Lee says AI cannot be ruled out after the same address hit seven Korean financial firms
Financial Services Commission chair Lee Eok-won said an AI-assisted attack could not be ruled out after breaches at seven firms. Shinhan reported about 25,000 people affected and Yegaram Savings Bank about 40,000. Investigators found one IP address across the firms and traces of the Artex testing tool.

Seoul3 min read
Last updated
Lee Eok-won, chair of South Korea's Financial Services Commission, said on Sunday that an attack using artificial intelligence could not be ruled out after breaches and intrusion attempts at seven financial firms. Investigators found the same internet address across the firms that were hit, and other traces pointed to Artex, a Chinese-developed tool built for penetration testing.
The largest reported exposures are at Shinhan Bank, about 25,000 people, and Yegaram Savings Bank, about 40,000. KB Kookmin Bank reported 153 people affected. Hana Bank reported 89. Hyundai Capital reported 146. Welcome Savings Bank reported 2,200. BNK Busan Bank reported 11 outsourced workers. Woori Bank and NH NongHyup Bank said they detected attempts and blocked them, with no data taken. The Korea Herald's count of firms with confirmed exposure, set against the two that blocked the traffic, is the shape of the campaign: one address, several doors, uneven results.
The FSC called an emergency meeting with industry leaders on Sunday and told firms to cut external access to systems unless the access is required for business. Lee told the sector to keep the highest level of watch. That order is operational. It does not identify a suspect, and it does not say a model wrote the exploit. It says the commission will not exclude an AI-assisted method while the same address and an AI testing platform appear in the traces.
What the shared address does and does not prove
A single IP address across seven firms is evidence of coordination or of a shared relay, not of a named person. Attackers rent addresses. A penetration-testing platform such as Artex can be used by a security team or by someone who is not one. The Herald reported that authorities suspect one attacker used an AI-powered tool to try several firms at once. That is the investigators' working view, not a charge. The useful public fact is narrower: the same address, the Artex trace, and a chair who has said AI cannot be ruled out.
The customer numbers are uneven for a reason. A savings bank with 40,000 records and a major commercial bank with 153 are not the same kind of breach, even if the address matches. The savings-bank figure is the one that moves the incident from an attempted intrusion into a notification problem. Shinhan's 25,000 is the other. Kookmin's 153 and Hana's 89 are smaller files at larger banks. Busan's 11 outsourced workers suggest a contractor path rather than a core ledger. Read together, the list looks like a scan that found different quality of lock, not a single vault emptied seven times.
Regulators have answered with access control rather than a public attribution. Blocking external connections unless they are essential is a blunt weekend instruction. It slows payment links, vendor tools and remote work. It is also the fastest way to cut a live address out of the network while the forensic work continues. Lee's AI remark raises the watch level for tools that can try many logins or many firms without a large team. It does not require the public to treat every failed login this week as a machine campaign.
Korean banks were already under notice after a run of incidents this year. Sunday's meeting puts seven names on one page and gives the commission a sentence it can repeat: AI is not excluded. The next useful disclosure is whether the shared address is still live, whether Artex was the tool or only present on a machine in the chain, and whether the 40,000 Yegaram records and the 25,000 Shinhan records are account files, contact files, or both. Until those distinctions are published, the incident is a coordinated intrusion with a known address and an open question about the tool, not a confirmed AI theft of any named sum.
Customers at the firms on the list have a practical step that does not depend on that question. If a bank has notified them, the notice is the document that says which data moved. The FSC instruction to the firms is about the door. Lee's sentence is about the method the door may have been tried with. Those are three different facts, and only the first two are settled.
Continue reading
- News
WHO tells contacts the Irkutsk death looks low-risk for the wider public
Almanaque Digital DeskGeneva
- News
Hundreds march on Cornell's Day Hall after a fraternity rape report
Almanaque Digital DeskIthaca
- News
Iyer's India open the Lucknow T20 series tonight after a West Indies chase of 352
Almanaque Digital Desk