AI-based tools were used in recent hacking attacks targeting South Korea’s financial sector, putting the country in the direct line of AI-driven hacking. Major financial companies were among the targets, drawing attention, but security experts believe AI hacking has likely already been attempted widely.
Security experts said on Monday that the latest attacks are notable because they used AI attack tools and exploited system gaps without particularly advanced techniques.
This follows confirmed customer information leaks at Shinhan, KB Kookmin and Hana Bank. At Yegaram Savings Bank, information on about 40,000 customers was leaked, and at Hyundai Capital, personal information on 146 mortgage loan brokers was leaked.
It was not a case of OpenAI AI agents breaking out of control during testing and abruptly hacking Hugging Face, an open-source AI model sharing platform. It was a case in which humans used AI to carry out a large-scale attack.
Not all, but many of the financial companies hit in the latest attacks are believed to have been hacked by the same attacker or group. An analysis of IP data suggests the attacker used ARTEX, an AI-based penetration testing tool, to break in.
ARTEX was developed in China. It is an open-source tool designed to automate penetration testing by using large language models and a multi-agent structure. It was designed to link and use various AI models such as Anthropic Claude, OpenAI GPT and DeepSeek.
Once the attacker assigns a mission through ARTEX, it operates autonomously. Although it is a tool developed in China, it is difficult to conclude the attacks were carried out by Chinese attackers because anyone can download and use it.
In the financial-sector attacks, relatively less monitored areas such as external web pages and servers used for work convenience by loan brokers or employees were used as entry points.
The attacker is said to have entered systems by bypassing authentication. The specific path used to bypass authentication is likely to become clear only after investigation results are released.
For now, a leading possibility is that the attacker entered systems through a credential stuffing brute-force attack. Credential stuffing is an automated cyberattack method in which an attacker uses leaked IDs and passwords to attempt logins across other websites or apps and hijack accounts.
Financial firms typically operate a process that blocks access after several incorrect password attempts.
But because the attacked systems were used by insiders or related parties, such safeguards may not have been in place. That raises the possibility that the attacker exploited vulnerabilities in an application programming interface or a login system.
Industry officials said that in the past it took several tens of days to several months from the discovery of a vulnerability to an actual attack, but now AI finds vulnerabilities and generates attack code on its own. The time required has shrunk to tens of minutes or a few hours. It is no longer difficult for a single attacker to quickly carry out a large-scale attack.
The latest hacking aimed at the financial sector was based on widely known conventional techniques rather than advanced attacks. Using AI tools and conventional methods, the attacker was able to find the most vulnerable points and secure entry routes. It means attacks can be threatening enough simply by repeating conventional techniques much faster.
A security industry official said, "If you cannot properly block conventional attacks, you will inevitably be breached. In these cases, they targeted relatively lax back doors or side doors rather than the well-defended front door. AI is good at finding the weakest point."
As AI-driven hacking incidents continue to emerge at home and abroad, debate is also intensifying over how to respond to new security threats.
Moves are also taking shape for alliances among companies, including semiconductor and platform firms, beyond the security sector.
Kim You-won (김유원), CEO of Naver Cloud, stressed at Cyber Summit Korea (CSK) 2026 in September at COEX in Seoul, "AI has fundamentally changed the nature of security threats. The era of responding to AI attacks at human speed is coming to an end." He added, "Security threats from AI can no longer be blocked by a single organisation. We must cooperate at a global level."
A Microsoft report in 2025 said security work has exceeded what humans can handle as AI-powered attacks ramp up. Some 41 percent of security alerts are being left unattended without investigation. As a result, a view is spreading that stopping AI attacks with AI is, for now, the most realistic approach.
Lee Eok-won (이억원), chairman of the Financial Services Commission, also said, "As new types of frequent cyberattacks could continue in the future, we must also speed up establishing a security system in which 'AI attacks are defended by AI'."
Jang Kwang-woon (장광운), security strategy adviser at Microsoft Korea, said, "Hiring 10 to 20 percent more security staff cannot solve these problems, and it is not enough just to introduce AI agents." He added, "Introducing AI in security is not the goal itself. The real goal is to stop attacks that come in at AI speed. There are limits to achieving that goal by splitting up work and attaching agents. The solution is to change the unit of work itself. Instead of processing tasks one by one, people should be responsible for achieving goals, and task execution should be left to agents."