Seven Banks in Days: When AI Offense Economics Go South
South Korea’s financial-sector attacks exposed familiar vulnerabilities. Evidence linking Chinese autonomous offensive tooling to the attacks points to a bigger concern: target-specific exploration becoming cheap enough to scale across many organizations at once.
Alt Security
By October 4, seven South Korean financial institutions had reported information exposure amid a wave of cyberattacks: Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. Other institutions reported attempts that were blocked. Regulators called emergency meetings and directed security checks across roughly 500 financial companies.

Investigators identified shared attacker IP infrastructure across several bank incidents. Infrastructure differed in the savings-bank and capital-company attacks, although techniques were similar. Whether all seven incidents share one attacker remains under investigation. Authorities assess that AI tools were used to automate attacks against numerous financial targets.
The speed and breadth of the campaign are notable. But the ARTEX evidence raises a more consequential question: what happens when persistent, target-specific exploration becomes cheap enough to repeat at scale?
The ARTEX connection
Researchers examining a web server suspected of involvement in the Shinhan attack found an HTML title containing “ARTEX 自主渗透测试控制台”, meaning “ARTEX Autonomous Penetration Testing Console.” Financial-security officials subsequently reported ARTEX traces on infrastructure associated with attacks against banks.

ARTEX is a Chinese-developed, open-source autonomous penetration-testing system. Its public repository documents agent management, asset and exploration views, tool execution, traffic recording and configurable LLM connections. Together, those components provide the harness for an agent to maintain context, coordinate tools and continue exploring a target across multiple steps.
The timeline shows how closely public recognition and suspected misuse followed one another:
- July 27: ARTEX is publicly launched on GitHub by its developer as an open-source autonomous penetration-testing system.
- August 13: Baidu Security Response Center formally announces its “Agent+” offensive-security challenge.
- September 3: ARTEX reportedly wins the final.
- October 2: ARTEX evidence is publicly reported on infrastructure linked to the Shinhan attack.
- October 4: South Korean authorities report seven affected financial firms, shared attacker infrastructure and suspected AI-driven mass automation.
Competition dates come from the organizer’s published recap; incident developments come from Korean reporting.

Within a month of its competition win, ARTEX had surfaced in reporting about real attack infrastructure.
It is important to note that public findings do not yet establish whether ARTEX discovered the exploited vulnerabilities, executed the intrusions, or which underlying model was used.
The economics of attacker attention
The reported weaknesses were familiar: missing authentication, inadequate access controls and known web vulnerabilities in employee tools, loan-broker services and support systems. Authorities reported no disruption to internet or mobile banking and no financial losses at that point.
Autonomous offensive systems can reduce the effort required to investigate such exposures. Agents coordinate tools, retain findings and use each result to guide the next attempt. Work that once demanded sustained human attention can become cheaper to repeat across more targets.
The South Korean incidents do not tell us exactly how much time AI saved, nor do they establish that every affected institution was targeted by the same actor. But the pattern matters: multiple financial firms were affected within days, additional attempts were blocked, and authorities described AI-driven automation across numerous targets.
AI is making target-specific offense scalable across many organizations at once. An operation that once had to concentrate human attention on a small number of organizations can increasingly explore many targets across the same sector, persistently and in parallel. The seven confirmed incidents may therefore matter less as a final count than as evidence of how broad the search can become.
Implications for defenders: close paths, not just tickets
If attacker attention becomes cheaper, defenders cannot assume obscure systems will remain obscure. The question is no longer simply whether a weakness exists, but what an attacker can reach through it, which weaknesses can be chained into viable paths, and where remediation will break those paths.
The measure of progress is not how many findings enter or leave the backlog. It is how quickly exploitable paths are closed and verified.
Our report, The Evolution of AI-Enabled Cyber Offense, explores how scaffolding and falling costs turn model capabilities into persistent campaigns, and how defenders can close the paths that matter before attackers complete them.