CrowdStrike links South Korean bank breaches to AI tool ARTEX, Claude Code
A CrowdStrike report published Oct. 7 says a likely Chinese-speaking, financially motivated attacker breached multiple South Korean financial institutions between late September and early October 2026, stealing large amounts of customer data — about 25,000 Shinhan Bank records alone, including names, contact details, income and credit limits. The report says the attacker used ARTEX, a free Chinese open-source autonomous penetration-testing tool built on AI language models, along with Anthropic's Claude Code; chat logs left on the attacker's servers included searches for where to sell the stolen data. President Lee Jae Myung ordered a thorough investigation, and police opened a formal probe on Oct. 6 covering seven financial firms.
Why it matters: The case is being cited as evidence that AI-assisted tooling can let a single actor carry out large-scale intrusions quickly, prompting Korean regulators to tighten access controls and speed up threat-intelligence sharing.
References TechRepublic · The Decoder · The Next Web · cnBeta
We may earn from vendors via affiliate links or sponsorships. This might affect product placement on our site, but not the content of our reviews. See our Terms of Use for details.
South Korean President Lee Jae Myung ordered a thorough investigation on Oct. 4 into a series of data breaches affecting banks and other financial institutions, according to the presidential office.
The incidents have reached major commercial banks, a regional bank, a savings bank and a finance company. Tens of thousands of customers have been affected, while authorities are also investigating whether AI-assisted tools played a role. South Korea’s Financial Services Commission (FSC) has told the sector to tighten access controls, review exposed systems and share threat information quickly.
Breaches spread across South Korea’s financial sector
According to Korea JoongAng Daily, the incidents have affected major commercial banks as well as regional and nonbank financial institutions. The spread across different parts of the sector prompted regulators to widen their response beyond individual firms and call for broader security reviews.
Institution****Reported impact Shinhan Bank About 25,000 customers Hana Bank 89 people KB Kookmin Bank 119 people BNK Busan Bank 11 outsourced developers Yegaram Savings Bank Roughly 40,000 customers Hyundai Capital 146 housing loan agents
The Korea Times reported that the exposed information included names, phone numbers, annual income, and loan limits, while some customers’ resident registration numbers were also compromised. Financial authorities said they had not found evidence that sensitive information directly usable for unauthorized payments had been exposed, but warned that the stolen data could still support secondary attacks such as voice phishing.
Investigators are looking at possible AI-assisted attacks
FSC Chairman Lee Eog-weon said authorities could not rule out the possibility that AI was used in the attacks. He also called on financial firms to accelerate the use of AI-based security tools as investigators examine how the breaches were carried out.
The Korea Times, citing industry officials, reported that traces of a Chinese-language AI penetration-testing tool were found on a server believed to have been used in the Shinhan Bank attack. The server’s HTML title reportedly contained a phrase translating to “AI autonomous penetration testing console,” raising questions about a possible connection to ARTEX AI, an open-source autonomous penetration-testing system based on a large language model.
The reported server traces do not confirm that ARTEX AI was used to carry out the Shinhan breach, or that AI tools were involved in the other incidents. Police are investigating the attacks, while the FSC has publicly described AI involvement as possible rather than confirmed.
Regulators order tighter controls and faster threat sharing
Reuters reported that South Korean regulators directed financial institutions to conduct comprehensive security inspections, tighten access controls, minimize external system access and strengthen consumer protection measures.
The FSC also said attack methods, IP addresses, and other threat information would be shared quickly across the industry to help prevent additional incidents. The emergency response included banks, securities firms, insurers, credit card companies, savings banks and fintech companies, although Korea JoongAng Daily reported that several of those sectors had not shown signs of similar attacks at the time.
Reuters, citing Yonhap, reported that regulators believe attackers may have broadly scanned several financial companies for vulnerabilities rather than concentrating on a single institution.
Must-read security coverage
- UK Police Convicts Pair in £5.5 Billion Bitcoin Launder Case
- Blackpoint Cyber vs. Arctic Wolf: Which MDR Solution is Right for You?
- How GitHub Is Securing the Software Supply Chain
- 8 Best Enterprise Password Managers
Attack traffic crossed several APAC countries
Reuters, citing Yonhap’s reporting on bank data submitted to lawmakers, said attack traffic came from IP addresses in the United States, Britain, Japan, Singapore and Vietnam. The IP locations show the international footprint of the traffic, but do not establish where the attackers themselves were located.
For financial institutions across APAC, South Korea’s response puts attention on internet-facing systems, access controls and rapid sharing of threat indicators between institutions. The data already exposedalso creates a separate risk, as attackers could use legitimate personal and financial details to make phishing or social engineering attempts more convincing.
For security teams, the practical takeaway is to review externally accessible systems and access permissions, share threat indicators promptly, and prepare for phishing attempts that exploit exposed customer details.
Other news:AI coding agents reportedly exposed 13,000 internal screenshots from 343 tech companies in public GitHub repositories, highlighting how weak approval and audit controls can turn routine agent workflows into data leaks.
Kezia Jungco
Kezia Jungco is a technology writer and researcher specializing in artificial intelligence, data analytics, CRM software, cloud infrastructure, cybersecurity, and emerging business technologies. With more than five years of experience evaluating software platforms and technology solutions, she helps business leaders understand the tools and trends shaping the future of work. Kezia has extensive hands-on experience testing and analyzing generative AI platforms, chatbots, natural language processing (NLP) tools, CRM systems, and business software. Her work focuses on translating complex technologies into practical insights that help organizations make informed decisions about technology adoption, operational efficiency, and digital transformation. As a staff writer for TechnologyAdvice, Kezia covers AI innovation, business applications of machine learning, data-driven technologies, cloud computing, cybersecurity, and sales technology. Her background in journalism, research, and education enables her to combine rigorous analysis with clear, accessible reporting for both enterprise and consumer audiences. Kezia holds a bachelor's degree in Development Communication with a major in Development Journalism from the University of the Philippines Los Baños. She has also completed professional training in artificial intelligence, data privacy, and information security. Her work has been featured in TechnologyAdvice, TechRepublic, eWeek, Datamation, and Selling Signals, where she helps readers navigate a rapidly evolving technology landscape with practical, research-driven guidance.
How we got here
- Researchers link AI agent fleet to Tencent and Amap scrapingTom’s Hardware · Anthropic
- Termexo v0.10.11 released, drives five coding agents over MCP开源中国 · Claude Code
- a16z: Only 4.5% of US consumers pay for AI, while GPU rents keep risingMIT科技评论中文 · Anthropic
- Study says Claude and ChatGPT may vary shopping prices by wealthBloomberg Technology · Anthropic
- Claude’s Logo Experiment Failed at Print-Ready DesignAndroid Authority · Anthropic
- Anthropic quietly adds Simplified and Traditional Chinese UI to Claude web and desktop创业邦 科技 · Anthropic