seoul Economic Daily and Newsis reported the string “ARTEX 自主渗透测试控制台” was found in a web server's HTML title, and Newsis said the trace appeared at all four of KB Kookmin, Shinhan, Hana and BNK Busan banks. CBS reported that Moon Jong-hyun of the Genians Security Center said on LinkedIn he confirmed a Chinese-language phrase for an “ARTEX-AI autonomous penetration testing console”, describing ARTEX as a Chinese-language open-source penetration testing tool based on a large language model, but that its use had not been officially confirmed. [ 5 , 7 , 9 ]
Yonhap reported Saemaul Geumgo blocked access attempts from the same IP used against Shinhan Bank and that similar attempts at NongHyup mutual finance were repelled. It reported no traces of the same attack had been confirmed at securities, insurance or card firms or at the policy banks IBK Industrial Bank and Korea Eximbank, while officials said further damage could not be ruled out and more companies may have been targeted than is publicly known. [ 1 , 3 ]
Why it matters
The attacks reached commercial banks, savings banks, a capital company and mutual finance, prompting authorities to alert about 500 financial companies and order emergency inspections on a two-tier deadline of Oct 6 and Oct 8. Financial Services Commission Chairman Lee Eok-won said the incidents should be used to raise the sector's information-security system, and officials said further damage could not be ruled out, pointing to wider notification, inspection and compensation obligations.
Key facts
- Authorities said the same attacker IP was found in intrusion cases at seven companies — Shinhan, KB Kookmin, Hana, BNK Busan Bank, Yegaram and Welcome savings banks and Hyundai Capital — and that the attacker changed IPs to keep attacking. [ 4 , 5 , 6 , 7 , 9 ]
- AI tools are suspected of having been used for large-scale automated attacks on multiple financial companies. [ 3 , 4 , 5 , 7 , 9 ]
- Shinhan Bank data submitted to the National Assembly showed the attacker IP first entered on Sept 28 at 18:04, the attack lasted until Sept 30 at 00:15 — about 30 hours — and 25,727 pieces of personal information leaked. [ 1 ]
- Attackers used IP addresses from South Korea, the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand and Britain, according to Shinhan Bank's data. [ 1 , 4 , 5 , 7 , 9 ]
- Authorities classified the incidents into three types and distributed attack IP addresses and security advisories to about 500 financial companies. [ 4 , 5 , 9 ]
- The Financial Supervisory Service set emergency inspection deadlines of Oct 6 for banks and card companies and Oct 8 for securities, insurance, savings banks and electronic financial businesses. [ 5 , 9 ]
- FSC Chairman Lee Eok-won said the whole financial sector must treat the situation with the highest level of alertness and re-examine its information-security systems from the basics. [ 4 , 5 , 7 ]
- Newsis reported about 25,000 Shinhan customers' personal and credit information leaked, that 119 KB Kookmin customers' personal credit information leaked and that 89 Hana Bank customers' information was exposed when an external group accessed the bank's sales support system (ODS). [ 2 ]
Confirmed by several sources
- The same attacker IP was found in intrusion cases at multiple companies, and the attacker changed IP addresses during the campaign, according to Asia Economy, Seoul Economic Daily, Newsis and Chosun Ilbo. [ 4 , 5 , 6 , 7 , 9 ]
- Seven named companies were affected: Shinhan, KB Kookmin, Hana, BNK Busan Bank, Yegaram and Welcome savings banks and Hyundai Capital. [ 4 , 5 , 6 , 9 ]
- AI tools are suspected of having been used for mass automated attacks on multiple financial companies. [ 3 , 4 , 5 , 7 , 9 ]
- Attackers used IP addresses from eight countries, including South Korea, the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand and Britain, per Shinhan Bank data submitted to the National Assembly. [ 1 , 4 , 5 , 7 , 9 ]
- Authorities classified the incidents into three types, distributed attack IP addresses and advisories to about 500 financial companies and ordered companies to fix or block vulnerable services. [ 4 , 5 , 9 ]
- The Financial Supervisory Service set emergency inspection deadlines of Oct 6 for banks and card companies and Oct 8 for securities, insurance, savings banks and electronic financial businesses. [ 5 , 9 ]
- Financial Services Commission Chairman Lee Eok-won called for the financial sector to treat the situation seriously and re-examine its information-security systems. [ 4 , 5 , 7 ]
- Financial authorities convened an emergency inspection meeting with financial industry association heads and the CEOs of affected companies at the Government Complex Seoul on Oct 4. [ 1 , 4 , 5 , 7 ]
- Shinhan Bank's leaked data came from auxiliary systems for employees and loan recruiters, with no impact on internet and mobile banking services and no financial damage so far. [ 5 , 9 ]
Still unclear
- Whether all the attacks were carried out by one group. Seoul Economic Daily quoted Financial Security Institute head Park Sang-won saying banking-sector IPs matched but savings-bank-sector IPs differed while the methods were similar; Newsis said it was hard to conclude a single culprit, and Chosun Ilbo reported authorities could not rule out the same actor.
