Hackers used a Chinese artificial-intelligence agent to attack South Korea's biggest banks and steal the personal information of 68,000 people, officials said, marking one of the first such AI-powered intrusions into the global financial system.
Investigators in Seoul said the attacks, initially detected last week, hit at least seven South Korean financial firms and showed traces of a cybersecurity tool called Artex AI that was developed in China. The National Police Agency's cyber terror unit said Tuesday it had opened a probe into the breach.
The attacks were the latest to highlight the vulnerability of even hardened targets to hackers using freely available AI tools. In previous cases, governments and nonfinancial corporations were hit, but it is unusual for banks to fall victim to hackers assisted by AI agents.
Anthropic last year alleged that state-sponsored Chinese hackers used Anthropic's AI technology to automate break-ins of roughly 30 global targets, including corporations and foreign governments. China at the time accused the U.S. of using cybersecurity to smear and slander Beijing.
In other cases, leading American models have gone rogue and infiltrated outside websites without humans' knowledge. Australia in September said an OpenAI agent infiltrated a government website to gain access to both public and nonpublic files in the country's healthcare-statistics portal. In recent weeks, Google's Gemini model autonomously accessed the internet and hacked other companies during a test of its cybersecurity capabilities.
Artex is an open-source AI agent developed by Li Puhua, a Chinese cybersecurity engineer who uses the alias Autumn. Open-source means it is free to download and adapt. The agent isn't itself an AI model but instead draws on AI models to deliver services, like an insurance agent who doesn't personally insure a home or car but helps homeowners get coverage from insurance companies.
Li designed Artex specifically for cybersecurity uses, aiming to help organizations identify vulnerabilities in their networks. In this case, however, South Korean officials believe malicious hackers used the tool to get into the banks' systems and steal data of customers and employees.
Officials haven't identified any culprits and said they were seeking international cooperation in the probe. The attacks originated from more than two dozen internet addresses in roughly a dozen countries, including the U.S., Japan and Germany, they said.
The stolen data included annual income and personal-loan limits of some customers -- information that could be sold to scammers or otherwise traded on the web.
After reports of the first bank breaches emerged, Artex updated its user guidelines to specify that the tool must not be used for unauthorized intrusions, data theft or other malicious reasons.
South Korean authorities called on banks to harden their systems.
"Speed is of the essence," President Lee Jae Myung said at a Tuesday cabinet meeting. "Implement the necessary measures immediately." Shares of South Korean cybersecurity companies surged by as much as 30% Tuesday.
"Cybersecurity attacks powered by AI agents have been increasing in South Korea, and I expect they will grow in number worldwide in the future," said Mun Chong-hyun, who heads Genians Security Center, a Seoul cybersecurity analytics firm. Mun identified Artex's potential involvement shortly after the bank data breach came to light.
Agents such as Artex allow users to select AI models such as Anthropic's Opus, OpenAI's GPT and China's DeepSeek. These agents draw on the models to autonomously discover vulnerabilities and plan attack routes. Often they require minimal human intervention.
South Korean officials didn't say which AI models were used in the bank attacks.
Artex earned notice in China in September when it won a contest sponsored by several Chinese tech companies to identify the top agentic AI system for offensive and defensive cybersecurity capabilities.