Han Seong-sook said South Korea’s seven major financial institutions were hit last week in breaches that investigators tied to artex traces in bank logs. The warning now points beyond a one-off bank incident, because the same playbook may be able to reach government and public systems too.
Han Seong-sook’s Tuesday warning
At a Cabinet meeting on Tuesday, she said, “This is a serious situation because this incident is believed to have taken advantage of artificial intelligence, and if AI is used in phishing attacks, it could lead to secondary damage.”
She added, “It is also a serious situation in that similar hacking methods could spread beyond the financial sector to industries, as well as government and public sectors.”
She also urged agencies and companies to “remain vigilant.”
ARTEX traces in bank logs
Investigators found traces of ARTEX in the bank logs, and ARTEX was described as an open-source autonomous penetration-testing agent built by a Chinese developer. The tool was said to be freely available on the internet, which makes its presence in the logs a clue rather than proof of who sat behind the keyboard.
Aditya Das said, “It is freely available on the internet and officials have said explicitly that a Chinese-built tool doesn't mean Chinese attackers,” and he described the use of multiple IP addresses as “a ploy by the hackers to hide their tracks.”
28 IP addresses across countries
The Financial Supervisory Service said it identified 28 internet protocol addresses involved in the bank breaches, with addresses in the United States, Japan, Germany and at least 10 other countries. That spread makes attribution harder, because the traffic trail now runs through multiple jurisdictions instead of one obvious source.
South Korean media reports said as many as 68,000 customers may have had data taken, including names, phone numbers, annual income figures, loan limits and loan products. Shinhan Bank, KB Kookmin Bank and Hana Bank were among the worst affected banks.
What the leak exposed
The attackers appeared to have exploited weak authentication protocols in portals used by external loan recruiters, employees’ mobile tools and sales-support systems. That means the exposure was not limited to one front door, and banks that leave those systems loosely guarded are likely to stay exposed even after the first breach is patched.
On Wednesday, two of the largest churches in South Korea and Korea Electric Power Corp. said their online systems had also been illegally accessed. The sequence suggests the bank case may sit inside a wider wave, not a single isolated intrusion.
The next question is who was actually behind the bank breaches, and what exact role ARTEX played in them, because the logs point to a tool and multiple IP addresses but not yet to one responsible actor.







