South Korean President Lee Jae Myung has confirmed a coordinated cyberattack targeting the country’s financial sector. He has ordered government agencies to send personnel and resources immediately to contain the damage. The breach affected seven financial institutions, including Shinhan Bank, KB Kookmin Bank, Hana Bank, Woori Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank, and Hyundai Capital, raising concerns over the use of AI-driven tools in attacks against critical financial infrastructure.
Investigators have identified 28 attack IP addresses spanning 12 countries, including the US, Japan, the UK, and Vietnam. South Korea’s National Office of Investigation said the addresses were used to continuously rotate attacks against different targets. Officials said it is highly likely that the open-source Chinese ARTEX AI tool was involved in the operation, although the Financial Security Institute stressed that the use of Chinese AI software and overseas IP addresses does not establish that the attackers were Chinese nationals.
South Korean police opened a full investigation today into a wave of suspected AI assisted hacks on banks. President Lee Jae Myung says the signs point to AI models being used.
1. Seven financial firms hit so far, including Shinhan, KB Kookmin and Hana, with about 66,000 people’s data exposed
2. Regulators shared 28 attacker IP addresses with financial firms and gave them until Thursday to finish security checks
3. A Korea University security professor named ARTEX, a tool that uses AI to find vulnerabilities, as possibly involvedIf you run customer facing systems, scan your own stack with the same kind of AI tools this week and fix the top findings first.
— Cronus (@soycronus) October 6, 2026
South Korea has since placed its cybersecurity agencies on a 24-hour emergency response footing and ordered cloud service providers to block network activity associated with the suspected overseas IP addresses.
The attacks also triggered a sharp rally in South Korean cybersecurity stocks. Sands Lab and RaonSecure both gained nearly 30%, while AhnLab and Ginieans rose 15.58% and 20.83%, respectively, as investors bet on stronger demand for cybersecurity solutions.
Crypto users warn AI is lowering the barrier for cyberattacks
Crypto and Web3 users have focused on the possibility that AI agents could lower the technical barrier for carrying out sophisticated cyberattacks. Web3 enthusiast Coppercode described the reported ARTEX attack as a potential turning point, saying the AI agent carried out reconnaissance, credential stuffing and verification with little human input. He said autonomous AI could make sophisticated hacking easier for more people to carry out.
Others framed the incident as evidence that AI-driven cybercrime is moving from a theoretical threat to a practical security challenge. SkeletronJV highlighted reports that AI may have been involved in attacks against major South Korean banks, while SmindCrypto questioned whether financial institutions are prepared for attackers capable of writing and deploying malicious code rather than relying on traditional methods. Their comments show increasing concern that conventional cybersecurity defenses may struggle to keep pace with automated attack systems.
🌏 Asia .
AI bank hacks in Korea.
Advanced AI tools may have been used in a cyberattack on Shinhan Bank, and leaks have since been confirmed at KB Kookmin, Hana and BNK Busan Bank.
Four Korean banks breached — possibly by AI.
The next bank robber won’t wear a mask; it’ll write code.
Is your bank ready?
— Smindi (@SmindCrypto) October 3, 2026
The discussion has also raised important questions about the resilience of traditional financial infrastructure and the emerging AI-versus-AI security race. John pointed to the possibility of regulators using AI to counter AI-enabled attacks while Astrinvestor questioned whether banks can remain trusted as AI capabilities evolve faster than existing cybersecurity practices. Ethereum co-founder Vitalik Buterin has similarly argued that AI will not make cybersecurity impossible to defend, suggesting that increasingly capable AI could ultimately give defenders an advantage over attackers.
What comes next?
The focus may now move beyond identifying ARTEX to understanding how widely AI-powered attack tools are being used. AhnLab’s Security Intelligence Centre found ARTEX activity linked to about 600 IP addresses worldwide, with some of the same servers also running another AI security tool called CyberStrikeAI.
However, AhnLab said the IP addresses cannot be linked to a single attacker because ARTEX is open source and can also be used by security researchers. This means investigators may increasingly have to track wider networks of AI-powered attack infrastructure rather than individual hackers or malware.
The attacks have also shown that banks may need to look beyond their core systems when improving security. Investigators found that attackers targeted third-party services, including loan-broker portals and employee support systems.
At Shinhan Bank, about 25,000 customers were reportedly affected after attackers accessed a loan-related service with weak identity checks. The incident is putting more focus on stronger authentication, zero-trust security and AI-powered vulnerability checks that can continuously look for weak points.
Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads, and CoinMarketCap Community for seamless access to high-quality industry insights
Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.





















































































