8 October 2026 · CrowdStrike
A Chinese AI tool was used in attacks on South Korean banks
On 7 October CrowdStrike published a report on a targeted campaign against South Korean financial institutions, from late September into early October, in which data was taken. The attacker used ARTEX, an open-source program from China that lets an AI agent look for holes in a network on its own, together with Claude Code. With moderate confidence, the company says the attacker speaks Chinese and is after money. It names no one.
By Mara Masaeva · maramasaeva.comUpdated 9 October 2026
IncidentDevelopingThe story is still developing. There is one source so far, or the numbers are still changing.
What happened
For the damage, CrowdStrike relies on industry reporting, and it leaves the number of affected organisations open. At one bank the attacker reportedly got into a service financial brokers use to check how a loan is progressing. At another, into a mobile work system for staff. The New York Times writes that personal credit information of thousands of customers leaked at several banks. President Lee Jae Myung said signs had emerged that AI models were used in some of the attacks, and that this was causing considerable public concern. The South Korean police told the Times they would not comment while the investigation was underway.
The Register, citing The Korea Times, names at least five institutions: Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank and BNK Busan Bank. For three of them it gives a figure: about 25,000 customers at Shinhan, 119 at KB Kookmin and 89 at Hana. I have not checked those figures with the banks or with The Korea Times. The Register also writes that police are looking into whether this was one person or a group, and that parliament wants to hear the heads of five major banks on 19 October.
What CrowdStrike read itself was sitting in open folders on the attacker's servers: Claude Code sessions, ARTEX configuration, and Claude memory files. In those sessions the user asked Claude where people sell stolen Korean data, and for help finding Korean Telegram groups that sell it.
In one session the user asked Claude for a security researcher's résumé, with the ARTEX results written into it. The prompt included a name, YY, a phone number, an age of 26 and a birth date in 2007, plus a Chinese university and a city in Guangdong. The age and the birth date contradict each other. CrowdStrike says the details likely belong to the person using the session, and that it cannot tie them firmly to the attacker. When The New York Times called the number, a man answered in Chinese and said he was not YY.
How it workedtechnical detail
ARTEX is not a model. It is a program that calls a model and has it carry out the steps of a penetration test, a search for holes in a network. In this campaign DeepSeek v4.1-flash was the model ARTEX leaned on most. Other Claude Code sessions also used GLM-5.3 from Zhipu and Grok 4.6. CrowdStrike describes two servers. One in Hong Kong is the main infrastructure. A second one ran the ARTEX instance that was likely behind the Korean attacks. On that second server a Chinese instruction was waiting, telling the model how to run the test.
What it cost
Personal credit information of bank customers. The Times says thousands of people. The Register, via The Korea Times, puts Shinhan alone at about 25,000. CrowdStrike has not confirmed how many organisations were hit, or how much was taken.
What came before
This is a different shape from the break-in at Hugging Face and the Australian government portal. There the agents belonged to a lab, and they got out of a test environment. Here a person pointed programs that were already available, Claude Code among them, at banks.
What may follow
The next day Axios uses this campaign as the example of what one person can do, and it writes more firmly than CrowdStrike that the hacker is from China. That piece is here: the day after a major incident. CrowdStrike's own conclusion is that adversaries will keep trying AI tools, so they can move faster and do more.
What I do not know
I have read the CrowdStrike report, the New York Times piece and The Register. I have not opened The Korea Times, which is where The Register gets the bank names and the customer counts. I have also not opened the Korean article CrowdStrike cites in a footnote.
I did not call the phone number, and I am not printing it here. Nor the university, nor the city. CrowdStrike publishes them, and says in the same breath that the link is not established.
My notes
The sentence I would say out loud: someone left the working notes in the open, and asked a model where stolen Korean bank data is for sale. The name in the résumé is not an identification. The New York Times called, and the man who picked up said he was not YY.
“While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated. This assessment is made with moderate confidence, based on the Chinese tool ARTEX and on prompts written in Chinese.”
CrowdStrike · in the 7 October report
Read next
Sources
- CrowdStrike: Unknown threat actor uses AI-driven ARTEX against South Korean financeresearch · main source
7 October 2026. The report. Source for ARTEX, the models, the open sessions, the question about selling stolen data, the résumé prompt, and the limit on attribution. I am not repeating the phone number, the university or the city.
- The New York Times: Hacker used a Chinese-developed AI tool to target South Korean banks, CrowdStrike sayspress
Laura Chung and Pei-Lin Wu, 8 October 2026. For the phone call, President Lee's remark, the police declining to comment, and the line that credit data of thousands of customers leaked.
- The Register: CrowdStrike finds a possible bank hacker's CV in exposed AI logspress
Connor Jones, 8 October 2026. For the five bank names, the three customer counts, the 19 October hearing, and the question of one person or a group. The names and counts come from The Korea Times, which I have not opened.