NewsMacroSouth Korea suspends bank security deregulation after AI-assisted hacks hit seven financial firms

South Korea suspends bank security deregulation after AI-assisted hacks hit seven financial firms

Author: Cryptopolitan·

Key Takeaways

  • •The FSC halted the second round of its security deregulation program, which would have expanded eligibility to 75 companies with lower asset and headcount thresholds, one day before selections were due on October 7.
  • •Cyberattacks that began on September 30 at Shinhan Bank ultimately breached seven financial institutions and exposed roughly 68,000 records, with Yegaram Savings Bank reporting the largest single loss at about 40,000 customers.
  • •The Korea Financial Security Institute identified ARTEX AI, an open-source large-language-model penetration-testing tool distributed on GitHub, as the common thread, clarifying that the tool did not act autonomously but was used by a hacker.
  • •Breach detection was slow across affected firms, with Shinhan taking more than 15 hours, Hana Bank nearly 42 hours, and KB Kookmin Bank close to 68 hours to identify the intrusions.
  • •Regulators have ordered emergency self-inspections at roughly 500 firms with reports due by October 8, and believe direct financial theft is unlikely but warn that accurate stolen data will make voice-phishing scams harder to detect.
South Korea suspends bank security deregulation after AI-assisted hacks hit seven financial firms

South Korea's Financial Services Commission (FSC), the country's top financial regulator, has suspended the next phase of its bank security deregulation program, pulling the plug one day before a second round of participating banks was due to be selected. The decision follows a string of AI-assisted cyberattacks that breached seven financial firms and exposed tens of thousands of customer records.

Deregulation built on the promise of AI-driven defense

The program's premise was that loosening security rules would let banks deploy AI to strengthen their defenses. The recent attacks, however, reached even firms rated among the most secure, prompting the regulator to halt the rollout while it reassesses.

At the center of the policy is South Korea's network separation rule, which requires financial companies to keep their internal business systems physically walled off from the internet. The rule was introduced after a wave of cyberattacks in the late 2000s, covering public agencies from 2007 and banks from 2014. For years it held firm: during the 2017 WannaCry outbreak, Korean finance escaped largely unscathed because the malware could not reach isolated networks.

The arrival of generative AI changed the calculus. Regulators argued that the separation rule prevented banks from running the very AI tools they needed to detect threats, and the FSC began carving out exemptions. Vice Chairman Kwon Dae-young convened a roundtable in May on advanced-AI security risks, and the first round of relaxation covered 49 firms with at least 10 trillion won in assets and 1,000 employees, each granted a one-year exemption to test AI-driven defenses.

The second phase was set to expand eligibility to 75 companies, lowering the asset threshold to 2 trillion won and the headcount floor to 300, while increasing the number of selected firms from 10 to as many as 15. Selections had been scheduled for October 7 — the very date the suspension preempted.

The FSC now says it needs further review with the Financial Supervisory Service, its supervisory arm, while the breaches are contained. The regulator maintains that it still supports deregulation in principle, framing the halt as a pause rather than a policy reversal.

The breaches: seven firms, tens of thousands of records

The incidents began on September 30 at Shinhan Bank, where an outside party slipped past identity checks in a loan-agent service and extracted the personal data of roughly 25,000 customers — 25,727 records in total. After the FSC circulated the attacker's IP addresses, other firms reviewed their logs and discovered that their systems had also been breached.

KB Kookmin Bank had 119 records compromised, Hana Bank 89, and BNK Busan Bank 11 outsourced developers. The damage then spread to secondary lenders: Yegaram Savings Bank disclosed a breach affecting about 40,000 customers, the largest single figure so far; Welcome Savings Bank lost up to 2,200 corporate records; and Hyundai Capital exposed data on 146 of its mortgage loan agents. Taken together, the disclosed figures put the toll at roughly 68,000 records across the seven firms.

Detection was slow across the board. Shinhan reportedly took more than 15 hours to spot its breach, Hana nearly 42 hours, and KB Kookmin close to 68 hours.

ARTEX AI: an open-source penetration-testing tool

The Korea Financial Security Institute, the Financial Supervisory Service's financial security affiliate, identified the common thread in the hacks as ARTEX AI, an open-source, large-language-model penetration-testing system distributed on GitHub mainly within Chinese-speaking circles — a category of tooling in which large language models drive penetration-testing steps autonomously, as the “Autonomous Penetration Testing Console” in its own name suggests. Analysts reportedly first spotted an “ARTEX — Autonomous Penetration Testing Console” string on servers tied to the Shinhan attack. The tool also won an offensive-security contest run by Baidu's security response center this year.

An institute official clarified that the tool did not act on its own and was simply used by a hacker to extract data from internal employee and partner systems, which the official said had been “managed less rigorously” than services offered to the public. The institute added that two or three IP addresses overlapped at each bank, and blocking one simply pushed the intruder to another — with the activity still live.

Emergency response

FSC Chairman Lee Eog-weon urged industry representatives at an emergency meeting on October 4 to stay on “the highest alert.” The FSC, the Financial Supervisory Service, and the institute have ordered emergency self-inspections at roughly 500 firms, with banks and card companies due to report first and savings banks, insurers, and e-finance operators to follow by October 8 — a sector-wide self-assessment whose first reports are due barely a day after the shelved selection date.

The institute believes direct financial theft is unlikely, since the attackers did not seize control of customer accounts. It cautioned, however, that voice-phishing scams will be far harder to detect now that attackers are armed with accurate sensitive information such as loan and credit details.