Thursday, October 8, 2026

AI hacking tool targeting financial firms; hundreds of servers spotted worldwide

Input
2026-10-08 14:52:34
Updated
2026-10-08 14:52:34
Graphic on hacking. Yonhap News Agency

[Financial News] Hundreds of servers running ARTEX, an open-source artificial intelligence (AI) penetration-testing tool whose use in recent cyberattacks on South Korea’s financial sector has been detected, have been observed around the world. There are concerns that AI’s automation of vulnerability searches and attack-path design could increase the speed and scale of cyberattacks. Questions have also been raised about the possibility that loan-related information leaked in the recent attacks on the financial sector could be used for secondary crimes, such as targeted voice phishing.
According to a threat intelligence note released on the 8th by S2W Inc., a security and data intelligence company, hundreds of servers around the world were observed running the same tool, ARTEX, whose use in recent cyberattacks on the financial sector was detected. ARTEX is an open-source, AI-based penetration-testing tool originally developed to check companies for security vulnerabilities. Once a user sets a target, the AI can gather information, search for vulnerabilities and design attack paths.
After analyzing attack information shared by financial authorities, S2W confirmed records showing that, at one of the IP addresses used in the attack, a relay program connecting the ARTEX management interface to an AI model was also running. The server had been operational since early September, and is believed to have been taken offline after related reports were published. However, determining whether the AI actually carried out the theft of personal information would require an investigation by the authorities.
The attackers are believed to have changed their access addresses by alternating between rented servers overseas and commercial proxies. The IP addresses used in the attacks included some based in South Korea, and most had almost no reports in existing global threat-reputation databases. This meant the attacks were difficult to detect using only methods that block known malicious IP addresses.
The attack targeted supplementary services, such as loan inquiries, whose security management is relatively weak—not core banking systems. The attacker is believed to have repeatedly changed customer numbers to access other customers’ information. The attack exploited inadequate authorization checks, which are meant to confirm that a user has permission to access the information even after the user has been authenticated.
There are also concerns about possible secondary harm resulting from the leak of personal information. According to financial authorities, there was no evidence that information directly usable for unauthorized payments, such as account passwords or one-time passwords (OTPs), had been leaked. However, the leak of names, contact details and loan-related information has raised concerns about the possibility of targeted voice phishing and smishing using that information.
Attempts to sell fake personal information by exploiting the cyberattacks on the financial sector have also been detected. According to S2W, posts appeared on the dark web offering to sell millions of customer records from a major South Korean card issuer. But analysis of samples revealed signs of fabricated data, including phone numbers using old prefixes such as “011,” “016” and “019,” and the absence of common Korean surnames.
In its report, S2W stressed, “To respond to AI-based attacks, we need to move beyond a security framework centered on blocking IP addresses, detect suspicious behavior such as abnormal high-volume queries, and build our own capacity to use AI to assess vulnerabilities.”

[email protected] Choi Hye-rim Reporter