AI-assisted attackers hit financial APIs from India to South Korea as CERT-In issues critical alert

CERT-In has issued a critical advisory (CIAD-2026-0046) warning that attackers are stealing payment API credentials from NBFCs, fintechs, payment providers and wallets, then triggering fund transfers directly to mule accounts. It flags the possible use of AI-assisted offensive frameworks. The alert follows a wave of AI-assisted API breaches at seven South Korean financial firms that exposed data on more than 67,000 people. In both cases attackers went through weakly guarded side APIs.
NEW DELHI: India's Computer Emergency Response Team (CERT-In) has issued a critical advisory warning that threat actors are hijacking payment and disbursement APIs to move money out of financial institutions without a single loan, KYC check or beneficiary approval.
The advisory, CIAD-2026-0046, was issued on 9 October 2026 with CSIRT-Fin, India's financial-sector security team.
It comes days after an AI-assisted hacking wave hit South Korea's largest banks through the same weak point: poorly guarded APIs.
Inside the attack chain
CERT-In says the campaigns target non-banking financial companies (NBFCs), digital lenders, fintechs, payment service providers and wallet operators.
Attackers get in through:
- Exposed internet-facing apps and vulnerable middleware
- Deprecated or unauthenticated APIs with unrestricted file uploads
- Long-lived static API tokens hard-coded in source code
- Forged commits into source-code repositories
- Plaintext credentials in config files and databases
- Remote services without multi-factor authentication (MFA)
Once inside, they plant web shells, map payment databases, steal payment-gateway and partner-bank API keys, then call the disbursal APIs directly from the victim's own whitelisted servers.
That bypasses every application-level check: loan creation, KYC, sanction, beneficiary verification, balance and per-transaction limits.
The transfers carry dummy reference numbers, run rapidly over IMPS and NEFT, and land in mule accounts at multiple banks, where the money is withdrawn at once.
The attackers then delete logs and tamper with endpoint security tools.
The AI factor
CERT-In says the attacks show the possible use of AI-assisted offensive frameworks and large numbers of custom scripts.
The gap between first break-in and fraudulent transfer has shrunk significantly in recent incidents.
Attacker IPs trace mostly to hosting infrastructure.
Chinese-linked syndicate behind a Rs 12.8 crore NBFC heist
The risk is not theoretical in India.
Delhi Police's Intelligence Fusion and Strategic Operations (IFSO) unit has arrested five people, including a private bank relationship manager in Jaipur, over the theft of Rs 12.8 crore (about $1.5 million) from an NBFC's corporate account.
The money left in 317 unauthorised transactions and was routed through 34 first-layer mule accounts before being spread further.
Police say the syndicate worked through Telegram groups allegedly run by Chinese operators.
Mule account holders were recruited with small commissions.
One account was controlled remotely after an APK (Android app file) was installed on the holder's phone, and another, which received about Rs 70 lakh, is linked to 43 complaints on India's National Cybercrime Reporting Portal.
Part of the money was converted to the USDT cryptocurrency and sent abroad, and police are probing a Dubai link.
About Rs 1.7 crore has been frozen.
Police have not said how the NBFC's account was first accessed or whether the case is part of the campaign CERT-In describes.
The cash-out, though, matches the advisory: hundreds of rapid debits, mule accounts across several banks, and quick conversion to crypto.
The Korean parallel
Since late September, seven South Korean financial firms have reported breaches, including Shinhan Bank, KB Kookmin Bank and Hana Bank, along with Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital.
Data on more than 67,000 people was exposed.
Shinhan alone lost names, income details and resident registration numbers of about 25,000 customers through its loan-broker service.
Investigators found traces of ARTEX, a Chinese-language autonomous penetration-testing tool that can connect to large AI models, on a server linked to the attacks.
Korean officials stress that a human operator drove the tool and that its presence does not prove the attacks came from China.
The Korean attackers skipped core banking systems guarded by fraud-detection tools.
Instead they went through "side doors": peripheral APIs used by loan brokers and staff support pages, with weak identity checks.
Sources say AI made it cheap to probe API after API until one gave way.
The tools behind the trend
ARTEX is one of a fast-growing set of AI-assisted penetration-testing frameworks, most of them open source and free to download from GitHub.
Built for legitimate security testing, they link large language models to scanners and exploit tools so a single operator can run reconnaissance, find vulnerabilities and attempt exploitation at machine speed.
Widely available frameworks include:
- ARTEX: Chinese-language autonomous pentesting console, released about two months before the Korean attacks, which works with DeepSeek, OpenAI and Anthropic models. Its original GitHub repository has since been taken down, though copies are still circulating.
- PentAGI: self-hosted, fully autonomous multi-agent system
- Strix: AI agents that find bugs and prove them with working exploits
- HexStrike AI: connects AI assistants to more than 150 hacking tools
- PentestGPT: academic copilot that guides a human tester
- Shannon: reads source code, then attacks through a browser and command line
- CAI (Cybersecurity AI): framework for building custom hacking agents
Others include RedAmon, NeuroSploit, Nebula, VulnBot and PentestAgent, alongside commercial platforms such as XBOW.
Because they are freely available and models can be swapped in and out, defenders cannot count on any one tool or signature to spot this kind of attack.
One systemic weakness
No link between the attackers in India and South Korea has been established.
The pattern, however, is the same:
- Entry point: forgotten, peripheral or weakly authenticated APIs, not the hardened core.
- Speed: AI tooling cuts the time from discovery to exploitation.
- Scale: automated scripts make probing many endpoints cheap.
- Gap: controls sit in the application layer, while attackers talk to the API underneath it.
In South Korea the attackers mostly took data, and regulators have warned of follow-on voice phishing and smishing.
In India they went straight for the money.
Together, the two cases show that AI-assisted offensive tools are now part of financial crime, and that every exposed API is a possible way to the money.
What CERT-In wants entities to do
- Enforce MFA on payment platforms, admin portals, bank APIs and remote access
- Keep a complete API inventory and decommission unused APIs
- Replace static tokens with per-session authentication, and store keys in secret managers or HSMs (hardware security modules)
- Cryptographically bind multi-step transaction flows so debit APIs can't be called without the earlier validation steps
- Require maker-checker approval, and reject payouts whose reference IDs have no matching record
- Apply per-transaction and daily caps, penny-drop and name-match checks on beneficiaries, and velocity limits
- Restrict outbound traffic from production servers, and monitor and reconcile transfers in near real time
- Keep logs for at least 180 days, and deploy tamper-protected EDR (endpoint detection and response)
- Use rate limiting and sequence-binding to break script-driven API abuse
Entities that see suspicious activity should disable compromised accounts, suspend affected APIs, rotate all credentials, preserve evidence and report to [email protected].
Additional recommendations for CISOs
Beyond CERT-In's list, chief information security officers at financial entities should widen their scope:
- Mandatory AI-assisted red teaming: Test both restricted internal environments and public-facing infrastructure with the same kind of AI-assisted penetration-testing tools attackers now use, so weak APIs are found before criminals find them.
- On-premises AI code analysis: Scan source code with advanced AI models running on in-house infrastructure, so code, credentials and customer data never leave the organisation.
- Real-time patching: Move from periodic patch cycles to near-real-time patching of devices and the full technology stack, starting with internet-facing systems.