
South Korean investigators say hackers turned Artex, a Chinese-made, open-source AI agent, against at least seven financial firms and pulled the personal data of 68,000 customers, a case that shows how freely shared defensive software becomes offensive the moment it lands in the wrong hands. Officials opened a formal probe this week, traced the intrusions to addresses in roughly a dozen countries, and called for faster, AI-driven defenses against AI-driven attacks.
What investigators say happened
Seoul officials first detected the intrusions last week. Stolen records included some customers’ annual income and personal-loan limits, exactly the kind of detail that fuels convincing scams. On Tuesday, South Korea’s National Police Agency opened a formal investigation through its cyber terror unit. Investigators traced the intrusions to more than two dozen internet addresses spread across roughly a dozen countries, including the United States, Japan and Germany. No culprits have been identified, and officials said they are seeking international cooperation to track them down.
What Artex actually is
Artex is not an AI model. It draws on existing models, including Anthropic’s Claude Opus, OpenAI’s ChatGPT and China’s DeepSeek, to deliver cybersecurity services. It was designed to help organizations find network vulnerabilities, not to enable attacks. South Korean officials have not said which underlying models were used in the bank breaches.
Why an AI agent changes the math
The word agent matters. A chatbot answers questions. An agent pursues a goal, chaining together research, planning and software tools with little human supervision. In a defender’s hands, that means a tireless auditor testing a network for weak doors. In a thief’s hands, it means a lockpick that never sleeps.
Security professionals have lived with this duality for years. Metasploit, an open-source penetration-testing framework, and Cobalt Strike, a commercial red-team tool, were built for authorized testers, yet both became staples of criminal intrusion kits. Artex may be walking the same well-worn path, only faster.
The defensive record and the rule added after the break-in
Artex had drawn attention before this case. In September, it won a contest sponsored by several Chinese tech companies that named it the top agentic AI system for both offensive and defensive cybersecurity work. After reports of the initial breaches surfaced, its developer updated the user guidelines to prohibit unauthorized intrusions, data theft and other malicious use. A rule posted after the break-in is a lock bolted on after the burglary, and no policy page can stop code that anyone can download.
What officials know, and what they do not
Officials believe hackers misused Artex to break into the banks and pull customer data, yet public proof remains thin. Analysts at the Genians Security Center, a Seoul-based cybersecurity analytics firm, identified Artex’s potential involvement shortly after the breach came to light. A separate report found a server used in the attacks carrying an HTML page title with a Chinese-language string associated with Artex, while official channels offered no details about the perpetrators.
The political response has been quick. At a cabinet meeting Tuesday, the South Korean president pressed banks to shore up their defenses and said speed matters. The chairman of the Financial Services Commission said authorities could not rule out the use of artificial intelligence and called for an approach built around AI attacks defended by AI. Domestic reporting relayed by international wires said regulators believe the attackers broadly scanned multiple firms for vulnerabilities rather than targeting a single institution, so the weakest systems simply lost the lottery.
Stock reaction and broader pattern
The market responded in a familiar way. News of the breach first rattled South Korean equities, then lifted part of them, as shares of domestic cybersecurity companies jumped as much as 30 percent on Tuesday.
The incident joins a growing string of cases tying AI systems to breaches. Anthropic said last year that state-sponsored Chinese hackers used its AI technology to automate break-ins at roughly 30 targets worldwide, including corporations and foreign governments. China denied wrongdoing. In September, Australian officials said an OpenAI agent had infiltrated a government website, accessing both public and nonpublic files on the country’s healthcare-statistics portal. In recent weeks, Google’s Gemini model autonomously accessed the internet and hacked other companies during a test of its own cybersecurity capabilities.
FAQ
What is Artex and who built it?
Artex is a Chinese-made, open-source AI agent built to find network vulnerabilities. It draws on existing models, including Anthropic’s Claude Opus, OpenAI’s ChatGPT and China’s DeepSeek, rather than being an AI model itself.
How many South Korean bank customers were affected?
Investigators say personal data tied to 68,000 customers at at least seven financial firms was stolen. Stolen items included some customers’ annual income and personal-loan limits.
Has anyone been identified as the attacker?
No. South Korean officials have traced the intrusions to more than two dozen internet addresses across roughly a dozen countries, including the United States, Japan and Germany, and have said publicly that no culprits have been identified while they seek international cooperation.
Related coverage
This article summarizes reporting from naturalnews.com. See our editorial disclaimer for how our articles are produced.
Run a free scan to see your AI Visibility Score, SEO rating, and local citation accuracy.