Business

Shinhan and six Korean lenders lose 68,000 records in hacks tied to an AI tool

Regulators ordered every Korean financial firm to cut outside access, but the leaked loan files are already a gift to phone scammers
Victor Maslow
Add us on Google

Shinhan Bank and six other South Korean lenders have lost the personal data of tens of thousands of people in a run of break-ins that investigators trace to a single attacker, and the attack server carried traces of an open-source AI tool built to test defences, not to breach them. The Financial Services Commission answered by ordering every financial firm in the country to shut off outside access to its systems unless that access is essential to the business.

For customers, the loss is not money. It is leverage. The leaked files hold names, phone numbers, resident registration numbers (Korea’s lifelong national ID), annual income, credit limits and loan-application details, the exact kit a phone scammer needs to sound like your bank. Regulators say nothing taken can be used directly to make payments. Their warning is about the second wave: voice phishing and fraudulent texts aimed at people whose loan terms the caller already knows.

The tool is ARTEX AI, a Chinese-language system distributed through GitHub that uses a large language model to scan for weaknesses and plan a route in. Investigators at the Korea Financial Security Institute picked it out through a data signature its traffic leaves behind, the Herald Business reported. They stress that a human directed the attacks, and the Chinese-language interface does not establish where that person is based.

None of the break-ins went through the mobile apps or internet banking that customers use. They hit the side doors instead: portals for employees, outsourced developers and the loan agents who sell credit on banks’ behalf. At Shinhan, the largest commercial-bank breach at roughly 25,700 customers, the attacker got past identity checks on a service reserved for loan brokers. Yegaram Savings Bank, a far smaller lender, lost the most, about 40,000 records. Across all seven firms, the count stands at roughly 68,000. Lim Jong-in of Korea University’s Graduate School of Information Security told the Korea Times that AI agents can hunt for weak points automatically and pick a partner’s server over a bank’s core system.

Money was not the missing ingredient. Shinhan, KB Kookmin and Hana together spent 124 billion won, about $92 million, on information security last year, according to the Korea Times. Detection was still slow. Shinhan took more than 15 hours to spot its intrusion, Hana nearly 42 and KB Kookmin almost 68, by the Korea JoongAng Daily’s count.

Much remains unproven. The commission’s chair, Lee Eog-weon, says regulators “cannot rule out” AI involvement, which is short of proof, and nobody has yet shown the tool did anything a skilled attacker with ordinary scanners could not. Record counts have shifted as banks re-audit, and KB Kookmin and Hana account for only a couple of hundred customers between them. Blocking outside access is an emergency brake, too, not a repair. It slows the contractors and loan agents whose work runs through those portals, and it does nothing about passwords leaked in earlier breaches, which experts say were reused here.

So far the campaign is Korean; no attack outside the country has been linked to it. But open-source testing tools like ARTEX are plentiful and legal to download, and an official told the Herald Business that restricting them worldwide is close to impossible. Any bank that sells loans through third-party agents shares the exposure. Hwang Suk-jin of Dongguk University argued that defences can no longer be organised firm by firm once attacks are automated.

The first breach surfaced at Shinhan on Thursday, October 1. The commission met industry chiefs in an emergency session on Sunday, October 4, the same day President Lee Jae Myung ordered a thorough investigation. Regulators have sent the attacker’s IP addresses to about 500 financial firms, and every lender must report the results of an emergency security inspection by Thursday, October 8. Shinhan has pledged full compensation to affected customers, according to KED Global.

The breach most victims will notice is still to come. It will arrive as a phone call from someone who already knows their credit limit.

Tags: , , , , ,

Add us on Google

Discussion

There are 0 comments.