- Who was behind the attacks and whether AI autonomous penetration-testing tools were actually used. Seoul Economic Daily and Newsis reported the string “ARTEX 自主渗透测试控制台” was found in a web server's HTML title and described it as a trace of Chinese-language AI autonomous penetration testing, but CBS NoCut News said authorities and Shinhan Bank had not officially confirmed that the tool was used.
- The number of Shinhan Bank customers affected. Yonhap reported 25,727 pieces of personal information leaked, citing data submitted to the National Assembly, while Newsis reported about 25,000 customers — different figures and units.
- The scale and cause of the corporate customer data leak at Welcome Savings Bank. Yonhap reported that the company is still investigating the exact scale and how the information leaked.
- The customer figures reported for KB Kookmin and Hana banks. The figures of 119 KB Kookmin customers and 89 Hana Bank customers were reported by a single outlet, Newsis, in a photo caption.
- Whether other financial companies were attacked without knowing it, and whether further damage is possible. Yonhap quoted a senior financial authority official saying further damage could not be ruled out and a financial-sector official saying more companies may have received attack attempts than is publicly known; Yonhap also said no traces had been confirmed at securities, insurance or card firms or at policy banks IBK Industrial Bank and Korea Eximbank.
What local media are saying
Timeline, local time
- Sept 28: an attacker IP first entered Shinhan Bank's system, according to data the bank submitted to the National Assembly. [ 1 ]
- Sept 29: Shinhan Bank detected the attack, blocked the IP and suspended some services, but attacks on six services including mobile loan application result inquiries continued. [ 1 ]
- Sept 30: the Shinhan Bank attack ended after about 30 hours; Yegaram Savings Bank was hit the same day and disclosed the breach on Oct 2. [ 1 ]
- Oct 4: Yonhap reported the spread of the attacks to savings banks, capital firms and mutual finance, the disclosed figures and an emergency meeting scheduled that afternoon, at which FSC Chairman Lee Eok-won and FSS Governor Lee Chan-jin were to convene financial association heads and the CEOs of affected companies. [ 1 ]
- Oct 4: Yonhap reported that the same attacker IP was found at several locations and that AI tools were suspected. [ 3 ]
- Oct 4: Asia Economy reported the shared attacker IP at seven companies, the three-type classification of the incidents and remarks by Lee Eok-won at the emergency meeting. [ 4 ]
- Oct 4: Seoul Economic Daily reported the seven companies, Park Sang-won's comments on differing IPs by sector, the advisory to about 500 financial companies and the inspection deadlines. [ 5 ]
- Oct 4: Newsis reported the ARTEX trace at four banks and Lee Eok-won's warnings on AI hacking, blocking external access and accountability for repeat breaches. [ 7 ]
- Oct 5: Chosun Ilbo reported the attacks spread to savings banks, capital firms and mutual finance and that authorities could not rule out the same actor. [ 8 ]
- Oct 5: CBS NoCut News reported a security researcher's account of the ARTEX Chinese-language tool and said its use had not been officially confirmed. [ 9 ]