[EXPLAINER] How AI emerged as new threat in Korea's bank hacking crisis【解读】人工智能如何成为韩国银行黑客危机中的新威胁
Hackers once had to manually test security defenses, identify vulnerabilities and work out how to exploit them. Now, artificial intelligence (AI) c...

AI-powered autonomous penetration testing tools were reportedly used in a series of cyberattacks on major South Korean banks since last week. Shinhan Bank said about 25,000 customers were affected, while KB Kookmin Bank and Hana Bank reported 119 and 89 affected customers, respectively. Investigators found traces of the Chinese-language ARTEX tool, but the attacker remains unidentified. Experts warn that AI can accelerate attacks and urge banks to deploy automated AI defenses.
ARTEX can scan systems for vulnerabilities and develop potential attack paths while connecting to AI models from DeepSeek, OpenAI and Anthropic.
Shinhan Bank said exposed information included customers’ names, phone numbers, annual income and loan limits.
Woori Bank and NH NongHyup Bank detected signs of hacking attempts, but no data leaks were confirmed.
Experts said attackers targeted supporting networks with weaker security rather than banks’ core systems, limiting the initial damage.
Hwang Suk-jin warned that the breaches could have been an initial test for larger follow-up attacks using information obtained from the compromised systems.
Published Oct 7, 2026 4:03 pm KST
Updated Oct 7, 2026 5:43 pm KST
AI-powered hacking could take cyberattacks to unprecedented scale, experts warn
Hackers once had to manually test security defenses, identify vulnerabilities and work out how to exploit them. Now, artificial intelligence (AI) can do much of that work, requiring little human input.
That possibility is at the center of Korea's latest security crisis in the financial sector, as investigators have found traces of an AI-powered autonomous penetration-testing tool in a series of recent cyberattacks on the country's major banks.
Since last week, Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank and BNK Busan Bank have all reported data breaches, while Woori Bank and NH NongHyup Bank have detected signs of hacking attempts, though no data leaks were confirmed.
Shinhan Bank reported that about 25,000 customers were affected, with personal information including names, phone numbers, annual income and loan limits exposed. KB Kookmin reported 119 affected customers, while Hana Bank said personal information belonging to 89 customers was exposed.
The hacking spree has drawn particular concern after investigators reportedly found traces of an AI-powered tool known as ARTEX.
The Chinese-language autonomous penetration-testing tool is designed to automate tasks that typically require human expertise, including scanning systems for vulnerabilities and developing potential attack paths.
The tool can connect to AI models developed by Chinese company DeepSeek as well as OpenAI and Anthropic, allowing multiple AI agents to analyze hacking targets and potential intrusion routes.
Experts warn that AI-powered hacking could mark the beginning of a broader shift in the cybersecurity landscape.
"It would be difficult for humans to carry out attacks this fast and on such a large scale across the financial sector in just a matter of days. It is highly likely that AI was used," said Lim Jong-in, a professor at Korea University's Graduate School of Information Security.
He likened the difference in speed between regular hackers and AI-powered attacks to that between a human running and a Ferrari, saying, "It would take weeks, if not months, for human hackers to plan and carry out such large-scale attacks."
However, the professor cautioned against assuming that China was behind the latest attacks simply because traces of a Chinese-language AI tool were found.
"The actor behind the attacks remains unknown," he said, noting that some Chinese AI models are released with relatively weak safeguards, allowing anyone around the world to download and modify them for malicious purposes.
In a nutshell, AI can make hacking faster and broader by automating parts of the attack process that once required significant human effort.
Traditional cyberattacks require hackers to identify targets, probe networks, find vulnerabilities and determine how to exploit them. AI agents can automate much of that process with little human input, allowing attackers to explore multiple attack paths more quickly.
ATMs from Korea's major banks are seen in Seoul, Sunday. Yonhap
But the damage from the latest bank breaches remains relatively limited.
That stands in contrast to some of Korea's biggest data breaches in recent years, including incidents affecting nearly 40 million Tving users in June and 33 million Coupang users last year.
Hwang Suk-jin, a professor at Dongguk University's Graduate School of International Affairs and Information Security, attributed the limited scale of the damage to the attackers' indirect route into the banks, which targeted supporting networks rather than their core systems.
"Banks have core networks and supporting networks. The supporting networks have relatively weaker security, and they were targeted in this attack. Rather than entering through the front door, the attackers came in through a window, using an indirect route to steal only some of the information," Hwang said.
However, the relatively limited scale of damage does not mean the threat is over. Hwang indicated that the recent attacks may have been an initial test to identify vulnerabilities, raising the possibility of larger follow-up attacks using the information obtained in the breaches.
As the threat from AI-powered hacking is expected to grow, experts say financial firms will need to overhaul their security systems and more actively use AI technologies in their defenses.
"As attackers use AI to rapidly find vulnerabilities, defenders also need to use AI to detect weaknesses first and strengthen systems capable of responding automatically around the clock," Lim said.
