BleepingComputer · Oct 5
South Korea is investigating bank breaches that analysts suspect used AI attack tools
South Korea's Financial Services Commission held an emergency meeting after breaches at Shinhan Bank and KB Kookmin Bank and a limited breach at Hana Bank, with local media reporting data on 25,000 Shinhan customers leaked. Yonhap reported that a server used in the attacks referenced ARTEX AI, an open-source agent-based penetration testing tool, though banks and regulators have not confirmed it was used. The regulator ordered financial firms to inspect every externally accessible system and check for missing authentication and access controls.
▸ The MSP Angle
How do I prepare clients for AI-automated attacks on their systems?
Automated attack tools find exposed systems and weak sign-ins faster than a human team, so the regulator's checklist is the right one for any client: list everything reachable from the internet, including internal tools nobody thinks of as public, and confirm each one requires authentication. Shut down what is not needed, put the rest behind MFA or a VPN, and run that review quarterly instead of once a year.