
Experts are offering varied assessments of the causes and responses after the possibility emerged that artificial intelligence was deployed in recent data breaches at South Korean banks.
Shinhan Bank confirmed on Sept. 30 that the personal information of about 25,000 customers was leaked by an unauthorized outside party that bypassed identity verification procedures in its loan broker service, according to industry sources on the 2nd. The leaked data included customer names, annual income and resident registration numbers. Around the same time, KB Kookmin Bank suffered a breach involving about 100 cases of customer information, putting the financial sector on alert over security.
The Shinhan Bank breach is said to have been carried out through a technique known as credential stuffing, in which an unauthorized outside party randomly enters query input values. Credential stuffing refers to a method of obtaining large volumes of ID and password combinations leaked from other sites, then entering them at random into a bank's system to find accounts that allow a successful login.
The industry is focusing on the possibility that AI automation tools were used in the attack. Moon Jong-hyun, head of the Genians Security Center, wrote on his LinkedIn account on the 2nd to the effect that a Chinese-made AI hacking tool called ARTEX AI may have been running on the web server used in the attack. ARTEX AI is an AI program that automatically handles the entire process of searching for targets on its own, finding vulnerabilities, launching attacks and verifying the results.
Another security industry official said the incident should draw attention to the fact that every business system handling customer information — from simple inquiry services to internal apps used by employees — can become a target. "We need to check whether authentication and inquiry permissions are being properly applied, and strengthen monitoring systems that can quickly detect and block abnormal bulk inquiries," the official said.
Experts first pointed to lax security management at the banks. "Systems that are connected to the external internet and have relatively weak authentication procedures may be exposed to automated attacks using AI," said Son Kyu-sik, a professor in the Department of Hacking and Security at Hanyang Cyber University. "When a contracting financial firm signs an agreement with an outside vendor, it must closely review that vendor's security framework and maintain a system for continuous management and inspection even after the contract is signed."
Some see the fundamental structure of financial sector security as the problem. The industry has built its security framework around separating internal and external networks, but many AI services sit on external networks, making it difficult to defend against attacks with existing security systems. "The reality is that the existing procedures for building security systems are not keeping pace with the speed at which AI attack technology is advancing," said Lee Sang-geun, a professor in the Department of Smart Security at Korea University's Graduate School of Information Security.
Others said countermeasures must be prepared because AI-driven attacks are expected to increase. "Hackers have begun using AI agents, so the frequency and scale of attacks are bound to grow more severe," said Kim Myeong-ju, head of the Barun AI Research Center. "We need investment in security software, an expansion of specialized personnel, and AI defense systems to counter AI attacks."






