Welcome to The Calibre Brief, a Calibre Code USA production. South Korea’s bank breaches raise a harder question than whether artificial intelligence was involved: when software leaves the trail, who can investigators actually identify? At Shinhan Bank, an internal loan-agent inquiry service exposed data on 25,729 people. Customers never see this portal. After investigators shared attacker indicators, other institutions searched logs and found intrusions they had missed. The count reached at least seven institutions and more than 68,000 people, which President Lee Jae Myung called the first known case of its kind. Investigators identified ARTEX AI, a free, open-source platform built on language models. A hacker set the objective; the software mapped systems, tested weaknesses, read results, and retried. The targets were employee- and partner-facing systems, managed less rigorously than services. Two or three IP addresses rotated per bank, while an ARTEX signature identified the tool. The lead agency corrected the headline: the AI did not act independently. “A hacker used the AI as a tool.” ARTEX names the software, not the operator. Separate research found AI agents could reproduce five documented groups’ behavior with 55 to 80 percent precision, enough to be plausibly mistaken for them. That study does not prove who ran the Korean attacks. The operator and any state link remain unknown. That shifts the practical question from who is coming after banks to what they are still exposing. Internal audits and shared warning signs can reduce that exposure. Woori and NH NongHyup were not breached because the vulnerabilities were absent. Attribution remains out of reach, but prevention is not. It shows the deeper problem: free software can make an attacker’s identity indistinguishable from the tool, while institutions still control the weaknesses that let campaigns in. You’ve heard The Calibre Brief from Calibre Code USA. Should banks report every attempted intrusion, including failed probes, and what would that visibility cost? Comment below, like and subscribe on YouTube, and follow the podcast.