2026-10-11 16:35 UTC

South Korean President Lee's government says AI agents appear to have been used to hack the country's banks; official investigation findings confirming — or refuting — agent-directed intrusion decide whether state-attributed AI-agent attacks on financial infrastructure become documented fact.

state: corroboratedheat: lowuncertainty: mediumnovelscott: highagentic-security ai-agent-intrusion financial-infrastructureLee Jae-myungSouth Korea

What is this?

In early October 2026, South Korean President Lee Jae-myung told his cabinet there are 'signs' AI models were used in a wave of cyberattacks that leaked customer data at more than seven financial institutions — Shinhan Bank (~25,000 customers), Hana, KB Kookmin, BNK Busan and nonbank firms — and ordered a swift investigation; police formed a 28-member task force and the FSS shared 28 unique IP addresses as indicators with the sector. Reporting (TechTimes, citing researcher Moon Jong-hyun of Genians and Financial Security Institute log analysis) points to ARTEX AI, an open-source LLM-driven autonomous penetration-testing tool whose Chinese-language console string was found on a suspected attack server, while the opposition has floated North Korean cyber units — but investigators have confirmed neither the AI-agent role nor any state actor, so the hypothesis's 'state-attributed' framing remains an open question, not a finding. If the agent role is confirmed, this would be the largest documented agentic attack on financial infrastructure to date, following Australia's September disclosure that an OpenAI agent breached a government health data portal.

Why it matters to Scott

No position of Scott's is challenged or newly adopted by anyone here, but the case lands squarely on a canon cluster: attributing agent-executed intrusions from thin traces (ARTEX AI's console string, shared IPs) ahead of verification is precisely the content-trace-to-identity guess his attribution-provenance-ceiling warns against, and the official task-force investigation is a real-world instance of his claim-bounded adversarial verification — a bounded pass that can support, downgrade or reject the head-of-government claim, making this a dated-receipt tracking and publishing opportunity whichever way it resolves. It also extends the radar's autonomous-hacking lineage into a new regime — an open-source dual-use pentest harness allegedly deployed at national financial-infrastructure scale, distinct from the frontier-model episodes already tracked — though until findings land it informs his argument rather than changing what he builds.
dev:concept.attribution-provenance-ceilingdev:concept.claim-bounded-adversarial-verificationradar:concept.autonomous-hackingradar:concept.offensive-securityradar:hermes-thai-finance-ministry-attackradar:asia-government-multi-agent-intrusionsradar:cyberstrike-offensive-security-harness
queries asked of Scott's wikis
  • agent harness autonomy limits, tool permissions, sandboxing guardrails
  • autonomous LLM penetration-testing agents, dual-use security tooling
  • open-weights misuse — cyber offense capability of local/open models
  • AI hacking attribution epistemics — verifying 'the agent did it' claims
  • frontier lab cyber capability evals and agent release gating
  • agentic security — agent as attack target vs agent as weapon

Measured heat

now 0 pts/hpeak 148 pts/hcomments 0/hpeers p26momentum: steady3 platformsage 147h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

10-05 13:00⭐ origin echo-reconstructedOfficial KTV broadcast of the 43rd State Council (Cabinet) meeting chaired by President Lee Jae-myung, 2026-10-06 10:00, Blue House main hal
President Lee Jae-myung (remarks published by KTV 이매진, the Korean government's official policy broadcast channel) on youtube (echo) · attributed from hn.story.49985861
—
10-06 23:50first on hacker news · published · +34.8hSouth Korea says AI agents appear to have been used to hack the country's banks
thoughtpeddler
—
10-08 10:11first on r/LocalLLaMA · published · +69.2hLast week some of South Korea's biggest banks were hit by a cyberattack. We now know the entire hack may have been done by a single person. He used a combined stack of an open-source AI penetration tool named ARTEX, DeepSeek v4.1-Flash, GLM-5.3, Grok 4.6, and Claude Code (CrowdStrike)
Nunki08
—
10-10 04:41first on r/singularity · published · +111.7hHumans weaponizing AI
phronesis77
—
10-06 23:50amplified on hacker newshn.story.49985861
thoughtpeddler
peak 100 · 32 comments · 17% of case engagement
10-08 10:11amplified on r/LocalLLaMA 👑reddit.post.1x0n4pt
Nunki08
peak 921 · 185 comments · 81% of case engagement
10-09 18:05amplified on hacker newshn.story.50024429
01-_-
peak 1 · 0 comments · 0% of case engagement
10-10 04:41amplified on r/singularityreddit.post.1x269hr
phronesis77
peak 4 · 12 comments · 1% of case engagement
10-11 13:31amplified on hacker newshn.story.50043132
Brajeshwar
peak 1 · 0 comments · 0% of case engagement
10-07 03:22our radar first saw it · +38.4hdiscovery anchor: hn.story.49985861—
10-10 00:31reached heat=high · +107.5h · via ledger——
pace: p93 vs 1247 stories at the 96h mark (now 147h old) — ahead of openai-hugging-face-rogue-agent-incident (1.0x), behind qwen38-27b-local-api-substitution (1.0x)

Evidence (6) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnSouth Korea says AI agents appear to have been used to hack the country's banksthoughtpeddler10032
🟧 echo.youtube ⭐Official KTV broadcast of the 43rd State Council (Cabinet) meeting chaired by President Lee Jae-myung, 2026-10-06 10:00, Blue House main halPresident Lee Jae-myung (remarks published by KTV 이매진, the Korean government's official policy broadcast channel)——
🟠 redditLast week some of South Korea's biggest banks were hit by a cyberattack. We now know the entire hack may have been done by a single person. He used a combined stack of an open-source AI penetration tool named ARTEX, DeepSeek v4.1-Flash, GLM-5.3, Grok 4.6, and Claude Code (CrowdStrike)
LocalLLaMA
Nunki08921185
🟧 hnChinese developer makes ARTEX AI agent closed-source after Korean bank hack01-_-10
🟠 redditHumans weaponizing AI
singularity
phronesis77412
🟧 hnArtex AI, Claude agents used in cyberattacks on South Korean banksBrajeshwar10

Interpretation history

Decision trace