AI Attack Exposes 68K Records at 9 South Korean Banks

CrowdStrike published a report on October 7, 2026, revealing that a suspected 26-year-old threat actor likely based in China’s Guangdong Province used AI-powered tools to target at least nine South Korean banks in what cybersecurity experts are describing as one of the first major campaigns leveraging agentic AI for financial fraud. The campaign, which ran from late September to early October 2026, resulted in personal information belonging to 68,000 people being exfiltrated by the attacker, prompting South Korean President Lee Jae-myung to call for robust response measures.

The attacker used ARTEX, a recently released Chinese-developed open-source penetration testing tool, alongside Anthropic’s Claude Code to automate multiple intrusions across South Korea’s financial sector. The disclosure marks a significant escalation in AI-enabled cyber threats and has raised urgent questions about whether organizations are prepared to defend against autonomous AI agents.

How the AI-Powered Attack Unfolded
CrowdStrike gained direct insight into the operation by analyzing threat-actor-controlled open directories containing Claude Code session histories, ARTEX configuration files, and Claude memory files. This operational security failure by the attacker revealed the technical details of how the campaign was executed.

ARTEX, published on GitHub in 2026 by a security engineer using the handle Autumn, functions as a bridge connecting to external large language models such as ChatGPT, Claude, and DeepSeek rather than operating as a standalone model. The tool is designed for automated penetration testing and was intended for use in controlled lab environments.
Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told reporters that this was an example of a human adversary leveraging AI agents to conduct widespread attacks, noting that “this is significant because it allows one human to target many customers in a very short period of time using the power of AI”.
Scale of the Data Breach
Multiple South Korean financial institutions confirmed customer data compromises in the wake of the campaign. Shinhan Bank said that personal information of about 25,000 of its customers was compromised, while KB Kookmin Bank said that the personal information of 119 of its customers was leaked.

At least nine South Korean banks have disclosed or have been reported by local media as having been targeted by cyberattacks since late September, prompting South Korean police to launch a probe this week. The full scope of the breach across all affected institutions continues to emerge as investigators review the incident.
Attribution and Threat Actor Profile
CrowdStrike’s report stated that “while this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated”. The assessment was made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts.
When contacted by researchers via a phone number found in the logs, a man who answered the call stated he had no knowledge of the matter, according to published reports.
Broader Implications for AI Security
Adam Meyers stated that “ARTEX shows how adversaries are operationalising agentic AI to move faster and conduct multiple intrusions in a short period”, highlighting the emerging threat landscape as AI tools become more sophisticated and accessible.
Such incidents are forcing cyber insurers to review their policies, as they come to grips with issues including whether autonomous AI systems fit traditional policy definitions of a cyber attacker and who bears liability for AI-generated actions that cause a loss.

The case has intensified scrutiny over how AI companies monitor and prevent misuse of their platforms. Anthropic’s Claude Code, designed as a legitimate coding assistant, was reportedly used alongside the ARTEX framework to automate reconnaissance and exploitation activities that would typically require manual effort from skilled hackers.
Key Facts
- CrowdStrike published its report on October 7, 2026, identifying a China-based threat actor behind attacks on South Korean financial institutions
- The campaign ran from late September to early October 2026, affecting at least nine banks
- 68,000 customer records were exfiltrated during the campaign, according to Seoul investigators
- The attacker used ARTEX, a Chinese-developed penetration testing tool, paired with Anthropic’s Claude Code
- Shinhan Bank reported 25,000 compromised customer records; KB Kookmin Bank reported 119
- CrowdStrike believes the suspect is approximately 26 years old and likely based in China’s Guangdong Province
- South Korean police launched an investigation and President Lee Jae-myung called for robust response measures
Sources
- CrowdStrike: Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance
- Insurance Journal: So. Korean Banks Were Likely Hacked by China-Based Actor With AI Agent
- Cyber Magazine: CrowdStrike on South Korea Bank AI Cyber Attack
- Taipei Times: S Korean banks likely hacked by China-based actor
Sources
- CrowdStrike: How a Cyber Attacker hit South Korean Banks
- South Korean banks were likely hacked by a China-based actor with an AI agent, CrowdStrike says
- S Korean banks likely hacked by China-based actor: CrowdStrike – Taipei Times
- Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance
- CrowdStrike Traces South Korean Bank Hacks to China Suspect – Time News
- So. Korean Banks Were Likely Hacked by China-Based Actor With AI Agent: CrowdStrike
- CrowdStrike: China-Based Suspect Used AI in South Korean Bank Attacks







