AI Agents Breached Korea's Banks: Inside the FSC's AI-vs-AI Response
Autonomous AI agents probed exposed support systems at seven Korean financial firms, leaking 65,000+ customer records. What the FSC breach teaches.
Published by Zero Hunt, an autonomous AI red team on an on-premise appliance running private AI: automated penetration testing for networks and infrastructure, black-box or gray-box, with a human approving every step that matters.
Over the first days of October 2026, at least seven South Korean financial firms — including three of the country's largest commercial banks — disclosed that attackers had reached personal data on tens of thousands of customers. What pushed the story onto every front page was not the volume. It was the regulator's own language: on October 4 the Financial Services Commission said "the possibility of AI-powered attacks cannot be ruled out," and ordered the sector to deploy "security that uses AI in place to defend against AI attacks." If that framing is right, this is one of the first regulator-acknowledged cases of an autonomous AI agent running the reconnaissance-and-breach loop against a national banking sector.
Developing story — first published 16:37 CEST (14:37 UTC), October 5, 2026. Updated as the FSC and affected firms publish more.
At a glance
| Who was hit | Shinhan, KB Kookmin, Hana, BNK Busan, Yegaram Savings Bank, Hyundai Capital, Welcome Savings Bank; Woori and NH Nonghyup were targeted but report no leak |
| Largest exposures | ~40,000 customers at Yegaram Savings Bank; ~25,000 at Shinhan via a loan-broker service |
| Data exposed | Names, phone numbers, addresses, resident registration numbers, income and loan-limit fields; no account or transaction data reached |
| Entry point | Externally-connected support and lookup systems — employee mobile work support, sales support, loan-broker services — not core banking |
| The AI angle | FSC: AI-powered attacks "cannot be ruled out"; a server in the attacks reportedly served pages tied to ARTEX AI, an open-source agentic pentest framework (unconfirmed) |
| Official response | FSC Chairman Lee Eog-weon chaired an emergency meeting on 2026-10-04; President Lee ordered a thorough probe the same day |
| Status | Under investigation; single-actor attribution not confirmed |
What happened
The disclosures came in a cluster. BleepingComputer reported confirmed intrusions at Shinhan, KB Kookmin and Hana — each a commercial bank holding over $400 billion in assets. Korea JoongAng Daily and UPI put the confirmed count higher and more varied: roughly 25,000 customers at Shinhan through a loan-broker service, around 40,000 at Yegaram Savings Bank, 146 mortgage agents at Hyundai Capital, 119 customers at KB Kookmin, 89 at Hana, and a handful of outsourced developers at BNK Busan. Woori Bank and NH Nonghyup's mutual-finance arm were probed but reported no data loss.
One detail defines the whole incident. In every case the attackers went after externally-connected support and lookup systems — employee mobile work platforms, sales-support tools, loan-broker portals — and not the core banking networks where account ledgers and transaction records live. UPI quoted authorities describing a focus on "externally connected support and lookup systems rather than core financial networks such as online banking or account ledgers." The data that leaked was identity data: names, phone numbers, addresses, resident registration numbers, annual income and loan limits. Painful, reportable, and useful for downstream fraud — but not the vault.
The AI tell: an agentic pentest framework pointed the wrong way
Why does a sector of banks suddenly call the same breach "AI-powered"? Two signals. The first is behavioral: investigators describe an actor that repeatedly probed many access paths across many institutions, hunting for a weak point in support and lookup systems the way a tireless scanner would. The second is an artifact — BleepingComputer reports that a server tied to the attacks served HTML carrying Chinese-language text associated with ARTEX AI, described as an open-source penetration-testing system whose agents automate information gathering, vulnerability discovery, attack-path planning, security-tool execution and vulnerability verification. No bank has officially confirmed the tool, and the FSC itself says it is still unclear whether one actor or AI tooling was behind all of it. Treat the ARTEX link as a strong lead, not a fact.
The mechanism is the part worth understanding, because it is not going away. An agentic pentest framework is a planner wrapped around ordinary tools. It takes a target, runs recon, reasons about what it found, picks the next action, executes it, checks whether the action worked, and loops — autonomously, across hundreds of endpoints, at machine tempo, without a human deciding each step. Pointed at authorized scope, that is a legitimate security tool. Pointed at someone else's bank, it is an attacker that never gets tired, never forgets a half-open door it saw three hours ago, and parallelizes across every institution in a sector at once.
"Our last pentest was clean." That sentence meant something when a human tester had two weeks and a fixed scope. Against an agent that re-plans after every response and runs continuously, a clean report from last quarter tells you about last quarter's configuration — not about the support portal a contractor stood up on Tuesday.
