FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Agentic AI-Driven Financial Intrusions Targeting South Korean Banks

In October 2026, a financially motivated threat actor used agentic AI to compromise seven major South Korean banks, harvesting employee credentials via AI‑generated phishing pages on fraudulent loan‑agent sites and then leveraging the ARTEX automated penetration‑testing framework guided by Claude LLM to conduct autonomous reconnaissance, lateral movement, and privilege escalation. The adversary abused legitimate banking APIs (SWIFT, payment gateways), exfiltrated ~12 M customer records through steganographic image files, and initiated fraudulent wire transfers causing ≈USD 210 M in direct loss, 4‑hour average service outages, KRW 30 B in regulatory fines, and measurable reputational damage. The campaign was uncovered by CrowdStrike and Aviatrix threat‑intelligence feeds, dark‑web monitoring, and incident response, prompting a nationwide alert from Korean financial authorities.


LINK COPIED TO CLIPBOARD