How did a two month old AI tool end up in attacks on Korean financial firms?
Here is a timeline that should make you a little uneasy. On July 26, a Chinese language, open source tool lands on GitHub. Its job: use a large language model to scan systems, find weak spots, plan attacks, run security tools and check what worked. Fast forward to early October. Seven South Korean financial companies report data breaches, and investigators find that tool's fingerprints all over the attack.
It is called ARTEX. Korea's financial security institute traced attack addresses and server logs from the first bank hit and confirmed a signature specific to the tool. One server even had a page title, in Chinese, calling itself an AI autonomous penetration testing console. Subtle it was not.
The numbers reported so far: around 25,000 customers at one major bank, credit card details of roughly 119,000 people at another, and about 40,000 at a savings bank. The banks say transaction data was not leaked.
Spray and pray, and it worked
Nobody here was picked by name. The attacker hit many firms at once and got through wherever the defences were weakest: systems used by employees, loan agents and partners, not the customer facing apps.
So who did it? Chinese tool, so Chinese hackers? Not so fast.
The tool is public. Anyone on the planet can download it, and the attack addresses hopped across several countries. The head of the institute said plainly that using a China built tool is not enough to pin down who is behind it. Police went further: whether AI was used is not the point, the gaps in the defences are.
Regulators ordered emergency security checks and shared lists of malicious addresses with roughly 500 institutions. The chair of the financial regulator called for defending against AI attacks with AI. And the scary part is how little skill any of this needs now. Download, aim, wait. One win like this is enough to make every other bank wonder if it is next.