
CrowdStrike traces South Korean bank hacks to AI-using suspect in China
A 26-year-old who may be based in China's Guangdong province used the ARTEX tool and Claude Code against South Korean banks, CrowdStrike says. Seoul has demanded a comprehensive overhaul of financial cyber safeguards.
The CrowdStrike findings
CrowdStrike said in a report published on Wednesday that a campaign against South Korean financial institutions, running from late September to early October, may have been carried out by a 26-year-old based in China's Guangdong province. The firm said it uncovered personal details linked to the suspected attacker while analysing AI coding-tool sessions and infrastructure. The attacker allegedly used ARTEX, an open-source penetration-testing tool published on GitHub this year by a Chinese security engineer using the handle Autumn, alongside Anthropic's Claude Code. ARTEX is not a standalone model. It connects to external large language models such as ChatGPT, Claude and DeepSeek. CrowdStrike also said the suspect likely used a Hong Kong-based IP address against the Korean lenders.
Attribution and the suspect's trail
CrowdStrike did not name a perpetrator, and its assessment carries moderate confidence based on the use of ARTEX and Chinese-language prompts. The firm wrote:
While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated.
In one session the suspect asked Claude where threat actors typically sell Korean data breach information and sought help finding Korean Telegram data sales groups. In another, the person asked Claude to create a security researcher resume listing a Telegram account, an age, an education and a location in Maoming, a city in Guangdong, which CrowdStrike said likely belonged to the attacker. A man who answered a phone number given in the report said he had no knowledge of the matter. Anthropic, South Korean police and China's foreign ministry did not immediately respond to requests for comment. Asked about the reports, a Chinese foreign ministry spokeswoman said she did not know the details, that China opposes and combats hacking in line with the law, and that it rejects disinformation driven by political motives.
Scale of the breaches
South Korean officials said seven financial institutions had their cyber defenses breached last week, leaking the private data of thousands of customers. Local media reports have named at least nine banks as attack targets or have said they were hit since late September. Shinhan Bank announced last week that personal data of about 25,000 customers was breached, and KB Kookmin Bank reported a leak affecting 119 customers. Two of the largest churches in the country and Korea Electric Power Corp. confirmed on Wednesday that their online systems had been illegally accessed, although it is not clear whether the same perpetrator was responsible for all of the attacks. The Financial Supervisory Service said it had identified 28 internet protocol addresses in the United States, Japan, Germany and at least 10 other countries involved in the bank breaches.
- Shinhan Bank
- 25000 customers
- KB Kookmin Bank
- 119 customers
Government response and expert views
Prime Minister Han Seong-sook called on Tuesday for swift measures to halt any further leaks, warning at a Cabinet meeting about AI use in phishing.
This is a serious situation because this incident is believed to have taken advantage of artificial intelligence, and if AI is used in phishing attacks, it could lead to secondary damage.
Han said government agencies, public institutions, the financial sector and private enterprises all need to remain vigilant, as similar methods could spread to other industries and public bodies. President Lee Jae Myung said that signs have emerged that AI models had been used in some of the cyberattacks. Aditya Das, an analyst at Brave New Coin in Auckland, told DW that investigators found traces of ARTEX in the bank logs.
It is freely available on the internet and officials have said explicitly that a Chinese-built tool doesn't mean Chinese attackers.
CrowdStrike's Adam Meyers told reporters on Thursday that the case shows one person can use AI agents to target many customers in a very short time.
This is significant because it allows one person to target many customers in a very short time, leveraging the power of artificial intelligence.
- Campaign against South Korean financial institutions starts in late September
- Prime Minister Han Seong-sook calls for swift measures to halt further leaks
- CrowdStrike publishes its report, and churches and KEPCO confirm illegal access
- CrowdStrike's Adam Meyers speaks to reporters by video call
Reuters also noted that Australia said last month that an OpenAI autonomous agent breached a government health statistics portal in June, one of the first known instances of an AI agent hacking a government system.

