Skip to content
Chinese AI Penetration Tool Traces Found on Hacking Server in South Korea's Shinhan Bank Breach

Chinese AI Penetration Tool Traces Found on Hacking Server in South Korea's Shinhan Bank Breach

Finance.Biggo • October 2, 2026

Traces of a Chinese-language artificial intelligence (AI) penetration testing tool have been discovered on a hacking server believed to have been used in the Shinhan Bank customer data breach. Security industry experts are weighing the possibility that "credential stuffing" was employed in the attack, and concerns are growing that AI-driven automation of cyberattacks is becoming a reality.

According to security industry sources on the 2nd, the string "ARTEX-自主渗透测试控制台" was identified in the HTML title of a web server used in a credential stuffing attack believed to have targeted Shinhan Bank. The phrase translates to "AI autonomous penetration testing console," indicating that ARTEX AI was operated on that infrastructure or that a related environment was utilized.

The analysis was disclosed by Moon Jong-hyun, head of the Genians Security Center, via . ARTEX AI is an open-source autonomous penetration testing system based on large language models (LLMs), primarily in Chinese, available on GitHub. It is designed to automate the entire process—from information gathering and vulnerability discovery to attack path planning, security tool execution, and vulnerability verification—using LLMs and a multi-agent architecture.

"Multiple threat analysts are reasonably suspecting that AI-based attack automation tools may have been used in this financial sector attack," he said. "On the surface, it is a tool developed to support security assessments and penetration testing," he explained, adding that "while it can serve as an efficient penetration testing tool in authorized security verification environments, if exploited by attackers, it could be repurposed as a means to enhance the automation and efficiency of actual cyberattacks."

Credential Stuffing: The Vulnerability Born of Password Reuse

Credential stuffing is an attack method in which attackers obtain username and password combinations (login credentials) leaked or stolen from other sources and repeatedly attempt them across login pages of multiple services. It exploits the fact that users reuse the same IDs and passwords across multiple sites. If account information obtained from one service works on another, the attacker can access the account through that service's normal login procedure.

Park Ki-woong, a professor in the Department of Information Security at Sejong University, likened the attack method to "duplicating a key and trying it on other doors that the same key can open."

This technique is not new. In 2017, hackers infiltrated the ID and password integrated management system "ALPass" of South Korean software company ESTsoft using credential stuffing, resulting in the leak of information belonging to 160,000 people. Damage has continued to recur recently. GS Retail was fined approximately 12 billion won (approximately $8.9 million) by South Korea's Personal Information Protection Commission in August for a personal data breach caused by credential stuffing. In January, T-money received an administrative fine after being hit by the same type of attack.

Attackers obtain account information that has been exposed through data breaches or is being illegally traded. They may also steal it directly through phishing or malware. Another method involves infecting users' devices with malware through malicious websites or documents to extract account information stored in browsers and elsewhere. The IDs and passwords obtained this way can then be used for credential stuffing attacks against other services.

AI Lowers the Barrier to Entry for Attacks

The reality that AI advancement is making cyberattacks easier could also lower the threshold for automating credential stuffing. Professor Park noted, "As 'vibe coding' with AI makes writing code easier, the barrier to entry for cyberattacks has been lowered," pointing out that attack programs can now be easily produced using AI.

ARTEX AI was introduced earlier this year as the winning project in the "Agent+" offensive and defensive capability challenge led by China's Baidu Security Response Center (BSRC). However, whether ARTEX AI was actually used in the Shinhan Bank customer data breach has not yet been confirmed. The mere discovery of the string does not conclusively prove it was used in the attack, and no official confirmation has been made through financial authorities or Shinhan Bank.

Shinhan Bank announced on the 30th of last month that it had confirmed customer information was leaked by an external unauthorized party who bypassed the identity verification process of its loan solicitation service. Security industry sources have raised the possibility that credential stuffing was used in the incident. However, the specific intrusion path and attack method remain under investigation.

Abnormal Login Detection Is the Key Countermeasure

Credential stuffing is difficult to counter because it attempts logins using legitimate IDs and passwords. Particularly in financial services, the source of leaked account information may differ from the actual service being targeted, making it critical to detect and block abnormal login attempts.

Professor Park said, "If we increase authentication procedures (to prevent credential stuffing), users will experience inconvenience, and ultimately no one will use the system," adding that "we need a defense system that closely analyzes and blocks anomalies in advance without doubling the inconvenience for customers."

South Korea's Personal Information Protection Commission, in its "2024 Personal Information Leak Reporting Trends and Prevention Methods" report published last year, proposed web server and application log analysis, detection of abnormal login attempts and IP address blocking, and the introduction of CAPTCHA as countermeasures against credential stuffing.

CAPTCHA is a technology that distinguishes whether a user is a human or an automated program, blocking indiscriminate login attempts. Additional authentication can also be required when risk indicators are detected, such as login attempts from unusual devices or locations. Users, too, should avoid using the same password across multiple services, and if account information has been leaked elsewhere, they should change the authentication credentials for any services where the same password is used.

Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.

Extracted Entities

Attack Types (1)

Companies (1)

Countries (2)

Industries (1)

MITRE ATT&CK (1)

Platforms (1)

Tools (1)