← October 11, 2026 briefing · added in the 04:00 KST update

P2 Other Generally available KoreaAI securityAgentsFinance & insurance04:00 updateSK shieldus

SK shieldus says 'ARTEX' in chain of financial-sector breaches automated old attacks; issues API security guide (report)

Announced October 8, 2026

What happened

On the 8th, SK shieldus released a guide titled 'Analysis of and Response Guide to Breaches Targeting Shadow IT in the Era of AI-Automated Attacks.' Drawing on recent breaches at Korean financial institutions, it analyzes how AI-based attack tools were used and the actual intrusion paths. According to ZDNet Korea, the attackers did not go after core financial transaction systems first. They targeted poorly managed internet-facing assets such as loan broker systems, employee support services, and sales support platforms. The analysis found that AI's role was to scan these assets faster and more widely. On the same day, Penta Security also released a response guide built on the principles of visibility, layered defense, and 'zero damage design.'

Provider claims

SK shieldus assessed the incident as closer to a case of AI automating and enhancing existing attacks than one in which AI created new attack techniques. The company also claimed that AI automation tools can scan the internet-facing assets and APIs of multiple financial institutions at once, and can quickly widen the set of targets based on API call patterns and response data.

Why it matters

This is the security industry's take on whether the AI hacking incidents at Korean financial institutions are an entirely new threat or existing attacks made faster. If the 'automation of existing attacks' view holds, the focus of the response changes too. Reviewing basic controls, such as inventories of internet-facing assets and APIs and additional authentication, would come before new defensive technology.

Confidence medium · official source pending

Sources

More about SK shieldus