Artex traces turn up in breaches at South Korea's biggest banks
Police opened a probe after officials said data on about 68,000 people was taken from South Korean banks using a Chinese-language tool called Artex. Shinhan said 25,000 customers were affected, including income and loan-limit fields. No suspect has been named.

Seoul3 min read
Last updated
A Chinese-language tool called Artex shows up in South Korea's bank breaches
Investigators in Seoul say hackers used a Chinese artificial-intelligence agent to steal personal data from customers of South Korea's largest banks. Officials put the number of people affected at about 68,000. The National Police Agency's cyber unit said on Tuesday it had opened a probe. President Lee Jae Myung told a cabinet meeting the same day that speed mattered and that banks should put the necessary measures in place at once.
The attacks, first detected last week, hit at least seven financial firms and left traces of a tool called Artex, a Chinese-language autonomous penetration-testing program. Shinhan Bank said about 25,000 customers were affected, with names, phone numbers, annual income and loan limits exposed. KB Kookmin Bank reported 119 affected customers. Hana Bank reported 89. Yegaram Savings Bank and BNK Busan Bank also reported breaches. Woori Bank and NH NongHyup Bank found signs of attempts, with no confirmed leak.
The 68,000 figure and the bank-by-bank figures do not add to the same total. Shinhan's 25,000 plus the two smaller confirmed counts is well short of 68,000. The larger number is the official aggregate. The smaller numbers are what three banks have published. Both should be kept. They describe different stages of the count.
What Artex is built to do
Artex scans systems for weaknesses and builds possible attack paths. It can connect to models from DeepSeek, OpenAI and Anthropic, and it can run several agents against a target at once. That design is sold as a tool for defenders who want to test their own networks. After the first Korean bank reports, Artex updated its user guidelines to say the tool must not be used for unauthorised intrusion or data theft. A guideline change does not identify the operator. It does show the maker responding to the reports.
Police have not named a suspect. They said the attacks came from more than two dozen internet addresses in about a dozen countries, including the United States, Japan and Germany. An address in another country is not a nationality. It is a routing fact. Seoul has said it is seeking international cooperation. The stolen fields, annual income and personal-loan limits, are the sort of data a fraud ring buys. They are not account numbers and passwords in the descriptions released so far. They are enough to tailor a loan scam.
The market reaction, and the limit of the finding
Shares of South Korean cybersecurity firms rose by as much as 30 percent on Tuesday. That is a price move, not a finding about who broke in. Lee's instruction to the banks was about speed of defence, not about attribution. The attribution available on Wednesday is a tool name, a language, a set of model providers the tool can call, and a list of banks. It is not a person, a state, or a charge.
The concrete takeaway is the split between a penetration-testing product and a live intrusion. Artex is built to find paths. Someone pointed it at Shinhan, Kookmin, Hana and at least four other firms. The data that left included income and loan limits for tens of thousands of customers, on the official count. The guideline Artex added after the reports is an admission that the same software can be used the other way.
Why income and loan limits matter
A stolen account number can be used once, until the bank freezes it. A stolen income figure and a loan limit can be used for months, in a phone call that sounds like the bank. That is why the Shinhan list, names, phone numbers, annual income and loan limits, is a fraud kit even without passwords. The 25,000 customers Shinhan named are the group for whom that kit is already confirmed. The 68,000 figure, if it holds, is the wider group.
Lee's cabinet instruction did not name Artex. The police unit did. The gap between a presidential order to harden systems and a police statement about a tool is the gap between defence and attribution. Banks can do the first without the second. Depositors cannot tell, from the public record on Wednesday, whether their own file is in the 25,000 or only in the aggregate.
Continue reading
- News
Bulgaria ends the search for 12 Syrian sailors after a Black Sea drone strike
Almanaque Digital DeskSofia
- News
Hezbollah received 200 million dollars from Iran, couriers took a fifth
Almanaque Digital DeskBeirut
- News
Pentagon sets a Fort Hood firing squad for Nidal Hasan on 3 December
Almanaque Digital Desk