The Scanner Became the Weapon

By: TechVanguard – SeaPRwire – A tool built to find weaknesses is now the suspected attack vector. Open-source ARTEX can call frontier models from Anthropic and OpenAI. Korean banks that use such scanners for defence appear to have been hit by the same class of technology. Customer records left the buildings. The president has ordered a full investigation and faster AI-based defences. The gap between patching after the fact and stopping the next probe is the real issue.

According to Korean media reports on 6 October, several banks suffered successive hacking incidents with personal-data leaks. Shinhan Bank saw information on approximately 25,000 customers exposed. KB Kookmin Bank reported 119 customers affected. Hana Bank reported 89. BNK Busan Bank reported 11 outsourced staff. Similar attacks occurred at savings banks, loan companies and mutual financial institutions. Investigators noted signs that the open-source cybersecurity tool ARTEX had been misused. The tool can invoke multiple AI models, including Anthropic’s Claude and OpenAI’s GPT, and was originally designed to help organisations discover network vulnerabilities. Attackers are suspected of turning it against those same networks. To evade tracing they routed traffic through more than twenty IP addresses in more than ten countries, including the United States, Japan and Germany. Suspect identities remain unknown. President Lee Jae-myung ordered a thorough investigation and the formulation of countermeasures. On the same day he further urged rapid inspection of private-sector and national core systems and the immediate application of necessary security-encryption measures. At a cabinet meeting he stated that remedies after an incident are insufficient against evolving cyber threats. Pre-emptive detection capability and the ability to actively block attacks are required. Speed, he said, is critical. He called for accelerated development and deployment of cybersecurity-specific AI technology and declared that the time has come to comprehensively innovate social-security models for the AI era. The National Police Agency formally opened an investigation into cyberattacks on seven financial institutions, citing violations of the Information and Communications Network Act. A 28-member cyber-terrorism investigation team is handling the case. Banks are advancing their own measures. Shinhan plans regular security checks next month on 317 points covering its website, mobile application and internal systems. Kookmin plans to introduce new intrusion-detection and blocking systems plus a web application firewall within the year. Both institutions stated that the steps had been planned in advance and are unrelated to the current incidents. South Korea’s three major credit-rating agencies have begun assessing the impact, including possible fines, business-suspension penalties, reputational damage, customer loss and any consequent effect on credit ratings.

The practical next step is inventory control. Every financial institution should state whether ARTEX or any comparable AI-calling scanner remains installed, who can invoke it, and what logging is retained. Those three answers will show whether the dual-use risk is still sitting on the network or has already been removed.

Author bio: TechVanguard, senior commentator for an international technology weekly covering AI dual-use risks and financial-sector cyber defence.