decrypted · 5 october 2026 · ransomware and cybercrime · vulnerabilities and patching · ai and llm security
Seven Korean lenders breached through side doors, with an AI tool suspected
South Korea's president has ordered a full investigation after seven financial firms reported data leaks in four days, and officials say they cannot rule out that AI did much of the work. It is a story about Korean lenders, but the lesson lands squarely on any UK organisation that lets suppliers and sales partners reach its systems.
What happened
According to the Korea Times, Shinhan Bank, KB Kookmin Bank, Hana Bank, Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital have all reported leaks since Thursday. More than 67,000 people are believed to be affected. The exposed data includes names, contact details, resident registration numbers, annual income and loan limits.
The Financial Services Commission's chairman, Lee Eog-weon, said there is currently no indication that data directly usable for unauthorised payments has leaked, but warned of follow-on voice phishing and smishing. Reported figures per firm differ between outlets, so treat exact counts with caution.
The door they used
The attackers did not go near the core banking systems. Reporting says they hit systems used by employees, outside contractors and loan agents, and that credential stuffing, which means replaying passwords stolen from other breaches, was involved. Investigators found traces of ARTEX AI on a server used in the attacks. It is a Chinese-language, open-source tool for autonomous penetration testing. Officials noted that this does not necessarily point to a Chinese origin, and no perpetrator has been named. The AI link is suspicion, not proof.
Think of a bank as a building with a strong vault and a dozen side doors for tradespeople. A human burglar tries a few doors and gives up. An automated one tries every door, every night, patiently, and does not need paying. The vault never mattered, because the side door opened onto the same corridor.
What a defender sees
Nothing dramatic. Failed logins spread across many accounts, repeated probing of the same partner portals, and valid credentials used from odd places. The useful signal is volume: one account pulling thousands of records is never a loan agent doing their job. JoongAng Daily reports that detection took between about 15 and 68 hours at three of the large banks. At machine speed, that is a very long time.
The Secure by Design lesson
Three design decisions would have blunted this, and none involves AI detection:
- Phishing-resistant sign-in on every external portal. Replayed passwords are useless when a passkey or hardware key is required. This is the cheapest control here.
- Partner access scoped to the job. A loan agent's portal should not return a customer's income and identity number in bulk. Limit what one account can pull, and alert on volume.
- Collect less. Data you never held cannot leak. Identity numbers sitting in sales-support tools are a design choice, not an accident.
For UK boards, the practical question is simple: list every system a supplier, broker or contractor can log into, and ask who last checked it. That list is usually longer than anyone expects.
What it costs
Less than the clean-up. Hardware keys for external users are a modest cost per head, and tighter data scoping is mostly a design review. The expensive part is the awkward conversation with suppliers, and that conversation is cheaper before an automated tool starts it for you.
Also this week
Dell System Update, patched. Dell fixed five flaws in its System Update tool on 1 October, led by CVE-2026-86360, a path traversal bug rated CVSS 9.6 that could give an unauthenticated remote attacker root code execution. Four further flaws were rated high, including two privilege escalation bugs, CVE-2026-86361 and CVE-2026-86362. All versions before 2.3.0.0 are affected, and Dell's advisory is DSA-2026-324. No exploitation or public proof of concept has been reported. The tool runs with elevated privileges on PowerEdge servers, which is why Dell rates the overall impact as critical. Tools that run as root on servers deserve the same patch urgency as the servers themselves.
MetaMask's unexplained incident. MetaMask said on 30 September it was responding to an ongoing security incident affecting part of its infrastructure, and began pulling its Ethereum validators out of the Lido staking protocol, with the last due out by the end of 7 October. It says it has identified no immediate threat to wallets. It has not said what was compromised or how, so everything beyond that is unverified. Exited ETH can take up to 45 days to return, so the disruption outlasts the headlines. The design question is concentration: when one provider runs validators, keys and infrastructure together, a single intrusion forces a mass exit. Any UK firm holding crypto through a third party should ask that provider the same questions.
Sources
- Korea Times: AI-powered attacks on banks expose technological lag in Korea's financial cyber defenses
- Korea JoongAng Daily: From banks to lenders, suspected AI hacks expose cracks in Korea's financial defenses
- BleepingComputer: South Korea probes bank breaches amid suspected AI-powered attacks
- BleepingComputer: New Dell System Update flaw lets hackers gain root privileges
- Security Online: Dell System Update flaw CVE-2026-86360 could allow root code execution
- Decrypt: MetaMask exits Lido validators amid infrastructure security incident
If you want help working out who can log into your systems from outside, get in touch.
More like this
- A 16-year-old's ransomware gang ran on unlocked doors 2 october 2026
- ShinyHunters walks round the PeopleSoft firewall fix with one character 28 september 2026
- Citrix's NetScaler has two zero-days and no patch yet 27 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.