CrowdStrike Traces South Korea's Bank Breaches to One Operator and an AI Pentest Tool
CrowdStrike links the South Korean financial breaches to a single, likely Chinese-speaking operator running ARTEX, an open-source agentic pentest tool, and found the attacker's own AI session logs.

Earlier this week I wrote about South Korean authorities investigating suspected AI-agent attacks on Shinhan, KB Kookmin and Hana Bank (that post is here). CrowdStrike has now published what it found, and it fills in a lot. The campaign ran from late September to early October 2026 and looks like the work of a single operator using an open-source AI penetration-testing tool. That operator also made an unusual mistake: they left their own AI session records on an exposed server.
The campaign
The tool is ARTEX, an agentic pentest console developed in China and published on GitHub on 26 July 2026. A few weeks later it was apparently pointed at banks, savings banks, capital firms and online lenders. Reported victims include Shinhan Bank, Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Hyundai Capital, Welcome Savings Bank and two online lending firms. The full number of affected organisations hasn't been confirmed.
Core internet and mobile banking weren't reported as compromised. The attacker worked the edges. At Shinhan it was a loan-progress inquiry service used by brokers. At Kookmin it was an internal mobile work-support app for employees. In one case the intruder entered random values into a broker service until valid customer numbers came back, then collected the records tied to them.
What the exposed server showed
CrowdStrike found Claude Code session records, ARTEX configuration files and memory files on infrastructure linked to the attacker. ARTEX used DeepSeek v4.1-flash as its main model, probably reached through an API reseller. Other sessions used GLM-5.3 from Zhipu AI and Grok 4.6.
In those sessions the operator asked where stolen South Korean breach data usually gets sold. CrowdStrike assesses, with moderate confidence, that the actor is Chinese-speaking and financially motivated. It hasn't linked them to any known group.
The real change is speed
Nothing here suggests the AI wrote novel exploits. What it did was shrink the busywork: target research, reading scan output, writing scripts, keeping notes. That's enough to let one person test many institutions before any of them notices.
For banks and lenders, a few practical points follow:
- Broker portals, employee apps, support tools and APIs belong in the same security reviews as core banking.
- Rate-limit lookups against customer identifiers and alert when someone is clearly enumerating them.
- Load the published indicators from this campaign into your monitoring.
- Assume attackers now move faster, and measure how long it takes you to go from detection to block.
Source: Cyber Security News — Solo Hacker Used AI Tools to Breach South Korean Financial Organizations, based on CrowdStrike's research