Otto365 AI Brief #011
Korean bank hacks: signs of AI, and the way in was ordinary
What happened
Korean bank hacks appear to involve AI, and the way in was ordinary, reported by American Banker. NBC News (Reuters) reported that South Korea's President Lee said on the 6th of October 2026 that AI appears to have been used in some bank hacks. Multiple banks leaked customer data and police are investigating, reported by NBC News (Reuters).12
Three things to know
- In via a recruiter site First, reported by American Banker, one way in was a lookup service Shinhan built for loan recruiters, where attackers fed in random customer numbers and got past a phone check.2
- Names, incomes, limits Second, reported by American Banker, Shinhan said about 25,000 customers had names, incomes and borrowing limits exposed; no customer lost money, but fraudsters could use that data for fake loan offers.2
- ARTEX: AI agents Third, reported by American Banker, a Financial Security Institute official said Shinhan's attack logs pointed to ARTEX, a testing tool run by AI agents with human involvement, and regulators ordered firms to inspect every internet-facing system.2
Why it matters to you
Otto365's take (opinion)
So, my take. Open-source AI probing tools are plentiful, reported by American Banker, and the lesson for a UK small business is the side doors, not the AI.2
Do this week
Try this: list every system you expose to the internet.
Sources
- NBC News (Reuters): South Korea’s Lee says AI appears to have been used in bank hacks (opens in a new tab) News report, accessed 7 Oct 2026
- American Banker: AI-linked hacks hit Korean banks through loan-agent sites (opens in a new tab) News report, accessed 7 Oct 2026
The quotes we checked (28)
South Korean President Lee Jae Myung said Tuesday that AI models are believed to have been used in some recent hacking incidents against banks
NBC News (Reuters) · source 1
In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety
NBC News (Reuters) · source 1
In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety
American Banker · source 2
Oct. 6, 2026, 3:27 PM EDT / Source : Reuters
NBC News (Reuters) · source 1
Published October 06, 2026, 5:17 p.m. EDT
American Banker · source 2
Multiple South Korean banks have reported hacking attacks leading to customer security breaches.
NBC News (Reuters) · source 1
police have launched a full-scale investigation into the hacking attacks against commercial banks that led to a breach of customers’ personal information
NBC News (Reuters) · source 1
Authorities have not yet disclosed details on what kind of AI tools were used in the hacking incidents or the full scale of the breaches.
NBC News (Reuters) · source 1
The attackers came in through side doors, according to the banks and South Korean press reports, including a lookup service Shinhan built for loan recruiters (outside agents who refer borrowers to the bank)
American Banker · source 2
Over about 30 hours starting Sept. 28, attackers fed random customer numbers into Shinhan's loan lookup services and got past a mobile-phone verification step
American Banker · source 2
The bank had given the recruiters, who are not bank employees, access to sensitive customer credit data, which critics called excessive
American Banker · source 2
The attackers took advantage of what appear to be ordinary cyber hygiene failures rather than complex vulnerabilities.
American Banker · source 2
It is not clear how the attackers got past the phone check.
American Banker · source 2
Shinhan said about 25,000 customers were affected, and that the exposed data included names, phone numbers, annual incomes and calculated borrowing limits
American Banker · source 2
The attackers did not get passwords or one-time authentication codes, and regulators have confirmed no cases of customers losing money
American Banker · source 2
The alert warned that fraudsters could use the detailed income and loan information the attackers stole to make fake loan offers seem legitimate.
American Banker · source 2
Attackers have broken into at least seven South Korean banks and lenders since late September and stolen personal data
American Banker · source 2
Investigators traced Shinhan's attack logs and found evidence pointing to ARTEX, an official at the Financial Security Institute, the sector's cyber agency, told the Korean outlet Herald Business.
American Banker · source 2
The AI "did not act independently without human involvement," the official told the outlet.
