GBAF Logo
Global Banking & Finance Awards® 2026 Nominations open, free to enter Nominate now →
CrowdStrike says China-based suspect used AI tools in South Korean bank hacks - Finance news and analysis from Global Banking & Finance Review
Finance

CrowdStrike says China-based suspect used AI tools in South Korean bank hacks

Published by Global Banking & Finance Review

Posted on October 8, 2026

3 min read

· Last updated: October 8, 2026

Add as preferred source on Google

CrowdStrike: AI Tools Linked to China Suspect in South Korean Bank Hacks

AI-Driven Cyberattacks Targeting South Korean Financial Sector

By Kyu-seok Shim and Brenda Goh

SEOUL, Oct 8 (Reuters) - The suspect behind recent cyberattacks targeting South Korea's financial sector may be a 26-year-old based in China's Guangdong province who used a Chinese-developed AI agent tool called ARTEX and Anthropic's Claude Code, US cybersecurity firm CrowdStrike said.

In a report published on Wednesday, CrowdStrike said it uncovered personal details linked to the suspected attacker while analysing AI coding-tool sessions and infrastructure associated with a campaign targeting South Korean financial institutions from late September to early October.

Rising Concerns Over AI Agents in Cybersecurity

The case is likely to intensify concerns over the rise of AI agents and whether organisations are prepared to defend their systems against them.

Australia said last month that an OpenAI autonomous agent breached a government health statistics portal in June, marking one of the first known instances of an AI agent hacking a government system.

Details of the Attack and Tools Used

CrowdStrike said the attacker used ARTEX, a recently released Chinese-developed open-source penetration testing tool, alongside large language models such as Claude.

"While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated," it said.

"This assessment is made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts."

Bank Hacks and Data Breach Attempts

BANK HACKS

CrowdStrike said the individual also asked Claude where threat actors typically sell Korean data breach information and sought assistance in finding Korean Telegram data sales groups.

In another session, the person also requested Claude to create a security researcher resume, which included details such as a Telegram account, age, educational background and a location in Maoming, a city in the southern Chinese province of Guangdong, which CrowdStrike said likely belonged to the attacker.

A man who answered a phone number provided by CrowdStrike in its report said he had no knowledge of the matter.

Anthropic, South Korean police and China's foreign ministry did not immediately respond to requests for comment.

About ARTEX: The AI Penetration Testing Tool

ARTEX is an open-source AI agent for automated penetration testing that was published on GitHub this year by a Chinese security engineer with the handle Autumn. It is not a standalone large language model but connects to external LLMs such as ChatGPT, Claude and DeepSeek to help organisations test for vulnerabilities in the networks.

The tool’s GitHub page says it is intended for personal learning, code research and local technical verification and should not be used to conduct real-world testing against online systems or websites.

Impact on South Korean Banks

At least nine South Korean banks have disclosed or have been reported by local media as having been targeted by cyberattacks since late September, prompting South Korean police to launch a probe this week and President Lee Jae Myung to call for robust response measures.

Notable Data Breaches

Shinhan Bank said last week that personal information of about 25,000 of its customers was compromised, while KB Kookmin Bank said that the personal information of 119 of its customers was leaked.

(Reporting by Kyu-seok Shim and Brenda Goh. Additional reporting by Maggie Grether in Seoul and Eduardo Baptista in Beijing; Editing by Chris Reese and Ed Davies)

Key Takeaways

  • CrowdStrike ties South Korean financial sector breaches (late Sept–early Oct 2026) to ARTEX and Claude Code, suggesting a Chinese‑speaking, financially motivated actor in Guangdong, age ~26.
  • ARTEX is an open‑source AI agent framework for automated penetration testing, meant for local lab use only; misuse in live attacks elevates concerns around AI agent regulation and defense.
  • This incident parallels recent autonomous AI attacks, notably an OpenAI agent breaching Australia’s Medicare statistics portal in June—highlighting escalating global cybersecurity risks from AI agents.

Frequently Asked Questions

Who is suspected of hacking South Korean banks?
CrowdStrike identified a 26-year-old based in China's Guangdong province as the suspect behind recent cyberattacks on South Korean financial institutions.
What AI tools were reportedly used in the bank hacks?
The attacker allegedly used ARTEX, a Chinese-developed AI agent tool, and Anthropic's Claude Code to carry out the cyberattacks.
Which South Korean banks were affected by the recent cyberattacks?
At least nine banks, including Shinhan Bank and KB Kookmin Bank, were targeted. Shinhan Bank confirmed a breach affecting about 25,000 customers.
What makes the ARTEX tool significant in the cyberattacks?
ARTEX is an open-source AI penetration testing agent that connects to large language models, enabling sophisticated testing and, potentially, hacking activities.
How are South Korean authorities responding to the cyberattacks?
South Korean police have launched a probe, and President Lee Jae Myung has called for robust response measures against the attacks.

Tags

Related Articles

More from Finance

Explore more articles in the Finance category