That is the real lesson of the Korean cluster: the banks' core networks held, but the periphery — the fast-moving, often-outsourced layer of support and lookup apps — is exactly where an autonomous prober finds the one unvalidated input it needs. It mirrors what we have been tracking all autumn, from agents fuzzing government web apps to continuous agentic red-teaming as the only cadence that keeps pace.
Who was exposed — and what the agent could not reach
The containment story matters as much as the breach. Across all seven firms, no financial-transaction or account data was reached; the exposure stopped at identity and loan-application fields held in peripheral systems. That is the segmentation working — core banking sat behind controls the probing agent did not get through. The counter-lesson is that identity data at this scale (65,000-plus records across Shinhan and Yegaram alone) is enough to seed convincing phishing, SIM-swap and loan-fraud campaigns against the same customers. "No transaction data" is not "no harm."
Remediation
There is no single patch here — the fix is configuration, exposure reduction and continuous validation of the systems an autonomous prober reaches first.
- Am I exposed? Inventory every externally-reachable support, sales and broker application — including ones stood up by contractors and business units outside IT's change process. For each, confirm it enforces authentication, rate-limits, and does not expose customer-lookup functions to unauthenticated or lightly-authenticated callers. The Korean entry points were all in this layer.
- Reduce the attack surface. Pull internal support and lookup tooling behind SSO and network controls; it rarely needs to face the public internet at all. Separate customer-facing portals from employee support systems so one does not pivot to the other.
- Hunt for the probing pattern. An agentic prober is loud over time: many distinct paths tried per source, systematic parameter and filename enumeration, and sustained request bursts that do not match human sessions, mapped to MITRE ATT&CK T1595 (Active Scanning) and T1190 (Exploit Public-Facing Application). Review access logs on peripheral apps for one source touching many endpoints and many institutions' patterns, not single-request signatures.
- Verify segmentation. Confirm that a compromise of a support or lookup app cannot reach account ledgers or transaction systems. Test the boundary, don't assume it.
- Rotate and notify. Where identity data leaked, treat it as material for fraud against those customers: force step-up on affected accounts, warn users about targeted phishing, and run the breach-notification clock from the moment you became aware, not from the moment you finished investigating.
What is not known yet
- Whether a single actor or one AI toolchain is behind all seven firms, or whether multiple opportunists hit the same weak layer in parallel. Authorities say this is still unclear.
- Whether ARTEX AI was actually used, or whether the Chinese-language artifact is a misdirection.
- The full count of affected individuals, which the FSC and firms are still reconciling.
- Whether any core financial system was touched and simply not yet disclosed.
We will update this post as the FSC, KISA and the affected firms publish verified findings.
Meeting autonomous offense with governed autonomous offense
The FSC's instinct — "use AI to defend against AI" — is right in spirit and incomplete in practice. Detection AI tells you an agent is already inside. The harder question the Korean banks are now asking is the one Zero Hunt is built to answer: where is the input-reachable weakness in our externally-exposed support systems that an autonomous agent will find first? The honest way to know is to run a governed autonomous agent against yourself before someone else runs an ungoverned one against you.
Zero Hunt is an autonomous AI red team that runs on-premise on its own private models. Its 10-agent swarm probes your web apps and APIs the way ARTEX would — black-box by default, Recon through Exploit through Pivot — but writes a fresh, per-target proof-of-concept with a local LLM rather than replaying a public script, and runs every finding through the AI Gym backtest corpus before it touches production. Because it is change-triggered, a new broker portal a business unit stands up on Tuesday gets a full campaign within the hour, not at next quarter's pentest. And because five human-in-the-loop autonomy levels gate every exploitation and escalation step, it has the discipline the attacker's agent does not — nothing leaves the appliance, and every action is approved, recorded and signed at write time. Where detection matters, the same appliance runs a deep-learning traffic model with four inference heads on its own GPU, reading the machine-tempo probing ladder — many paths, many endpoints, no human cadence — while it happens, not in the next morning's SIEM digest. This is also why automated penetration testing has stopped being a once-a-year line item: when the attacker is an agent that re-plans after every response, the only test that means anything is one that runs on the same loop, under human control. Talk to us about validating the systems an AI prober reaches first.
Is this exploitable in your environment?
Zero Hunt answers that on your own network: an autonomous AI red team on an on-premise appliance, running on private AI, black-box or gray-box, with a human approving every step that matters. Proof of what is exploitable, the fix, and signed evidence — no data leaves your perimeter.