AI‑Powered Penetration Testing Tool ‘Artex’ Linked to Theft of 66,000 South Korean Bank Customers’ Data
South Korean authorities say the open‑source AI tool Artex was used to automate vulnerability discovery and exfiltrate personal data from seven banks, affecting 66 000 individuals. The case highlights the need for documented governance of AI‑enabled security tools to satisfy audit and control‑assurance requirements.
ADTP Breach Watch· October 7, 2026· DataBreachToday
Police allege that the freely downloadable AI platform Artex was employed to automate reconnaissance, vulnerability scanning, and attack‑path planning against seven financial institutions, resulting in the theft of personal data for roughly 66 000 individuals and 2 200 corporate records.
Why it matters for trust and compliance
Uncontrolled AI‑driven testing bypasses traditional change‑control and logging, exposing a gap in the control objective for secure use of security‑testing tools; mapping this gap to a control‑mapping program provides continuous evidence for audit readiness.
Document and enforce policies for AI‑enabled security tools to satisfy control‑assurance objectives.
Collect continuous logs and evidence of tool usage to demonstrate due diligence during audits.
Who is affected
Banking and payments firms handling consumer financial data
Recommended actions
Create an inventory of all AI‑based security tools and verify each against an approved usage policy.
Enable detailed logging of tool activity and integrate alerts into your SIEM for continuous monitoring.
Map the AI‑tool governance process to the control objective for secure security‑testing and collect evidence for audit readiness.
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.