
The whole AI trail in the Korean bank breaches is one HTML string
South Korean regulators are examining breaches at several financial firms, with Shinhan Bank reporting 25,000 customers affected and KB Kookmin reporting credit card data for 119 clients. Hana Bank was hit through a compromised sales-support system. Confirmed records come to at least 25,119.
“The bank and financial authorities have not confirmed its use in the Shinhan breach, and the Chinese-language string doesn't link the attacks to any particular threat actor”
— BleepingComputer, Об уликах по ARTEX
What the AI evidence consists of
A server used in the attacks returned an HTML page whose title contained a Chinese-language string associated with ARTEX AI. That is the link between these breaches and artificial intelligence.
ARTEX is an open-source penetration-testing system in which an AI agent automates information gathering, vulnerability discovery, attack-path planning, security-tool execution and vulnerability verification. A tool that fits the job was present somewhere in the chain. Nobody has shown it did the work, and authorities have published nothing about the perpetrators.
The totals in circulation disagree
Several outlets put the campaign at seven firms and 65,000 to 66,000 victims. BleepingComputer's confirmed figure is 25,119 across the named institutions. The gap comes from three different counts being mixed: customers affected, records leaked and firms touched.
One figure travelled further than it should have. KB Kookmin's exposure is 119 credit card clients. It has been reported in places as 119,000, which is a factor of a thousand.
The doors they came through
The Korean bank breach matters outside Korea for a narrow reason. Exchanges and custodians run the same category of system: partner portals, staff apps, back-office tools that sit outside the hardened customer path and get less attention per line of code. A toolchain that finds those automatically does not care which industry owns them.
None of the named entries was internet banking. The attackers used a loan-agent inquiry service, an employee mobile app and a sales-support system, which are the systems a bank builds for partners and staff rather than customers.
We counted a fleet of 14 parallel agents running against a mapping API on 7 October, and nobody could attribute that either. On 5 October Google froze its open-source bug bounty under automated submissions. In each case the tool was identifiable and the operator was not, which is the part regulators will have to solve before anyone can assign blame.
Informational material, not investment advice. The investigation is open, authorities have published nothing about the perpetrators, and the counts below come from the sources named beside them.

Comments (0)
No comments yet — be the first!
The market talks all day. We write when it says something
Short, and it tells you why it came
Related news
Most readTop 7
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
351AI





