For two years the industry argued about whether AI would meaningfully change offensive security or simply write better phishing emails. The attacks on South Korea's banking sector at the start of October have moved that argument on, though not in the direction most of the predictions pointed.
What happened
Between late September and early October 2026, six South Korean financial institutions reported breaches: Shinhan Bank, KB Kookmin, Hana Bank, BNK Busan, Yegaram Savings Bank and Hyundai Capital. The data exposed included names, phone numbers, annual income figures and loan limits, and in some cases resident registration numbers — the Korean equivalent of a national ID. More than 144,000 customers were affected, and some systems were taken offline. The government convened an emergency meeting demanding immediate remediation.
The operator appears to have been one person.
According to CrowdStrike's analysis, they used ARTEX — an open-source agentic penetration-testing suite that automates reconnaissance, vulnerability discovery, attack-path planning and exploit verification — alongside Claude agents. The ARTEX deployment ran DeepSeek's model as its primary backend, supplemented by Zhipu AI's GLM and xAI's Grok.
That mix matters more than it looks. This is not a problem with one company's model. Once the orchestration layer is open source and the model behind it is swappable, restricting any single provider relocates the work rather than preventing it. ARTEX's developer responded by taking the project closed source, saying the attacks had nothing to do with the tool's intended purpose — but English and Korean derivatives were already circulating.
The operator was eventually identified through carelessness rather than forensics. They left Claude session histories, ARTEX configuration files and agent memory files sitting in open web directories. Among the exposed material, researchers found a résumé generated with the same tooling. CrowdStrike was careful to note the resulting attribution is not reliable enough to be definitive.
A note on the Mexico comparison
Most coverage of this incident reaches for a precedent: the claim that a single operator used AI agents to breach nine Mexican government agencies earlier in 2026. We would treat that comparison carefully. That account comes from a single vendor report, the named agencies have publicly denied it, and a far more ordinary explanation — an exposed federal API returning citizen records to anyone who asked — is on the table. We went through it in detail in 2.3 Terabytes: Mexico's Citizen Records and the Systems Nobody Owned.
The Seoul intrusions are a different kind of evidence. There are named victim institutions that have acknowledged breaches, a regulator responding in public, and an independent technical analysis built on the attacker's own exposed working files. That is why this post is about Seoul.
What actually changed
Not the techniques. The campaign did not require a zero-day. It relied on exposed, peripheral systems — the subsidiary portal, the service nobody owns any more, the host that never made it onto the asset register. These are the same weaknesses that have been on every assessment report for twenty years.
The tempo. Reconnaissance, enumeration, exploit development and exfiltration used to be the slow parts of an intrusion, and that slowness was a defensive asset. It was the window in which an alert got read and a patch got applied. Agentic tooling compresses it. One person now covers ground that previously took a coordinated team.
The economics of target selection. When reconnaissance is expensive, attackers prioritise. When it is close to free, there is no longer any reason to skip the small target, the dormant subdomain or the subsidiary nobody remembers acquiring. "We are too small to be worth the effort" was always a weak argument. It is now close to meaningless, because there is barely any effort to weigh.
Guardrails are a speed bump. Where commercial models were involved, they did something — refusing, flagging, pushing back. They were also worked around, and the operator simply moved tasks to models that did not object. Guardrails are worth having. They are not a control you get to rely on, and they are not your security programme.
What this means for your defences
The practical implications are, frustratingly, the same fundamentals. The margin for leaving them undone has narrowed.
Find what is exposed before an agent does. The campaign succeeded against peripheral infrastructure. An accurate, current inventory of everything of yours reachable from the internet — including the systems inherited, inherited again and never decommissioned — is the highest-value exercise available. You cannot defend what is not on the list.
Shorten the patch window on anything internet-facing. Automated discovery means the gap between a vulnerability becoming public and your exposure being found is now measured in hours.
Assume reconnaissance is continuous and automated. Scanning and enumeration against your perimeter should be logged and should produce signal. In a campaign of this shape it is one of the few early indicators you get.
Treat decommissioning as a security task. Switched off is a different state from forgotten, and only one of them is safe.
Keep a human in the approval path. The thread running through this is that autonomy without a checkpoint is the dangerous property — and it applies on both sides. Defensive AI is genuinely useful for the volume problem: triaging alerts, correlating signals, drafting the remediation. It should not be making changes to your environment on its own judgement. Our position is that AI should prepare the fix and wait for a person to approve it, which is how the AI layer in our stack is built. An agent that can act unsupervised is a capability, and capabilities get turned around.
The honest conclusion
Nothing in this campaign would have surprised a security team in 2015. Exposed services, unpatched systems, forgotten platforms, data where it should not be. What has changed is that exploiting all of it at once is now within reach of one motivated person with a laptop and a subscription.
The defensive fundamentals have not changed. The cost of neglecting them has.
Sources
- ARTEX AI, Claude agents used in cyberattacks on South Korean banks — BleepingComputer
- ARTEX AI pentesting tool used in data theft attacks on South Korean financial firms — The Hacker News
- CrowdStrike finds possible bank hacker's CV among exposed AI logs — The Register



