Friday, October 2, 2026

Traces of 'Chinese-language AI penetration tool' found on Shinhan Bank's hacked server

Input
2026-10-02 14:47:18
Updated
2026-10-02 14:47:18
View of Shinhan Bank headquarters. News1

[Financial News] In connection with the leak of Shinhan Bank customer information, traces associated with a Chinese-language open-source artificial intelligence (AI) penetration-testing tool were found on a server presumed to have been used in the cyberattack. Although it has not been confirmed whether AI was used in the actual attack, the cybersecurity industry is focusing on the possibility that AI was used to automate the cyberattack process.
According to the cybersecurity industry on the 2nd, the HTML title of a web server presumed to have been used in the attack on Shinhan Bank contained the phrase 'ARTEX-AI Autonomous Penetration Testing Console (ARTEX—Autonomous Penetration Testing Console).'
ARTEX AI is an open-source, large language model (LLM)-based penetration-testing system developed and released primarily in Chinese. It is designed to have multiple AI agents divide responsibilities and perform tasks such as information gathering, vulnerability discovery, attack-path design, security-tool execution, and vulnerability verification.
Moon Jong-hyun, head of the Genians Security Center, disclosed these findings on LinkedIn that day. Based on the discovery of strings on the web server that appeared to be related to ARTEX AI, Moon raised the possibility that an AI-based attack-automation tool had been used.
Moon said, "Several threat analysts have reasonable grounds to suspect that an AI-based attack-automation tool may have been used in the attack on the financial institution. While it can serve as an efficient penetration-testing tool in authorized security-validation environments, if abused by attackers, it could be repurposed to increase the automation and efficiency of actual cyberattacks."
ARTEX AI was also introduced as the project that won the Agent+ offense-and-defense capabilities challenge led by the Baidu Security Response Center (BSRC) in China this year.
However, based solely on the evidence currently available, it is difficult to conclude that ARTEX AI was actually used as an attack tool in the process of leaking Shinhan Bank customer information. The financial authorities and other relevant institutions, including Shinhan Bank, have not officially confirmed whether ARTEX AI was actually used.
Shinhan Bank previously announced on the 30th of last month that it had confirmed the personal information of about 25,000 customers was leaked after an external unauthorized party accessed its loan-recruiter service by bypassing the identity-verification process.
[email protected] Choi Hye-rim Reporter