In short: In late September and early October 2026, South Korea's five largest commercial banks faced a wave of cyberattacks: Shinhan Bank confirmed a breach affecting roughly 25,000 customers, KB Kookmin Bank 119, Hana Bank 89, and BNK Busan Bank 11. Investigators found traces of ARTEX AI — an open-source, autonomous AI pentesting tool that searches for targets, finds vulnerabilities, launches attacks, and verifies results on its own — on the compromised servers. The breach is linked to credential stuffing against Shinhan Bank's loan-application platform, and the same attacker IP address has surfaced in incidents at at least seven financial firms.
What happened
Shinhan Bank was the first to disclose the breach: attackers bypassed identity checks in a service used by loan agents and accessed data on roughly 25,000 customers — names, phone numbers, annual income, credit limits, and national ID numbers. KB Kookmin Bank (119 customers), Hana Bank (89), and BNK Busan Bank (11) confirmed breaches shortly after; Woori Bank and NH Nonghyup Bank said they blocked intrusion attempts. According to The Korea Times, the same attacker IP address appears in incidents at seven financial firms, including savings banks and Hyundai Capital.
Where AI comes in
Investigators found traces of ARTEX AI on the breached servers — an autonomous, LLM-based penetration-testing tool distributed mainly through GitHub and aimed at Chinese-speaking users. Tools like this run the entire attack cycle on their own: finding a target, scanning for vulnerabilities, trying stolen credentials, and verifying whether access worked, with minimal human operator involvement. Whether ARTEX AI was the actual tool behind the Shinhan breach is still under investigation, but the possibility alone — an AI agent capable of autonomously carrying out a bank cyberattack — has already pushed South Korea's financial sector to overhaul its defenses. The underlying method at Shinhan was classic credential stuffing: testing previously stolen username-password pairs against a legitimate login form, something an AI tool can do far faster and more adaptively than a human operator.
What this means for ordinary bank customers
Credential stuffing only works where a person reuses the same password across multiple services — a password leaked from one site gets replayed against a bank's login form by a bot. That's largely why the per-bank numbers (25,000, 119, 89, 11) differ so much: banks with stronger anti-credential-stuffing defenses and more customers using unique passwords plus MFA saw far less damage. We've covered how to use online banking safely in more depth here: how to use online banking safely.
What you can do now
- Don't reuse your banking password anywhere else. Credential stuffing exists precisely because people repeat passwords; a password manager removes the problem — see our guide: how to choose a password manager.
- Turn on two-factor authentication for your banking app and for the email account tied to your financial services — it blocks logins even if a password is already compromised.
- Check whether your passwords have already leaked in prior breaches, and change any you've reused first.
- Encrypt your traffic on public networks. Credential stuffing happens on the bank's server side, so a VPN doesn't stop it — but LiMP VPN covers an adjacent risk: interception of your banking traffic on open Wi-Fi and visibility into which services you use.
Plans with a verified no-logs policy: LiMP VPN pricing. More breakdowns of breaches and attacks on the LiMP VPN blog.
Sources
- Rossiyskaya Gazeta (RU) — Is AI involved? What's known about the mass data breach at South Korean banks, October 2, 2026
- The Korea Times — Shinhan, KB Kookmin data breaches raise concerns over AI-powered cyberattacks, October 2, 2026
- Seoul Economic Daily — Same IP Used in Hacks on Multiple Korean Financial Firms, October 4, 2026
