AI Attack Exposes 68K Records at 9 South Korean Banks

AI Attack Exposes 68K Records at 9 South Korean Banks

CrowdStrike published a report on October 7, 2026, revealing that a suspected 26-year-old threat actor likely based in China’s Guangdong Province used AI-powered tools to target at least nine South Korean banks in what cybersecurity experts are describing as one of the first major campaigns leveraging agentic AI for financial fraud. The campaign, which ran from late September to early October 2026, resulted in personal information belonging to 68,000 people being exfiltrated by the attacker, prompting South Korean President Lee Jae-myung to call for robust response measures.

Coordinated cyber attack map showing South Korean banks hit by malware, phishing, DDoS, and data breaches across multiple ...

The attacker used ARTEX, a recently released Chinese-developed open-source penetration testing tool, alongside Anthropic’s Claude Code to automate multiple intrusions across South Korea’s financial sector. The disclosure marks a significant escalation in AI-enabled cyber threats and has raised urgent questions about whether organizations are prepared to defend against autonomous AI agents.

ARTEX Tool architecture diagram showing AI integration with Claude Code, ChatGPT, and DeepSeek for automated task processi...

How the AI-Powered Attack Unfolded

CrowdStrike gained direct insight into the operation by analyzing threat-actor-controlled open directories containing Claude Code session histories, ARTEX configuration files, and Claude memory files. This operational security failure by the attacker revealed the technical details of how the campaign was executed.

Server data directory exposing sensitive logs, config files, and memory dumps from database breach affecting South Korean ...

ARTEX, published on GitHub in 2026 by a security engineer using the handle Autumn, functions as a bridge connecting to external large language models such as ChatGPT, Claude, and DeepSeek rather than operating as a standalone model. The tool is designed for automated penetration testing and was intended for use in controlled lab environments.

Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told reporters that this was an example of a human adversary leveraging AI agents to conduct widespread attacks, noting that “this is significant because it allows one human to target many customers in a very short period of time using the power of AI”.

Scale of the Data Breach

Multiple South Korean financial institutions confirmed customer data compromises in the wake of the campaign. Shinhan Bank said that personal information of about 25,000 of its customers was compromised, while KB Kookmin Bank said that the personal information of 119 of its customers was leaked.

Data breach chart showing 68,000 records exposed across 9 South Korean banks, with Shinhan Bank affected most at 25,000 re...

At least nine South Korean banks have disclosed or have been reported by local media as having been targeted by cyberattacks since late September, prompting South Korean police to launch a probe this week. The full scope of the breach across all affected institutions continues to emerge as investigators review the incident.

Attribution and Threat Actor Profile

CrowdStrike’s report stated that “while this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated”. The assessment was made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts.

When contacted by researchers via a phone number found in the logs, a man who answered the call stated he had no knowledge of the matter, according to published reports.

Broader Implications for AI Security

Adam Meyers stated that “ARTEX shows how adversaries are operationalising agentic AI to move faster and conduct multiple intrusions in a short period”, highlighting the emerging threat landscape as AI tools become more sophisticated and accessible.

Such incidents are forcing cyber insurers to review their policies, as they come to grips with issues including whether autonomous AI systems fit traditional policy definitions of a cyber attacker and who bears liability for AI-generated actions that cause a loss.

AI cyber attack threat illustration with policy and liability documents, hacker, and South Korean banks under digital assa...

The case has intensified scrutiny over how AI companies monitor and prevent misuse of their platforms. Anthropic’s Claude Code, designed as a legitimate coding assistant, was reportedly used alongside the ARTEX framework to automate reconnaissance and exploitation activities that would typically require manual effort from skilled hackers.

Key Facts

  • CrowdStrike published its report on October 7, 2026, identifying a China-based threat actor behind attacks on South Korean financial institutions
  • The campaign ran from late September to early October 2026, affecting at least nine banks
  • 68,000 customer records were exfiltrated during the campaign, according to Seoul investigators
  • The attacker used ARTEX, a Chinese-developed penetration testing tool, paired with Anthropic’s Claude Code
  • Shinhan Bank reported 25,000 compromised customer records; KB Kookmin Bank reported 119
  • CrowdStrike believes the suspect is approximately 26 years old and likely based in China’s Guangdong Province
  • South Korean police launched an investigation and President Lee Jae-myung called for robust response measures

Sources

Sources

  1. CrowdStrike: How a Cyber Attacker hit South Korean Banks
  2. South Korean banks were likely hacked by a China-based actor with an AI agent, CrowdStrike says
  3. S Korean banks likely hacked by China-based actor: CrowdStrike – Taipei Times
  4. Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance
  5. CrowdStrike Traces South Korean Bank Hacks to China Suspect – Time News
  6. So. Korean Banks Were Likely Hacked by China-Based Actor With AI Agent: CrowdStrike
  7. CrowdStrike: China-Based Suspect Used AI in South Korean Bank Attacks

Written by

Mike Gingerich

Author

Author: Mike Gingerich, President of web firm Digital Hill, Co-Founder of TabSite .
Digital and Social Media Marketer, Speaker, and Business Consultant. Part geek, part marketer, total digital junkie! Seeking to add value, make the complex simple, and leave a positive impact.

Follow me on twitter: @mike_gingerich.