Skip to content

October 6, 2026 / Issue 51 / 4 min read

AI-assisted attackers skipped seven Korean banks' front doors and walked in through the employee apps

The daily briefing video for this issue, 4:25.
Subscribe on YouTube for a daily briefing video(opens in a new tab)

Since October 1, seven South Korean financial firms have reported breaches by attackers, including Shinhan Bank, KB Kookmin Bank and Hana Bank, exposing data on more than 67,000 customers, the Korea Times reported(opens in a new tab). Investigators found traces of ARTEX AI, a Chinese-language open-source tool that uses a large language model to run a penetration test largely on its own, on a server used in the attacks. President Lee Jae Myung said AI appears to have been used. The attackers did not hit core banking. They came in through employee work apps, contractor networks and a loan-agent portal.

That detail belongs in your next budget meeting. The three largest banks spent about 124 billion won ($92 million) on information security in 2025, per the same report(opens in a new tab), and the money protected what it was pointed at. Shinhan's 25,729 exposed records came from a loan-agent inquiry service, Herald Business found(opens in a new tab). KB Kookmin's 119 came from an employee mobile work system. Every large enterprise runs hundreds of systems like these: low traffic, owned by a business unit, rarely reviewed. A human red team never had time to probe them all. A tool that plans and runs the probing does. Investigators stress a human operated it. That is the point: one operator with this kind of tool can cover the attack surface of many institutions at once.

The second lesson is about loosening controls to let AI in. South Korea's Financial Services Commission had been relaxing its network separation rule, which keeps bank systems off the internet, so banks could run AI security tools. Shinhan and Hana were in the first pilot. The regulator has now postponed picking firms for the second round, which was due on October 7, BigGo Finance reported(opens in a new tab), while saying the policy direction stands. Nothing public ties the breaches to the exemptions. The pause happened anyway. Expect your board to ask the same question after any incident: what did we open for AI, and who was watching it?

What to do this quarter. Inventory every system reachable from outside your network, including employee, contractor and partner portals, and rank them by authentication strength, not business importance. Ask the CISO how long the last intrusion on a low-tier system went undetected. And if you are relaxing a control to deploy AI, write the rollback condition into the approval now, before a regulator writes it for you.

Action items

AI tooling made the long tail of employee and contractor systems cheap to attack. Treat those systems as the front door now.

For the CAIO

Any control you relax to deploy AI needs a named owner and a written rollback condition.

For General Counsel

A regulator paused an AI-friendly exemption within days of a breach. Plan for that response in your own sector.

For the CISO

Rank every externally reachable system by authentication strength, and measure detection time on the low-tier ones.

Researched and drafted by an automated workflow, then reviewed and edited by a human editor before publication. Every source is linked. See how we use AI here.

Also worth knowing