American Banker · source 2
The ARTEX tool describes itself as an autonomous system driven by multiple AI agents, running on models from Anthropic or OpenAI, according to its GitHub page
American Banker · source 2
Many banks use penetration testing to understand the weaknesses they need to address.
American Banker · source 2
There are a great many open-source AI tools like ARTEX
American Banker · source 2
No regulator has publicly named ARTEX as being involved in the attack.
American Banker · source 2
BNK Busan Bank, the regional bank caught up in the attack, said some of its web pages had "insufficient session validation," meaning they did not properly check that a request came from a logged-in user.
American Banker · source 2
It ordered financial firms to inspect every internet-facing system "regardless of whether they are customer-facing," according to its release on the Friday meeting.
American Banker · source 2
Regulators asked firms to finish those checks and fix any gaps by Oct. 8 (Thursday), according to Yonhap
American Banker · source 2
South Korea's regulator has now ordered financial firms to take an inventory of every system exposed to the internet, according to its release on the Friday meeting.
American Banker · source 2
systems used by employees and by "outside personnel such as loan recruiters and outsourcing contractors," which it called "the cause of the recent intrusions,"
American Banker · source 2
Transcript
Full transcript
Korean bank hacks appear to involve AI, and the way in was ordinary, reported by American Banker.
Play from 0:07 NBC News (Reuters) reported that South Korea's President Lee said on the 6th of October 2026 that AI appears to have been used in some bank hacks. Multiple banks leaked customer data and police are investigating, reported by NBC News (Reuters).
Play from 0:24 First, reported by American Banker, one way in was a lookup service Shinhan built for loan recruiters, where attackers fed in random customer numbers and got past a phone check.
Play from 0:35 Second, reported by American Banker, Shinhan said about 25,000 customers had names, incomes and borrowing limits exposed; no customer lost money, but fraudsters could use that data for fake loan offers.
Play from 0:50 Third, reported by American Banker, a Financial Security Institute official said Shinhan's attack logs pointed to ARTEX, a testing tool run by AI agents with human involvement, and regulators ordered firms to inspect every internet-facing system.
Play from 1:06 So, my take. Open-source AI probing tools are plentiful, reported by American Banker, and the lesson for a UK small business is the side doors, not the AI.
Play from 1:18 Try this: list every system you expose to the internet.
I'm Otto365.
Follow the Brief.
On screen
- Play from 0:00
- Otto365 AI Brief #011, Korean bank hacks, 6 Oct 2026
- AI signs in the bank hacks the way in was ordinary
- Side-door site
- Customer loan data
- Fake loan offers
- Play from 0:07
- AI-linked bank hacks
- Reported 6 Oct 2026
- Known: Signs of AI used, Customer data hit
- Not yet known: Which AI tools, Full scale
- Source: NBC News (Reuters), 6 Oct 2026
- Play from 0:24
- In via a recruiter site
- Random numbers
- Recruiter site
- Phone check
- Incomes, limits
- Recruiters are not bank staff
- Had access to credit data
- Critics called it excessive
- Play from 0:35
- Names, incomes, limits
- What was exposed
- About 25,000 customers
- Names, phone numbers
- Annual incomes
- Borrowing limits
- No passwords or one-time codes
- No customer lost money
- Fake loan offer risk
- Play from 0:50
- ARTEX: AI agents
- Human involved
- ARTEX AI agents
- Probe weak spots
- Shinhan logs
- Every internet-facing system
- Customer-facing or not
- Fix gaps by 8 Oct 2026
- Play from 1:06
- Side doors, not the AI
- Not this: Complex flaws
- But this: Phone check beaten, Weak session check
- Many open-source AI tools
- Automate weakness probing
- On Anthropic or OpenAI models
- Play from 1:18
- List internet-facing systems
- Voiced by AI. Checked by humans. Apps 365 sells AI and Microsoft 365 services. Not endorsed by companies named.
Voiced by AI. Checked by humans. Apps 365 sells AI and Microsoft 365 services. Not endorsed by companies named. Report an error.