MBA Training Data. Daily strategy in data governance, architecture, analytics and AI, for data leaders and aspiring CDOs. New episode every day at mba-training.com.
ARTEX bank breaches: why side-door data access is a CDO issue
How did an attacker using ARTEX, an open-source agentic AI penetration-testing tool, take data on more than 67,000 customers from seven South Korean firms, including Shinhan, KB Kookmin and Hana, without touching core banking? The episode argues the failure was data access design. Broker portals and employee apps returned income, loan limits and resident registration numbers to callers who did not need them, despite nearly 124 billion won in security spending.
You come away knowing what the Financial Services Commission ordered, how CrowdStrike linked the attack to Claude Code and DeepSeek, and why basic cyber hygiene matters more than an AI defense product. You also get a concrete plan to inventory every externally reachable system that returns customer data and remove unneeded fields.
0:00 Shinhan breach through a loan broker portal
1:13 ARTEX agentic AI tool and the human attacker
2:38 Side-system data access as a CDO problem
4:42 FSC emergency order on exposed systems
6:06 Hygiene failure or AI-driven attack speed
8:16 Weekly task: audit customer data endpoints
6 Oct 2026
UK GDPR Article 21: 44,000 objections hit NHS Palantir
What happens when a data platform is legally defensible, operationally embedded and publicly distrusted at the same time? More than 44,000 people have filed Article 21 objections under UK GDPR against NHS England's Palantir-powered Federated Data Platform, live in 142 trusts, weeks before a February 2027 contract break clause comes into reach. The position here: objection handling is a throughput problem, not a policy document.
You come away able to pressure-test your own platform. Check the published benefits claims, 117,000 extra operations, a 14.3% cut in discharge delays, against Foxglove FOI data showing 13 of 41 trusts doing fewer operations, and name the owner and service level for mass objections before someone else does.
0:00 44,000 Article 21 objections to NHS data
1:40 What the Federated Data Platform runs
2:31 Palantir politics versus legal mechanism
3:01 Why patients cannot opt out of FDP
4:09 Testing Palantir's NHS benefit claims
7:28 What transfers to any CDO
6 Oct 2026
dbt State: lag_tolerance is now a budget decision
dbt State went generally available in September 2026, so rebuilding every model on a cron schedule is now a choice rather than a default. The position here: the tool cannot tell you how stale each model is allowed to be, and the lag_tolerance config most teams set once and globally is a business decision about decision cadence, not an engineering setting.
You leave with a method: meter wasted rebuilds using BigQuery INFORMATION_SCHEMA.JOBS or Snowflake credit consumption, tie tolerance to the decision each model feeds, keep source freshness checks running, read the Explain tab in audit mode, and cap agent queries with resource monitors and maximumBytesBilled. Includes the RxBenefits 59% result, dbt's 15 to 30% range, FinOps Foundation and Flexera 2026 findings.
0:00 Why 60% of scheduled model builds repeat
1:13 What dbt State GA actually changes
2:57 Metering wasted rebuilds before flipping the switch
4:18 Silent semantic drift when models are reused
5:41 Committed spend contracts hide the savings
6:57 Capping autonomous agents in the warehouse
Contact Leaders Insights — Data
Guest appearances
Does not typically book guests
Based on episode analysis; this does not confirm that the show is currently accepting guests.
Host of Leaders Insights — Data?
Claim your podcast to manage its listing and keep your show details accurate.
Pod Engine is an independent podcast discovery and analytics service and is not affiliated with or endorsed by this podcast. Artwork and show content belong to their owners. Full legal notice.
Explore this show Podcast research with Pod Engine