DataThis week in data

ARTEX bank breaches put side-door data access on the CDO's desk

An attacker using an open-source AI penetration-testing tool took data on tens of thousands of customers from seven South Korean financial firms, and got in through broker portals and employee apps instead of core banking. For data leaders, the story is about who can see which customer fields through which side system, and how quickly an automated attacker can find out.

Guarded bank entrance at night while a robotic arm reaches through a small glowing side door, pulling out data.

Listen to the podcast

10 min

Chapters

Key takeaways

  • List every system reachable from outside your network that returns customer data, including partner portals and employee mobile apps.
  • For each system, record the fields it returns and who outside the company can call it.
  • Remove any field the caller does not need, starting with income, credit limits and national ID numbers.
  • Make sure the data office is in the room when partner and broker APIs are specified, so a loan status is returned instead of a full customer profile.
  • Have your red team run an agentic penetration-testing tool against partner portals before an outsider does.
Read the full transcript

Host:Welcome back to MBA Training. ARTEX bank breaches put side-door data access on the CDO's desk, and why it matters this week. Twenty-five thousand Shinhan Bank customers had their income and loan limits taken, and the attacker never touched online banking. Where did they get in?

Expert:Through a side door built for loan brokers. UPI reported the data was exposed through unauthorized access to a service associated with loan brokers. The fields included names, telephone numbers, annual income and loan limits, as well as some resident registration numbers. Those are South Korea's national ID numbers.

Host:And it wasn't only Shinhan.

Expert:No. The Korea Times counted seven firms: Shinhan, KB Kookmin, Hana, Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital, with more than 67,000 people believed to have been affected. At KB Kookmin, according to UPI, personal and credit information belonging to 119 customers was exposed through an intrusion into an employee mobile work-support system.

Host:Bank breaches happen every month. Why is everyone in security and data arguing about this one?

Expert:Because of what CrowdStrike published on 7 October. According to Cyber Magazine, the attacker used ARTEX, an open-source penetration-testing tool developed in China. Penetration testing means attacking your own systems, with permission, to find the holes. ARTEX is "agentic", meaning it chains AI agents that plan and carry out steps by themselves. The attacker paired it with Claude Code, Anthropic's coding assistant, and with large language models, the text-generating AI systems: DeepSeek v4.1-flash as the main engine, plus GLM-5.3 and Grok 4.6.

Host:So AI hacked the banks. That's the headline.

Expert:That's the headline, and I'd push back on it. An official at the Financial Security Institute, the sector's cyber agency, told Herald Business that the AI "did not act independently without human involvement". That quote comes via American Banker. A person ran this. CrowdStrike's report, as Cyber Magazine describes it, points to a suspect who could be a 26-year-old based in China. The logs show that person prompting Claude to ask where Korean data breach information can be sold and asking for help finding Telegram groups that trade it.

Host:Then why should a data leader care more than the CISO, the chief information security officer?

Expert:Look at what got breached. UPI identified the common thread: externally connected support and lookup systems rather than core financial networks such as online banking or account ledgers. Those lookup systems exist because somebody decided a broker or a field employee needed to see a customer's income and credit limit. That's a data access design decision. In most firms it belongs to the data office, or to nobody at all.

Host:Convenient for you to say. Security budgets are security's problem.

Expert:One number cuts against that. The Korea Times reported that Shinhan, KB Kookmin and Hana together spent nearly 124 billion won ($92 million) on information security last year. Yet the latest attacks appeared to bypass such defenses by exploiting weaker links elsewhere. The money protected the front door, and the data left through an app built for loan agents.

Host:Who decided loan agents should see national ID numbers?

Expert:I don't know for each bank, and I won't guess. What American Banker reported, citing the Korean agency Newsis, is that one bank had given the recruiters, who are not bank employees, access to sensitive customer credit data, which critics called excessive. This next part is my opinion: that's the real failure. If the broker portal had returned only a loan status instead of a full customer profile, the same intrusion would have leaked far less.

Host:Let me push. Every CDO talks about data minimization on stage. Why did nobody at these banks actually do it?

Expert:Because minimization takes a feature away from someone. The broker wants the whole picture to close the loan faster. The business owner of that channel wins the argument, and the data office isn't in the room when the API gets specified. An API is the interface one system uses to query another. That's my reading of how these things usually go, not a reported fact about these banks.

Host:Fine. What did the regulator actually order?

Expert:The Financial Services Commission, Korea's financial regulator, held an emergency meeting chaired by FSC Secretary General Shin Ji-chang. According to Herald Business, the FSC directed financial firms to take stock of all IT assets and services exposed to the internet and review their security vulnerabilities and access controls. Firms also had to check for paths into internal data that skip authentication, and to share attacker IP addresses (the network addresses the attacks came from) and attack methods across the industry.

Host:The order says every externally accessible system "regardless of whether it serves customers." That phrase stood out to me.

Expert:Me too. It quietly admits that the asset list most firms keep covers the customer-facing systems. Internal tools, partner portals and the pilot app someone built for a sales team tend to fall off it.

Host:Banks pay for exactly this kind of attack testing, don't they?

