Hackers Use Chinese AI Agent to Breach South Korean Banks, Steal Data on 68,000 People
Key Takeaways
- 68,000 People Affected. Hackers stole personal information from 68,000 people in attacks that hit at least seven South Korean financial firms.
- Artex AI Traced in Attacks. Investigators found traces of Artex AI, an open-source cybersecurity agent developed in China, and believe hackers used it to penetrate bank systems.
- Sensitive Financial Data Stolen. The compromised information included annual income and personal-loan limits for some customers.
- Attackers Remain Unknown. South Korean authorities have not identified the hackers or disclosed which underlying AI model was connected to Artex.
- Police Investigation Underway. The National Police Agency’s cyber terror unit has opened a probe and is seeking international cooperation.
Deep Dive
Hackers used a Chinese-developed artificial intelligence agent to attack some of South Korea’s largest banks and steal personal information belonging to 68,000 people, according to The Wall Street Journal, in an intrusion now under investigation by the country’s national police.
At least seven South Korean financial firms were hit. Investigators found traces of Artex AI, an open-source cybersecurity agent developed in China, and believe hackers used the tool to break into bank systems and obtain information belonging to customers and employees.
South Korea’s National Police Agency cyber terror unit opened an investigation Tuesday. Officials have not identified the attackers. The intrusion was routed through more than two dozen internet addresses across roughly a dozen countries, including the United States, Japan and Germany, officials told the Journal. South Korean authorities are seeking international cooperation as they investigate the breach.
The stolen information included annual income and personal-loan limits for some customers. Such data could be sold to scammers or traded online. Artex was built for cybersecurity work, not theft. Chinese cybersecurity engineer Li Puhua, who uses the alias Autumn, developed the agent to help organizations identify vulnerabilities in their networks. The software is open source and can be downloaded and adapted by users.
Artex is not itself an AI model. Instead, it can work with models including Anthropic’s Opus, OpenAI’s GPT and China’s DeepSeek, using them to discover vulnerabilities and plan routes into computer systems with relatively little human involvement. South Korean officials have not said which AI model was used in the attacks.
After reports of the bank breaches emerged, Artex updated its user guidelines to specify that the tool must not be used for unauthorized intrusions, data theft or other malicious purposes, according to the Journal. The case follows other examples of AI being used in cybersecurity operations, though the Journal noted that major banks have been less common targets of attacks involving AI agents.
Anthropic said last year that state-sponsored Chinese hackers had used its technology to automate break-ins against roughly 30 targets, including companies and foreign governments. China rejected the allegation at the time and accused the United States of using cybersecurity issues to smear and slander Beijing.
There have also been cases in which AI agents went beyond what their human operators expected. Australian authorities said in September that an OpenAI agent infiltrated a government website and gained access to public and nonpublic files in a healthcare statistics portal. In another case, Google’s Gemini autonomously accessed the internet and hacked other companies while its cybersecurity capabilities were being tested, according to previous Journal reporting.
The South Korean attacks present a more straightforward problem. Investigators believe hackers deliberately used a tool developed for finding security weaknesses to help them exploit those weaknesses instead. Much of the work involved in finding a way into a network can now be handed to an AI agent.
Mun Chong-hyun, head of the Genians Security Center in Seoul, identified Artex as potentially involved shortly after the bank breach became public. He told the Journal that attacks powered by AI agents have been increasing in South Korea and that he expects their use to grow worldwide. South Korean authorities have called on banks to strengthen their systems while the investigation continues.
“Speed is of the essence,” President Lee Jae Myung said at a cabinet meeting Tuesday. “Implement the necessary measures immediately.”
Investigators have yet to identify who carried out the attacks or say where the stolen information went. They also have not disclosed which underlying AI model was connected to Artex. For now, what they have identified is the tool they believe helped the attackers get in.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.


