CrowdStrike: AI Hack Targets South Korean Banks

CrowdStrike: AI Hack Targets South Korean Banks

A suspected Chinese hacker used artificial intelligence tools, including Anthropic’s Claude Code and a Chinese-developed penetration testing agent, in a series of cyberattacks targeting South Korean financial institutions, cybersecurity firm CrowdStrike reported on October 7, 2026. The campaign targeted at least nine South Korean banks between late September and early October, compromising customer data from thousands of individuals. CrowdStrike said the suspect may be a 26-year-old based in Guangdong province, with personal details discovered while analyzing AI coding-tool sessions and infrastructure associated with the attacks.

AI cyber attack on South Korea banks visualization with location pins and data flow connections across Asia network map.

AI Tools Deployed in Bank Breaches

CrowdStrike said the individual used ARTEX, a recently released open-source AI agent for automated penetration testing, together with large language models including Claude. ARTEX was published on GitHub in 2026 by a security engineer using the handle Autumn, and functions as a bridge connecting to external large language models such as ChatGPT, Claude, and DeepSeek.

The attacker also used Anthropic’s Claude Code, as well as GLM-5.3 and Grok 4.6 in separate sessions. Session logs recovered from attacker-controlled servers revealed that the suspect asked Claude where stolen Korean data could be sold and sought information about sales channels on platforms like Telegram.

ARTEX Rendthration Trading platform comparing AI models Claude ChatGPT DeepSeek Grok GLM-5.3 for cybersecurity

CrowdStrike stated that “the threat actor is likely a Chinese speaker and financially motivated,” making the assessment “with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts.”

Scope of Customer Data Compromised

Shinhan Bank said information belonging to about 25,000 customers was compromised, while KB Kookmin Bank reported that data from 119 customers was leaked. Hana Bank disclosed 89 affected customers, while BNK said records on 11 outsourced workers were taken.

The exposed records covered names, phone numbers, annual income, and calculated loan limits, and also included 66 resident registration numbers, South Korea’s national ID numbers.

South Korean banks data breach: 25,219 customers affected by CrowdStrike AI hack compromising names, phone numbers, income...

Identity Clues from AI-Generated Resume

In one session, the person requested Claude to create a security researcher resume, which included details such as a Telegram account, age, educational background and a location in Maoming, a city in the southern Chinese province of Guangdong, which CrowdStrike said likely belonged to the attacker.

A man who answered a phone number published by CrowdStrike in its report said he had no knowledge of the matter. The cybersecurity firm noted that while it identified potential personal details, the activity has not been formally attributed to a named threat actor or group.

Resume of Xiao Chen, cybersecurity specialist in Maoming, China, age 26, linked to South Korean bank hacking attacks.

Government Response and Investigations

The attacks prompted South Korean police to launch a probe this week and President Lee Jae Myung to call for robust response measures. Chinese foreign ministry spokesperson Mao Ning told a regular press briefing that the ministry was not familiar with the case and that China as a matter of principle has consistently opposed and combated hacking activities.

Anthropic and South Korean police did not respond to requests for comment.

Growing Concerns Over AI-Enabled Attacks

The breaches raise fresh concerns over the use of AI to automate cyberattacks. While ARTEX’s public repository states it is intended for personal learning, code research, and local technical verification, and warns against targeting online systems, analysts observed it being deployed in the wild.

The incident represents one of the first publicly documented cases in which AI coding assistants and automated penetration testing agents were identified as key tools in a significant financial sector breach. CrowdStrike’s discovery of session logs stored in open directories on attacker-controlled servers provided unusual visibility into how the suspect used AI tools throughout the campaign, from vulnerability discovery to planning data monetization.

AI-powered attack workflow diagram showing vulnerability discovery, system compromise, data exfiltration, and monetization...

Key Facts

  • At least nine South Korean banks were targeted in attacks between late September and early October 2026
  • Shinhan Bank reported approximately 25,000 compromised customer records; KB Kookmin Bank reported 119 affected customers
  • The suspected attacker used ARTEX penetration testing tool alongside Claude Code, GLM-5.3, and Grok 4.6
  • CrowdStrike identified a potential suspect as a 26-year-old based in Maoming, Guangdong province, China
  • Stolen data included names, phone numbers, income details, and 66 South Korean national ID numbers
  • AI session logs revealed the attacker asked Claude where to sell stolen Korean data

Sources

Sources

  1. AI agents used in cyberattacks targeting South Korean banks, CrowdStrike says
  2. South Korean banks were likely hacked by a China-based actor with an AI agent, CrowdStrike says
  3. CrowdStrike Traces South Korean Bank Hacks to China Suspect – Time News
  4. CrowdStrike Says Suspected Chinese Hacker Used Anthropic’s Claude, AI Agent to Steal South Korean Bank Da – Benzinga
  5. Korean Bank Hacker Asked Claude Where to Sell the Stolen Data, CrowdStrike Says

Written by

Mike Gingerich

Author

Author: Mike Gingerich, President of web firm Digital Hill, Co-Founder of TabSite .
Digital and Social Media Marketer, Speaker, and Business Consultant. Part geek, part marketer, total digital junkie! Seeking to add value, make the complex simple, and leave a positive impact.

Follow me on twitter: @mike_gingerich.