Skip to content
Banking & Compliance

AI Agents Helped Hack Seven Korean Banks Through Their Side Doors: A Loan-Recruiter Lookup, A Staff Mobile App, A Sales Tool. Every UK Bank Has The Same Doors

South Korea has what investigators describe as the first known case of AI agents being used to attack the financial sector. Since late September attackers have breached at least seven banks and lenders - Shinhan, KB Kookmin, Hana, BNK Busan, two savings banks and a consumer lender - exposing personal data on about 68,000 people. They did not break through the front door. They cycled through customer numbers for 30 hours on a lookup service Shinhan built for loan recruiters, slipped past weak session checks on an employee mobile app, and found similar gaps in a sales-support system. Investigators suspect ARTEX, an open-source penetration-testing framework described as 'an autonomous system driven by multiple AI agents'. On 6 October President Lee said AI now makes it 'possible to hack with ease even without specialized skills'. The lesson for UK banks is not about exotic AI attacks. It is that AI has made the oldest weaknesses cheap to find.

AlchmAI Editorial12 min read

7

Korean banks and lenders breached since late September, including Shinhan, KB Kookmin, Hana and BNK Busan

~68,000

People whose personal data was exposed - names, phone numbers, income, loan limits and, in some cases, resident registration numbers

30 hours

How long attackers cycled through customer numbers on Shinhan's loan-recruiter lookup service, starting 28 September

8 Oct

Deadline Korea's Financial Services Commission set for firms to audit and fix every internet-facing system

The breaches came to light on 30 September and the count has grown since. At least seven South Korean financial institutions - Shinhan Bank, KB Kookmin, Hana Bank, BNK Busan, two savings banks and a consumer lender - have had customer data stolen. Shinhan reported about 25,000 customers affected, much of it loan-application detail; KB Kookmin 99 customers and 20 current and former employees; Hana 89 customers. Across all seven, roughly 68,000 people's names, phone numbers, annual incomes and calculated borrowing limits were exposed, and in some cases their resident registration numbers - exactly the material a fraudster needs to make a fake loan offer convincing.

On Tuesday 6 October President Lee Jae Myung told his cabinet that 'signs have emerged' of AI being used, and that 'it's now become possible to use AI to hack with ease even without specialized skills.' Investigators suspect ARTEX, an open-source AI penetration-testing framework whose documentation describes it as 'an autonomous system driven by multiple AI agents' running on commercial models; officials have said the tool did not act without human involvement. Police have set up a dedicated investigative team, authorities have shared dozens of IP addresses traced to at least a dozen countries with the sector, and the Financial Services Commission ordered every financial firm to audit and fix its internet-facing systems by 8 October.

The Side Doors Every Bank Has

  • Introducer and broker portals. UK lenders run portals for mortgage brokers, introducers and affiliates that look up applications and customer status - the direct equivalent of Shinhan's loan-recruiter service.
  • Staff mobile and remote-work apps. Built quickly, often by a different team from the customer app, with session handling that has never faced a determined attacker.
  • Sales, CRM and marketing tools. Internet-facing because sales teams work on the move, holding customer contact and income data, and rarely in the scope of the main penetration test.
  • Legacy and vendor-hosted pages. Old campaign sites, document upload forms and third-party hosted services that still connect to customer data.
  • Test and pre-production environments. Reachable from the internet 'temporarily', for years.

“AI did not invent a new way into Korea's banks. It walked through the ones the banks had forgotten they had, faster and more patiently than any human attacker.”

What UK Banks And Fintechs Should Do This Month

  1. 01Do what Korea's regulator ordered: inventory every internet-facing system, including partner, broker, staff and vendor-hosted ones, and fix the gaps. Most firms discover systems they did not know were exposed.
  2. 02Kill enumeration. Rate-limit and alert on any lookup that can be driven by guessing identifiers - customer numbers, application references, phone numbers. Thirty hours of guessing should never go unnoticed.
  3. 03Fix session management on every app, not just the flagship one: short-lived tokens, server-side validation on every request, device binding for staff apps.
  4. 04Bring partner portals into the same security standard and monitoring as customer channels. Broker and introducer access should be scoped to their own cases, logged and reviewed.
  5. 05Use the same tools defensively. AI-assisted attack-surface discovery and continuous testing will find these weaknesses first if you point them at your own estate.
  6. 06Prepare to report. Under the UK's financial-sector incident regime - a 24-hour initial notification and 72-hour report - an AI-assisted breach of a partner portal is reportable like any other. Rehearse it.

The Bottom Line

South Korea's breaches - seven banks and lenders, about 68,000 people's data, and what investigators call the first known use of AI agents against the financial sector - happened through side doors: a loan-recruiter lookup cycled for 30 hours, a staff mobile app with weak sessions, a sales tool with the same flaw. The suspected tool, ARTEX, is an open-source multi-agent penetration-testing framework, and the president's warning that AI now lets attackers 'hack with ease even without specialized skills' is the point. For UK banks and fintechs the response is not exotic: inventory every exposed system, stop enumeration, fix session handling everywhere, hold partner portals to customer-channel standards, test continuously with the same AI tools, and be ready for the 24-hour clock. That is the secure banking portal and compliance engineering we do as a fintech AI agency in London, and Korea has just shown where to look first.

References & Further Reading

Compliance & Regulatory SystemsBanking Portals & InterfacesEnterprise-Grade Security & ScalabilityAI cyber riskFintech AI Agency LondonAI Agency UKAgentic AI
Share Email
AI

AlchmAI Editorial

Research and analysis, London

The AlchmAI team writes about the markets, technology and regulation we work with every day. We build trading platforms, real-time charts and AI analysis tools for brokers, prop firms and fintech teams from our office in Mayfair, London. Every article lists its sources. Nothing we publish is investment advice.

This article is general information and commentary. It is not investment advice or a recommendation to buy or sell any investment. Important information