South Korea blames AI tool for bank data breaches

A Chinese AI cybersecurity tool named Artex has been connected to recent bank breaches in South Korea after its creator halted updates and access, citing abuse by attackers. The software, intended for security testing, was deployed in attacks on over 7 financial institutions, the South Korean Financial Services Commission reported. More than 68,000 individuals were affected, with Shinhan Bank confirming a leak of personal data—including names, phone numbers, and annual income—from 25,000 loan applicants.
The developer, using the pseudonym Autumn-27, posted on GitHub that Artex would transition to closed-source and no longer receive updates. “Given the misuse of the tool, the Artex project will no longer be updated and will be converted to closed-source,” the message stated, adding that future versions would not be released to the public, nor would maintenance support be provided. This decision followed South Korea’s government attributing the attacks to Artex with “high probability,” though the developer did not address the claims directly. US cybersecurity firm CrowdStrike traced the hacker to a 26-year-old Chinese speaker acting for financial gain.
The firm’s analysis indicated the attacker exploited Artex’s features to evade security measures. While restricting access may limit new users, experts warn that copies of the open-source code already exist. “Because the code was public, people could download it, change it and run it themselves,” said Poe Zhao, founder of Hello China Tech. “The developer could ask users to follow the rules, but had little control over their actions,” he added.
Ilya Kulyatin, CEO of Foundry Labs and founder of the Tokyo AI tech community, said users of open-source programs can “remove restrictions built into the tool,” which “makes certain forms of misuse easier.” Open-source programs like Artex allow security researchers to study and improve protections. “But openness also benefits defenders: researchers can inspect the code, identify weaknesses and improve protection,” he said. South Korean President Lee Jae Myung highlighted the growing threat of AI-driven cyberattacks, noting their expanding scale and impact beyond finance. In Japan, around 20 companies reported potential data breaches, though authorities have not confirmed a direct link to Artex.
Police chief Yoshinobu Kusunoki said the damage was spreading across all areas on a scale that is difficult to compare with the past. The Artex developer’s shutdown shows the conflict between open-source collaboration and misuse risks. While the tool aimed to help organizations detect vulnerabilities, its open nature enabled attackers to adapt its functions. Moving to closed-source prevents new downloads or modifications, but existing copies remain accessible. Experts emphasize that once code is public, enforcing responsible use is nearly impossible.
The developer’s acknowledgment of abuse without addressing specific incidents reflects the challenges of accountability in open-source projects. South Korea’s Financial Services Commission has not disclosed whether additional institutions were breached beyond the seven confirmed. Investigators are also examining whether the attacks followed a shared pattern, such as exploiting specific banking system flaws. The commission urged financial firms to audit security protocols, particularly those relying on third-party penetration-testing tools. Separately, China and the European Union agreed to strengthen trade talks, with Beijing promising to ease exports of rare earths and permanent magnets to the bloc.
The joint statement marked progress on export controls, with both sides reiterating the need to further strengthen the dialogue on export controls between China and the EU. China is willing to continue facilitating the approval of export licenses for rare earths and permanent magnets destined for the EU. The two sides also reached an understanding on trade in hybrid vehicles, committing to procedures under World Trade Organization rules. In Asia, Malaysia declared an environmental emergency after haze from Indonesian forest fires enveloped cities, including Kuala Lumpur.
Schools in four states and two federal territories closed as air quality readings exceeded 150 on the Air Pollutant Index, surpassing the “unhealthy” threshold. Sultan Ibrahim endorsed the closures due to health risks, while Prime Minister Anwar Ibrahim called on Indonesia to act urgently. Regional leaders prepared for an ASEAN meeting to address the crisis, and Singapore’s air quality also deteriorated, reaching “very unhealthy” levels with readings of 205 on the Air Quality Index.