Expert:American Banker points out that many banks use penetration testing to understand the weaknesses they need to address. The automation that finds holes for a paying client finds them just as well for a thief. My view: if your red team, the internal group paid to attack your own systems, hasn't run an agentic tool against your partner portals, assume an outsider will do it first.

Host:Give me the strongest case that this is overblown.

Expert:American Banker made it plainly: the attackers took advantage of what appear to be ordinary cyber hygiene failures rather than complex vulnerabilities. Read that way, AI is a footnote. My opinion is that weak authentication on side systems has been exploitable by humans for a long time. If this story pushes you to buy an "AI defense" product, you could end up skipping the boring fix.

Host:And the case against that?

Expert:Speed and reach. Cyber Magazine reports CrowdStrike found that the IP addresses linked to the hacking attempts at different financial institutions overlapped with each other. That fits one operator hitting several targets in a short window. Adam Meyers of CrowdStrike said it shows adversaries "operationalising agentic AI to move faster". The hygiene failures are old. What has shrunk is the time between a weak system going live and someone finding it.

Host:How solid are the numbers?

Expert:Not fully settled. CrowdStrike says the number of banks affected by the attacks is not yet confirmed, though South Korean authorities have confirmed intrusions at seven institutions, according to ChosunBiz. Reported totals run between 67,000 and 68,000 people, so I'd treat that as a floor.

Host:What's the real harm to customers? Nobody emptied an account.

Expert:Correct, so far. FSC Chairman Lee Eog-weon said "There is currently no indication that sensitive information that could be directly used for unauthorized payments or other financial crimes has been leaked." He also warned about voice phishing and smishing, which is phishing by text message. A name, a phone number, an income figure and a loan limit give a scammer everything they need for a convincing fake loan offer.

Host:So the risk moves from the bank's balance sheet to the customer's phone.

Expert:And from there back to the bank's reputation. That explains why the regulator widened the circle. UPI reported the Sunday meeting brought in banks, securities companies, insurers, credit finance companies, savings banks, mutual finance institutions, cryptocurrency businesses and fintech companies.

Host:Is this a Korea story, or one for someone running data at a European insurer?

Expert:The tool is public. American Banker notes that the ARTEX tool describes itself as an autonomous system driven by multiple AI agents, running on models from Anthropic or OpenAI, according to its GitHub page. Nothing about it is specific to Korea. What is specific is a regulator that acted within days. In other markets the attack may well come before the directive.

Host:Last uncomfortable one. Your CEO asks on Monday whether this could happen to you. What do you say?

Expert:That I don't know yet, and I'll have an answer by Friday. Here's this week's task. List every system reachable from outside your network that returns customer data, including partner portals and employee mobile apps. For each one, write down the fields it returns and who outside the company can call it. Then remove any field the caller doesn't need to do the job, starting with income, credit limits and national IDs.

Host:And what will you be watching?

Expert:Two things. First, whether the on-site findings confirm that the broker and employee systems lacked basic authentication, because that would settle the hygiene argument. Second, whether the confirmed count climbs past seven institutions. If it does, the side-door problem runs across the whole industry, and your board will start asking about yours.

Host:Drawn from Cyber Magazine, The Korea Times and UPI, links in the show notes. Done. Want to know where you actually stand? Take the CDO self-assessment at mba-training.com.

On 7 October, CrowdStrike published its analysis of a campaign against South Korean lenders. According to Cyber Magazine, a suspected attacker used China-developed, open-source agentic penetration-testing tool ARTEX alongside Anthropic's Claude Code. That is software that uses AI agents to probe systems for weaknesses by itself. The ARTEX instance used DeepSeek v4.1-flash as the primary backend, supplemented by GLM-5.3 from Z.ai and Grok 4.6 of SpaceXAI.

The Korea Times counted seven financial firms reporting leaks, including Shinhan Bank, KB Kookmin Bank and Hana Bank, along with Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. More than 67,000 people are believed to have been affected. According to UPI, Shinhan's information belonging to about 25,000 customers was exposed through unauthorized access to a service associated with loan brokers, including names, telephone numbers, annual income and loan limits.

Data leaders should pay attention to how the attackers got in. UPI reported that attackers appeared to focus on externally connected support and lookup systems rather than core financial networks. The Korea Times noted that the three largest banks together spent nearly 124 billion won ($92 million) on information security last year. The Financial Services Commission's response, according to Herald Business, was to tell firms to examine every externally accessible system, regardless of whether it serves customers.

The role of AI is disputed. American Banker wrote that the attackers took advantage of what appear to be ordinary cyber hygiene failures rather than complex vulnerabilities, and a Financial Security Institute official said the AI "did not act independently without human involvement". The same outlet reported that one bank had given the recruiters, who are not bank employees, access to sensitive customer credit data, which critics called excessive. On the other side, CrowdStrike's Adam Meyers argues adversaries are "operationalising agentic AI to move faster".

What to watch next: the final count, since the number of banks affected by the attacks is not yet confirmed, and follow-on fraud. FSC Chairman Lee Eog-weon warned that regulators "cannot rule out the possibility of secondary damage, such as voice phishing and smishing using the leaked data."

Finished reading?

Validate your read to earn XP and feed your radar.