The Wall Street Journal reports that attackers used Artex in incidents at at least seven South Korean financial institutions, with access to data on about 68,000 people.
Artex is an open-source automated penetration-testing tool, not an AI model.
After the disclosures, its terms were changed to explicitly prohibit unauthorized intrusion and data theft.
The newspaper describes the case as one of the first times an artificial intelligence agent has been used in a real-life attack on banks. The data exposed includes names, contact details, ID numbers, annual incomes and borrowing limits.
Which institutions were affected?
The list includes Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. According to data reported by the Wall Street Journal, about 40.000 Yegaram customers and 25.000 Shinhan customers were affected.
There is no indication so far that the data is sufficient to make payments without the owners' permission. South Korean authorities are warning, however, of a possible second wave of phishing and smishing attacks: deceptive emails or SMS messages that attempt to trick recipients.
How does Artex work?
Artex AI is not an AI model, but an automated penetration testing tool: it scans systems for vulnerabilities so that organizations can strengthen their security. It acts as an “agent” that delegates tasks to other models, such as Anthropic’s Opus, OpenAI’s GPT models, and DeepSeek. With limited human intervention, it can search for vulnerabilities and plot potential entry points.
It was created by Chinese cybersecurity engineer Li Puhua, known as Autumn. Following the revelations, Artex changed its terms of use, explicitly prohibiting unauthorized intrusion, data theft, and other malicious uses.
The traces and origin of the attacks
Researchers identified more than 24 IP addresses linked to the attacks, in about 12 countries, including the US, Japan and Germany. Later, South Korean cybersecurity firm AhnLab found traces of Artex on about 600 IP addresses worldwide. A second tool, CyberStrikeAI, appeared to be used on some servers.
These findings do not prove that the attacks originated in China. The origin of the perpetrators has not been ascertained from the evidence described in the report.
Researchers warn that tools like Artex can reduce the technical knowledge required for complex attacks by taking sequential steps without ongoing guidance. This allows a less experienced attacker to attempt more complex actions, while an experienced one can move faster and on a larger scale.
Anthropic reported in 2025 that Chinese state-backed hackers had used its technology in attacks against about 30 organizations. Incidents or attempts at autonomous attacks using AI agents have also been recorded in Australia and Canada.
South Korean President Lee Jae-myung has called for a swift investigation and immediate reinforcement of security systems. Police are investigating the case and are seeking international cooperation to find the perpetrators, while the regulator has called on the financial industry to develop defenses that also leverage artificial intelligence.
Top comments (0)