Science & Tech · Cybersecurity · 1 day ago
AI-assisted attacks hit South Korean financial institutions
CrowdStrike says an attacker used the ARTEX penetration-testing tool and AI models in attacks on South Korean financial institutions from late September to early October 2026.
The exposed session logs showed the operator using Claude Code and other AI models to help conduct the activity.
The Register reports that at least five lenders were affected, while CrowdStrike's account does not confirm the total number of organizations.
Reported targets included services used by financial brokers and an employee mobile work-support system.
Shinhan Bank said about 25,000 customers were affected, while KB Kookmin Bank and Hana Bank reported 119 and 89 respectively.
CrowdStrike says the attacker stole data and sought help finding places to sell Korean breach information, but has not linked the activity to a specific group.
Police are investigating whether one person or an organized group was responsible, and lawmakers plan to question five major commercial banks at an October 19 parliamentary audit.
CrowdStrike says an attacker used the ARTEX AI penetration-testing tool and large language models in attacks on South Korean financial institutions from late September to early October 2026.
The attacks resulted in stolen data, and exposed server directories revealed AI session histories, configuration files and memory files documenting the activity.
The Register, citing The Korea Times, reports that at least five lenders were affected, while Security Affairs says the total number has not been confirmed.
CrowdStrike assessed that the operator was likely financially motivated and Chinese-speaking, but did not link the activity to a specific group.
The exposed logs included a résumé-writing request with personal details that CrowdStrike said may belong to the attacker but could not definitively connect to them.
- Who
- An attacker CrowdStrike assessed was likely Chinese-speaking and financially motivated. The activity has not been linked to a specific group.
- What
- Attacks using ARTEX and large language models targeted South Korean financial institutions and resulted in stolen data.
- When
- From late September to early October 2026.
- Where
- South Korean financial institutions; exposed infrastructure included servers in Hong Kong and at 38.244.50[.]120.
- Why
- CrowdStrike assessed the operator was financially motivated. The sources do not state a definitive motive for each attack.
This story does not have two clearly opposing sides.
Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files, providing direct insight into the threat actor’s operational methodology and tooling.
This activity demonstrates how AI tooling can enable a financially motivated threat actor to conduct multiple intrusions within a short time span.
CrowdStrike Intelligence assesses that adversaries will likely continue to experiment with implementing AI tooling in their operations to enhance their operational tempo and capabilities.
The campaign against South Korean financial organizations took place and ended with stolen data.
Researchers found exposed directories and AI session records on servers associated with the attacks.
The Register published its report on CrowdStrike’s findings.
Security Affairs published an account of CrowdStrike’s research.
Lawmakers approved plans to summon the heads of five major commercial banks to a parliamentary audit.
- Tool
- ARTEX, an open-source penetration-testing tool developed in China
- Reported affected lenders
- At least five, according to The Register citing The Korea Times
- Shinhan Bank customers
- About 25,000 affected, according to the bank
- KB Kookmin customers
- 119 affected, according to the bank
- Hana Bank customers
- 89 affected, according to the bank
- Attacker-linked server
- 38.244.50[.]120 hosted an ARTEX instance and an open directory











