South Korea’s president said out loud this week what every bank customer already suspects: the attackers are bringing artificial intelligence to the fight, and the people guarding the money are not keeping up. Twenty-five thousand Shinhan Bank customers had their personal data exposed before a single regulator said a word in public. The tool suspected in the intrusions is free, open-source, and sitting on the internet for anyone to download.
The Financial Services Commission called an emergency session on October 2 after the Shinhan leak surfaced, then watched the damage spread. KB Kookmin Bank was hit. So were Hana Bank and Woori Bank, according to NBC News. Shinhan and KB Kookmin each hold more than $400 billion in assets, and that is the figure the country’s markets noticed first — not the 25,000 people whose details were already gone.
Inside those meetings the language stayed careful. Authorities confirmed the Shinhan breach, said the incidents were still being counted, and promised to manage consumer protection and compensation. That is the order this work always happens in: contain the story, then get to the customers somewhere after the audit.
Lee Jae Myung — The First Head of State to Say the Hackers Brought AI, and Mean It
On October 6, President Lee Jae Myung told a cabinet meeting that AI models appear to have been used in some of the bank break-ins, that the signs had produced real public alarm, and that the country needed cybersecurity built for the AI era. He told officials to establish the facts quickly and to put people and resources into limiting the damage. The National Police Agency then opened a full-scale investigation, per NBC News.
Consider what that announcement actually concedes. A head of state, in public, in a cabinet room, named AI as part of an active criminal attack on his country’s banking system and had no specific tool, no confirmed suspect and no full tally to hand the public. The admission arrived before the answer did.
It says something about 2026 that a president naming AI as an attack instrument counts as a revelation. The intruders did not discover new physics. They found a cheaper employee.
ARTEX AI — A Free Attack Kit With a Chinese Label and No Owner
Yonhap reported that a server used in the attacks carried an HTML page title with a Chinese-language string linked to ARTEX AI. That is an open-source penetration-testing system which runs AI agents through the entire job a human intruder used to do by hand: reconnaissance, vulnerability discovery, attack-path planning, driving the security tools, and confirming which openings actually worked. BleepingComputer notes the banks have not confirmed ARTEX was used at Shinhan.
That caveat matters, and it also misses the point. A framework that automates the thinking of a human intruder does not need to be proven in one breach to be a problem in the next hundred. It needs only to exist, to be free, and to be easier than hiring.
Run the arithmetic that has already gutted every other kind of work. If the tool costs nothing and the labor was never free, the tool wins. Nobody had to build a better cybercriminal. They had to publish a cheaper one.
Shin Jin-chang — Inspect Everything, Fix It Fast, and Please Do Not Ask Who Is Next
At the October 2 emergency meeting, FSC Secretary-General Shin Jin-chang sat with the Financial Supervisory Service, the Financial Security Institute, six banks, three card companies and the banking associations, and handed down three orders, according to the commission’s own readout: check every system reachable from outside the company, close the paths that reach internal data without authentication, and share attacker IP addresses fast enough that the next bank can block them before it becomes another case file.
Banks were told to submit their inspection results as soon as possible. The instruction is the right one. It is also the same instruction that follows every breach, which is the part worth noticing: the checklist is old, and the thing that broke it is new. Nobody attached a date to the promise that customers would be made whole.
A data breach is the only robbery where the goods get copied, the victim keeps the original, and the victim still pays for the locks.
Shinhan Bank — 25,000 Customers Learned the Price of Someone Else’s Shortcut
Count the people. Twenty-five thousand Shinhan customers whose personal details are now somewhere the bank does not control, plus credit card information taken from Kookmin. Officials have not published a complete tally, which means the number is either unknown or unwelcome, and either way it is not shrinking.
Those customers will spend the next year resetting passwords, scanning statements and arguing with a call center about a charge that is not theirs. The bank will spend the next quarter on a forensic report almost nobody outside the building will read. One side of that ledger gets a lawyer. The other side gets a helpline.
Compensation, when it arrives, comes as a form and a wait. The breach did not ask permission.
What Changes Next — A Free Tool, an Open Question, and Banks That Were Always the Test Case
Watch three things. First, whether investigators confirm ARTEX AI was the instrument at Shinhan or merely a name on a server that happened to be nearby — attribution changes the politics, never the damage. Second, whether Korea converts this into enforceable rules for externally exposed banking systems or settles for another checklist and another follow-up meeting. Third, whether the same free framework surfaces in the next country’s breach report, because nothing about it is Korean, expensive, or hard to find.
The artificial intelligence boom has a bill, and the industry keeps pointing at the chips. The sharper cost sits here. Twenty-five thousand people who never bought a processor, never trained a model and never signed a contract with an AI company are now carrying the loss from one anyway. Their data was the collateral, and nobody asked them to co-sign.
The defenses held right up until a tool anyone could download walked in through the front door.
Sources: NBC News, BleepingComputer, Financial Services Commission.