Max AlexanderD.Eng., CEng MIET

Attribution can wait

5 October 2026

Between September 27 and September 30, attackers worked their way through South Korea's financial sector. Shinhan Bank disclosed a breach affecting 25,727 customers — names, phone numbers, annual income, loan limits. Then the list grew: KB Kookmin, Hana, BNK Busan, Yegaram Savings Bank, Welcome Savings Bank, Hyundai Capital, and two online investment-linked lenders. Seven-plus institutions in four days.

On October 2, two days after Shinhan's disclosure, the Financial Services Commission convened an emergency meeting: six major banks, three card companies, the Financial Supervisory Service, the Financial Security Institute, and both industry associations in one room. The directives that came out of it fit on an index card. Identify every externally reachable IT asset and service, without omission, customer-facing or not. Cut unnecessarily exposed information to a minimum and verify that authentication cannot be bypassed on the way to personal data. Share attacker IPs, methods, and attempted intrusions with the authorities and with each other, immediately. Then report your self-inspection results — banks and card companies by October 6, securities firms, insurers, savings banks, and e-finance companies by October 8.

Timeline of the September–October 2026 South Korean financial-sector intrusions: first disclosure September 30, sector-wide directive October 2, self-inspections due October 6–8, attacker still unknown. Five cards compare outcomes from the same attack wave: zero records at Woori and NH NongHyup, which blocked the attempts; 89 at Hana Bank; about 2,200 at Welcome Savings; 25,727 at Shinhan Bank; and about 40,000 at Yegaram Savings.

Notice what is absent from that list: any claim about who did it. Attribution was, and as I write this still is, unconfirmed. The regulator moved anyway, and that ordering of priorities is the most instructive thing about the whole episode.

The attack was old. The speed was new.

Strip away the headlines and the intrusion technique at Shinhan was almost embarrassing. According to reporting in the Kyunghyang Shinmun, the attacker fed sequential and random values into an externally reachable service built for loan solicitors, found valid customer identifiers, and used them to pull everything else. That is enumeration against a weakly authenticated endpoint — a technique old enough to have grandchildren. No zero-day, no malware, no phishing. A door that checked identity poorly, discovered by someone willing to knock on it a few hundred thousand times.

The suspected novelty is who, or rather what, was knocking. Analysts at Genians found that a web server used in the attacks carried an HTML page title naming ARTEX, an open-source, LLM-driven penetration-testing system — an agent that automates reconnaissance, vulnerability discovery, attack planning, and execution. The tool was published on GitHub on July 26 of this year by a developer known only by a handle. It won a Baidu security competition on September 3. Its latest version shipped September 24. The attacks began September 27.

I want to be careful here, because the sourcing deserves it: neither the banks nor the authorities have confirmed that ARTEX was actually used, and an HTML title on one server is circumstantial. The attacker's identity is unknown, and the traffic came through IPs in eight countries. It may yet turn out to be several unrelated actors; investigators note the same IP recurred across the commercial-bank intrusions but not the savings-bank ones.

But whether or not this particular tool did this particular job, the pattern is the one I described in the Siemens advisory piece in August: the attacks aren't getting smarter, they're getting cheaper. An enumeration attack against one bank's loan-broker portal was always possible. Running the equivalent reconnaissance against an entire country's financial sector in a single week used to require a team. If an autonomous agent was involved, it required a download.

Why the response is the right shape

Security culture is addicted to attribution. Who was it, which group, which country, what's the actor profile. It is genuinely useful for intelligence purposes and almost useless for the defensive decisions that matter in week one — and the FSC's directive list quietly embodies that truth.

Every item on the card targets the exposure class rather than the adversary. Inventory what's reachable from outside. Close the paths that reach personal data without real authentication. Share indicators so one institution's incident becomes every institution's early warning. None of this requires knowing whether the attacker was a Chinese AI agent, a bored teenager, or both on different days. It would be the correct homework against all of them, which is exactly the property you want when the facts are still moving — defenses keyed to an actor collapse when the actor turns out to be someone else; defenses keyed to your own exposure don't care.

There is also a deadline discipline worth noticing. First disclosure September 30. Sector-wide directive October 2. Self-inspection results due October 6 and 8. From first blood to a completed, reported exposure review across every bank, insurer, broker, and fintech in the country: roughly one week. I have sat through incident responses where a single company took longer than that to agree on the scope of its own review.

Same wave, very different outcomes

The detail I would put in front of every board is buried in the damage figures. This was, as far as investigators can tell, broadly the same wave of activity — and the outcomes ranged from nothing to forty thousand records. Woori and NH NongHyup detected and blocked the attempts outright. Hana lost 89 records. Shinhan lost 25,727. Yegaram Savings Bank lost around 40,000. Korean officials attributed the disparity to differences in multi-factor authentication, access controls, encryption, and management of externally exposed systems.

Read that again: the attacker was held constant, and the controls were the variable. This is as close to a natural experiment as our field ever gets. The institutions that had done the dull work — knowing what they exposed, authenticating access to it, watching it — shrugged the wave off. The ones that hadn't became disclosure notices. Resiliency is not measured on the day you buy the tooling; it is measured on the worst day, by the gap between you and the neighbor who got the same knock.

The hard instruction is the first one

If there is a weakness in Seoul's response, it is that self-assessment is only as good as the inventory underneath it, and "identify your externally exposed assets without omission" is the hardest instruction on the card while looking like the easiest. Shinhan's breach came through a portal for loan solicitors — exactly the kind of system that falls outside anyone's mental model of "our internet-facing estate," which is presumably why it was reachable and weakly authenticated in the first place. The same was true of the Siemens controllers in August: the exposed systems were the ones nobody thought of as exposed. Institutions will complete the checklist by Wednesday. Whether the checklist covered the forgotten portal is the part no deadline can guarantee.

Still, as regulatory reflexes go, this one is worth copying. A sector that shares indicators within days, reviews its exposure class within a week, and leaves the whodunit for later has its priorities in the right order. Attribution is a luxury you earn after the doors are locked. South Korea's regulator seems to understand that the reverse order — the one most of us instinctively reach for — gets you a well-documented history of exactly how you were robbed.

← All writing