Loading prices...
All news
Broken padlock with a single glowing fingerprint on its otherwise blank face

The whole AI trail in the Korean bank breaches is one HTML string

15:45 · 08.10.2026
Source: BeInCrypto
1

South Korean regulators are examining breaches at several financial firms, with Shinhan Bank reporting 25,000 customers affected and KB Kookmin reporting credit card data for 119 clients. Hana Bank was hit through a compromised sales-support system. Confirmed records come to at least 25,119.

“The bank and financial authorities have not confirmed its use in the Shinhan breach, and the Chinese-language string doesn't link the attacks to any particular threat actor”

— BleepingComputer, Об уликах по ARTEX

What the AI evidence consists of

A server used in the attacks returned an HTML page whose title contained a Chinese-language string associated with ARTEX AI. That is the link between these breaches and artificial intelligence.

ARTEX is an open-source penetration-testing system in which an AI agent automates information gathering, vulnerability discovery, attack-path planning, security-tool execution and vulnerability verification. A tool that fits the job was present somewhere in the chain. Nobody has shown it did the work, and authorities have published nothing about the perpetrators.

The totals in circulation disagree

Several outlets put the campaign at seven firms and 65,000 to 66,000 victims. BleepingComputer's confirmed figure is 25,119 across the named institutions. The gap comes from three different counts being mixed: customers affected, records leaked and firms touched.

One figure travelled further than it should have. KB Kookmin's exposure is 119 credit card clients. It has been reported in places as 119,000, which is a factor of a thousand.

The doors they came through

The Korean bank breach matters outside Korea for a narrow reason. Exchanges and custodians run the same category of system: partner portals, staff apps, back-office tools that sit outside the hardened customer path and get less attention per line of code. A toolchain that finds those automatically does not care which industry owns them.

None of the named entries was internet banking. The attackers used a loan-agent inquiry service, an employee mobile app and a sales-support system, which are the systems a bank builds for partners and staff rather than customers.

We counted a fleet of 14 parallel agents running against a mapping API on 7 October, and nobody could attribute that either. On 5 October Google froze its open-source bug bounty under automated submissions. In each case the tool was identifiable and the operator was not, which is the part regulators will have to solve before anyone can assign blame.

Informational material, not investment advice. The investigation is open, authorities have published nothing about the perpetrators, and the counts below come from the sources named beside them.

Published: 15:45 · 08.10.2026
Maks

Author

Maks

Trading man

I've been interested in the cryptocurrency market for a long time, am a trader, and write articles and news about my experience and crypto in simple terms.

Comments (0)

No comments yet — be the first!

The market talks all day. We write when it says something

Short, and it tells you why it came