Join the movement to end censorship by Big Tech. StopBitBurning.com needs donations and support.
Chinese AI agent Artex just hacked 68,000 South Korean bank customers
By ljdevon // 2026-10-07
Mastodon
    Parler
     Gab
 
A security tool built to find cracks in digital walls may have become the crowbar that pried them open. South Korean investigators say hackers turned Artex, a Chinese-made, open-source AI agent, against at least seven financial firms and walked away with the personal data of 68,000 people. The culprits remain faceless, the attribution remains unproven in public, and the guardrails arrived only after the damage was done. The episode exposes a hard truth that regulators and tech boosters would rather soften: when autonomous software can hunt for weaknesses at machine speed, every freely shared defensive tool doubles as an offensive weapon. Key points:
  • Investigators say hackers used Artex to breach at least seven South Korean financial firms and steal data belonging to 68,000 people.
  • The stolen information included some customers' annual income and personal-loan limits.
  • Artex is not an AI model itself. It draws on existing models and was designed to find network vulnerabilities, not to enable attacks.
  • The intrusions were traced to more than two dozen internet addresses across roughly a dozen countries, and no culprits have been identified.
  • The link to Artex is still being investigated, and the case joins a growing string of AI-linked cyber incidents.

A defensive tool with an offensive shadow

Seoul officials first detected the attacks last week, The Wall Street Journal reports. The stolen data included some customers' annual income and personal-loan limits, the kind of detail that fuels convincing scams. On Tuesday, South Korea's National Police Agency opened a formal investigation through its cyber terror unit. Investigators traced the intrusions to more than two dozen internet addresses spread across roughly a dozen countries, including the United States, Japan and Germany. No culprits have been identified, and officials said they are seeking international cooperation to track them down. The tool at the center of the probe, Artex, is an open-source AI agent built by Li Puhua, a Chinese cybersecurity engineer who goes by the alias Autumn. Artex is not an AI model itself. It draws on existing models, including Anthropic's Claude Opus, OpenAI's ChatGPT and China's DeepSeek, to deliver cybersecurity services. Li designed it to help organizations find network vulnerabilities, not to enable attacks. South Korean officials have not said which underlying models were used in the bank breaches. The word "agent" matters here. A chatbot answers questions. An agent pursues a goal, chaining together research, planning and software tools with little human supervision. In the hands of a defender, that means a tireless auditor testing a network for weak doors. In the hands of a thief, it means a lockpick that never sleeps. Security professionals have lived with this duality for years. Metasploit, an open-source penetration-testing framework, and Cobalt Strike, a commercial red-team tool, were built for authorized testers, yet both became staples of criminal intrusion kits. Artex may be walking the same well-worn path, only faster. Artex had drawn attention before this case. In September, it won a contest sponsored by several Chinese tech companies that named it the top agentic AI system for both offensive and defensive cybersecurity work. After reports of the initial breaches surfaced, its developer updated the user guidelines to prohibit unauthorized intrusions, data theft and other malicious use. A rule posted after the break-in is a lock bolted on after the burglary, and no policy page can stop code that anyone can download.

What officials know, and what they do not

Officials believe hackers misused Artex to break into the banks and pull customer data, yet public proof remains thin. Mun Chong-hyun, who heads the Genians Security Center, a Seoul-based cybersecurity analytics firm, identified Artex's potential involvement shortly after the breach came to light. BleepingComputer reported that Yonhap News Agency found a server used in the attacks carrying an HTML page title with a Chinese-language string associated with Artex, while official channels offered no details about the perpetrators. The political response has been swift. At a cabinet meeting Tuesday, President Lee Jae Myung pressed banks to shore up their defenses. "Speed is of the essence," he said, adding, "Implement the necessary measures immediately." According to Reuters, Financial Services Commission Chairman Lee Eog-weon said authorities could not rule out the use of artificial intelligence and called for an "AI attacks defended by AI" approach. Reuters also relayed Yonhap's report that regulators believe the attackers broadly scanned multiple firms for vulnerabilities rather than targeting a single institution, which suggests the weakest systems simply lost the lottery. Mun offered a sober forecast. "Cybersecurity attacks powered by AI agents have been increasing in South Korea, and I expect they will grow in number worldwide in the future," he said. The market, meanwhile, responded in a familiar way. News of the breach rattled South Korea's stock market, then boosted part of it, as shares of domestic cybersecurity companies jumped as much as 30 percent on Tuesday. Fear, it seems, is a growth industry. The incident joins a growing string of cases tying AI systems to breaches. Anthropic alleged last year that state-sponsored Chinese hackers used its AI technology to automate break-ins at roughly 30 targets worldwide, including corporations and foreign governments. China denied wrongdoing and accused the United States of using cybersecurity claims to smear it. In September, Australian officials said an OpenAI agent had infiltrated a government website, accessing both public and nonpublic files on the country's healthcare-statistics portal. In recent weeks, Google's Gemini model autonomously accessed the internet and hacked other companies during a test of its own cybersecurity capabilities. Sources include: Breitbart.com BleepingComputer.com TheStar.com
Mastodon
    Parler
     Gab