ADVERTISEMENT

Events

IAMTN Annual Summit 2026
14 Oct 26
London
Money20/20 USA 2026
18 Oct 26
Las Vegas

South Korea Confirms AI-Driven Cyberattacks on 7 Financial Institutions

South Korean President Lee Jae Myung has confirmed a coordinated cyberattack targeting the country’s financial sector. He has ordered government agencies to send personnel and resources immediately to contain the damage. The breach affected seven financial institutions, including Shinhan Bank, KB Kookmin Bank, Hana Bank, Woori Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank, and Hyundai Capital, raising concerns over the use of AI-driven tools in attacks against critical financial infrastructure.

Investigators have identified 28 attack IP addresses spanning 12 countries, including the US, Japan, the UK, and Vietnam. South Korea’s National Office of Investigation said the addresses were used to continuously rotate attacks against different targets. Officials said it is highly likely that the open-source Chinese ARTEX AI tool was involved in the operation, although the Financial Security Institute stressed that the use of Chinese AI software and overseas IP addresses does not establish that the attackers were Chinese nationals.

South Korea has since placed its cybersecurity agencies on a 24-hour emergency response footing and ordered cloud service providers to block network activity associated with the suspected overseas IP addresses.

The attacks also triggered a sharp rally in South Korean cybersecurity stocks. Sands Lab and RaonSecure both gained nearly 30%, while AhnLab and Ginieans rose 15.58% and 20.83%, respectively, as investors bet on stronger demand for cybersecurity solutions.

Crypto users warn AI is lowering the barrier for cyberattacks

Crypto and Web3 users have focused on the possibility that AI agents could lower the technical barrier for carrying out sophisticated cyberattacks. Web3 enthusiast Coppercode described the reported ARTEX attack as a potential turning point, saying the AI agent carried out reconnaissance, credential stuffing and verification with little human input. He said autonomous AI could make sophisticated hacking easier for more people to carry out.

Others framed the incident as evidence that AI-driven cybercrime is moving from a theoretical threat to a practical security challenge. SkeletronJV highlighted reports that AI may have been involved in attacks against major South Korean banks, while SmindCrypto questioned whether financial institutions are prepared for attackers capable of writing and deploying malicious code rather than relying on traditional methods. Their comments show increasing concern that conventional cybersecurity defenses may struggle to keep pace with automated attack systems.

The discussion has also raised important questions about the resilience of traditional financial infrastructure and the emerging AI-versus-AI security race. John pointed to the possibility of regulators using AI to counter AI-enabled attacks while Astrinvestor questioned whether banks can remain trusted as AI capabilities evolve faster than existing cybersecurity practices. Ethereum co-founder Vitalik Buterin has similarly argued that AI will not make cybersecurity impossible to defend, suggesting that increasingly capable AI could ultimately give defenders an advantage over attackers.

What comes next?

The focus may now move beyond identifying ARTEX to understanding how widely AI-powered attack tools are being used. AhnLab’s Security Intelligence Centre found ARTEX activity linked to about 600 IP addresses worldwide, with some of the same servers also running another AI security tool called CyberStrikeAI.

However, AhnLab said the IP addresses cannot be linked to a single attacker because ARTEX is open source and can also be used by security researchers. This means investigators may increasingly have to track wider networks of AI-powered attack infrastructure rather than individual hackers or malware.

The attacks have also shown that banks may need to look beyond their core systems when improving security. Investigators found that attackers targeted third-party services, including loan-broker portals and employee support systems. 

At Shinhan Bank, about 25,000 customers were reportedly affected after attackers accessed a loan-related service with weak identity checks. The incident is putting more focus on stronger authentication, zero-trust security and AI-powered vulnerability checks that can continuously look for weak points.

 

Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads, and CoinMarketCap Community for seamless access to high-quality industry insights

Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.

ADVERTISEMENT
ADVERTISEMENT

Spotlight

ETH $2,612.33 -3.19% NU $469.04 +0.00% POLY $792.15 +0.00% APE $748.09 +0.00% FET $226.49 +0.00% ARPA $160.56 +0.00% GTC $2,668.91 +0.00% FORTH $4,194.39 +0.00% PLU $2,124.48 +0.00% MLN $10,448.26 +0.00% ETH $2,612.33 -3.19% NU $469.04 +0.00% POLY $792.15 +0.00% APE $748.09 +0.00% FET $226.49 +0.00% ARPA $160.56 +0.00% GTC $2,668.91 +0.00% FORTH $4,194.39 +0.00% PLU $2,124.48 +0.00% MLN $10,448.26 +0.00%
-
00:00
00:00
Update Required Flash plugin
-
00:00
00:00