Multiple IPs used to hide origin of recent cyberattacks against financial firms
AI-powered attacks on banks expose technological lag in Korea's financial cyber defenses
Shinhan, Kookmin, Hana data breaches fuel concerns over AI-powered cyberattacks in financial sector
据报道,自上周以来,韩国多家大型银行遭受了一系列网络攻击,攻击者使用了人工智能驱动的自主渗透测试工具。新韩银行表示约有2.5万名客户受到影响,而KB国民银行和韩亚银行分别报告有119名和89名客户受到影响。调查人员发现了中文版ARTEX工具的痕迹,但攻击者身份尚未确定。专家警告称,人工智能可能会加速攻击,并敦促各银行部署自动化人工智能防御系统。
ARTEX 可以扫描系统漏洞并开发潜在的攻击路径,同时还能连接到 DeepSeek、OpenAI 和 Anthropic 的 AI 模型。
新韩银行表示,泄露的信息包括客户姓名、电话号码、年收入和贷款限额。
友利银行和农协银行检测到黑客攻击迹象,但尚未证实发生数据泄露。
专家表示,攻击者瞄准的是安全性较弱的支持网络,而不是银行的核心系统,从而限制了最初的损失。
黄锡镇警告说,这些安全漏洞可能是对后续更大规模攻击的初步测试,攻击将利用从被入侵系统中获取的信息进行。
发布于2026年10月7日下午4:03(韩国标准时间)
更新于2026年10月7日下午5:43(韩国标准时间)
专家警告:人工智能驱动的黑客攻击可能将网络攻击推向前所未有的规模
过去,黑客必须手动测试安全防御措施,识别漏洞并研究如何利用这些漏洞。如今,人工智能 (AI) 可以完成大部分此类工作,几乎不需要人工干预。
这种可能性是韩国金融领域最新安全危机的核心,因为调查人员在最近针对该国主要银行的一系列网络攻击中发现了人工智能驱动的自主渗透测试工具的痕迹。
自上周以来,新韩银行、KB国民银行、韩亚银行、Yegaram储蓄银行和BNK釜山银行均报告了数据泄露事件,而友利银行和NH农协银行则检测到了黑客攻击的迹象,但尚未证实发生数据泄露。
新韩银行报告称,约有2.5万名客户受到影响,包括姓名、电话号码、年收入和贷款额度在内的个人信息被泄露。KB国民银行报告称有119名客户受到影响,而韩亚银行则表示有89名客户的个人信息被泄露。
据报道,调查人员在黑客攻击中发现了名为 ARTEX 的人工智能工具的痕迹,这引起了人们的特别关注。
这款中文版自主渗透测试工具旨在自动化执行通常需要人工专业知识的任务,包括扫描系统漏洞和开发潜在攻击路径。
该工具可以连接到中国公司 DeepSeek 以及 OpenAI 和 Anthropic 开发的 AI 模型,使多个 AI 代理能够分析黑客攻击目标和潜在的入侵路径。
专家警告称,人工智能驱动的黑客攻击可能标志着网络安全格局发生更广泛转变的开始。
“人类很难在短短几天内对金融领域发动如此迅速且大规模的攻击。极有可能使用了人工智能,”韩国大学信息安全研究生院教授林钟仁表示。
他将普通黑客和人工智能驱动的攻击之间的速度差异比作人类跑步和法拉利之间的速度差异,并表示:“人类黑客需要数周甚至数月的时间来计划和实施如此大规模的攻击。”
然而,这位教授告诫说,仅仅因为发现了中文人工智能工具的痕迹,就断定中国是最近这些攻击的幕后黑手,这是不可取的。
“幕后黑手仍然不明,”他说道,并指出一些中国人工智能模型发布的安全措施相对较弱,允许世界各地的人下载并修改它们用于恶意目的。
简而言之,人工智能可以通过自动化攻击过程中曾经需要大量人工投入的部分,使黑客攻击更快、范围更广。
传统网络攻击需要黑客识别目标、探测网络、发现漏洞并确定如何利用这些漏洞。人工智能代理可以自动完成大部分此类过程,几乎无需人工干预,从而使攻击者能够更快地探索多种攻击路径。
周日,首尔街头可见韩国各大银行的自动取款机。(韩联社)
但最近这起银行数据泄露事件造成的损失仍然相对有限。
这与近年来韩国发生的一些最大的数据泄露事件形成了鲜明对比,其中包括 6 月份影响近 4000 万 Tving 用户和去年影响 3300 万 Coupang 用户的事件。
东国大学国际事务与信息安全研究生院教授黄锡镇将损失规模有限的原因归结于攻击者采取了间接途径进入银行,攻击目标是支持网络而不是核心系统。
黄说:“银行有核心网络和辅助网络。辅助网络的安全防护相对较弱,因此成为此次攻击的目标。攻击者没有走正门,而是从窗口进入,采取间接方式,只窃取了部分信息。”
然而,损失规模相对有限并不意味着威胁已经解除。黄指出,最近的攻击可能只是对漏洞的初步测试,这意味着攻击者有可能利用从攻击中获取的信息发动更大规模的后续攻击。
随着人工智能驱动的黑客攻击威胁预计将会增长,专家表示,金融公司需要彻底改革其安全系统,并在防御中更积极地使用人工智能技术。
林表示:“攻击者利用人工智能快速发现漏洞,防御者也需要利用人工智能首先检测弱点,并加强能够全天候自动响应的系统。”
多个IP地址被用来隐藏近期针对金融公司的网络攻击的来源。
人工智能驱动的银行网络攻击暴露了韩国金融网络防御的技术滞后
新韩、国民、韩亚数据泄露事件加剧了人们对金融领域人工智能网络攻击的担忧