AI-Powered ARTEX Tool Used in Cyberattacks on South Korean Banks

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

A Chinese-based hacker used the AI-powered ARTEX penetration testing tool and large language models to breach multiple South Korean banks, resulting in data theft. Following the incident, ARTEX's developer made the tool closed-source to prevent further misuse. Financial authorities are investigating the attacks.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves the use of AI systems (ARTEX and Claude Code) by a hacker to conduct cyberattacks that led to the leak of sensitive personal data, causing harm to individuals and communities. The AI systems' involvement is in the use phase, facilitating malicious activity. The harm is realized, not just potential, as personal credit information was leaked. This fits the definition of an AI Incident because the AI system's use directly led to harm (violation of privacy and potential breach of rights).[AI generated]
AI principles
AccountabilityRobustness & digital security

Industries
Financial and insurance servicesDigital security

Affected stakeholders
Business

Harm types
Human or fundamental rights

AI system task:
Event/anomaly detectionGoal-driven organisation


Articles about this incident or hazard