{"slug": "crowdstrike-links-south-korean-bank-breaches-to-ai-agent-artex", "title": "CrowdStrike Links South Korean Bank Breaches to AI Agent ARTEX", "summary": "CrowdStrike linked breaches at South Korean financial institutions to an unidentified operator who used ARTEX, a China-developed open-source AI penetration-testing agent, in a campaign active from late September to early October 2026 that exfiltrated data. Shinhan Bank said about 25,000 customers had names, phone numbers, annual income and loan limits exposed, while KB Kookmin Bank reported 119 affected customers and Hana Bank 89; South Korean media reported seven financial firms hit and more than 67,000 people potentially affected, a figure CrowdStrike said remained unconfirmed. CrowdStrike said the ARTEX system used DeepSeek V4.1-Flash as its primary model backend, with the operator also using Zhipu AI's GLM-5.3 and Grok 4.6 in separate Claude Code sessions.", "body_md": "# CrowdStrike Links South Korean Bank Breaches to AI Agent ARTEX\n\n- CrowdStrike identified ARTEX, a China-developed open-source agentic penetration-testing tool, in infrastructure linked to attacks on South Korean financial organizations. <sup>[\\[1\\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)</sup>\n- Shinhan Bank reported that about 25,000 customers had personal information exposed, including names, phone numbers, annual income and loan limits. <sup>[\\[2\\]](https://www.theinformation.com/briefings/south-korean-banks-hacked-using-chinese-ai-agent-researchers-say)</sup><sup>[\\[3\\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)</sup>\n- South Korean media reported that seven financial firms were affected and that more than 67,000 people may have been exposed. <sup>[\\[4\\]](https://www.koreatimes.co.kr/business/banking-finance/20261005/ai-powered-attacks-on-banks-expose-technological-lag-in-koreas-financial-cyber-defenses)</sup>\n- The operator used DeepSeek V4.1-Flash, Zhipu AI’s GLM-5.3, Grok 4.6 and Anthropic’s Claude Code during the activity. <sup>[\\[1\\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)</sup><sup>[\\[3\\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)</sup>\n\nCrowdStrike has linked a series of recent breaches at South Korean financial institutions to an unidentified operator who used ARTEX, an open-source artificial-intelligence penetration-testing agent developed in China. The cybersecurity company said the campaign was active from late September to early October 2026 and resulted in data exfiltration from financial organizations. [\\[1\\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)\n\nShinhan Bank said about 25,000 customers were affected. The exposed information included names, phone numbers, annual income and loan limits, according to South Korean reporting. KB Kookmin Bank reported 119 affected customers, while Hana Bank reported exposure involving 89 customers. [\\[3\\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)\n\nSouth Korean media reported that seven financial firms had suffered information leaks and that more than 67,000 people may have been affected. CrowdStrike said in its own assessment that the number of organizations involved remained unconfirmed. [\\[1\\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)[\\[4\\]](https://www.koreatimes.co.kr/business/banking-finance/20261005/ai-powered-attacks-on-banks-expose-technological-lag-in-koreas-financial-cyber-defenses)\n\n## The Campaign\n\nCrowdStrike said investigators found open directories containing Claude Code session histories, ARTEX configuration files and Claude memory files on infrastructure associated with the attacks. The material provided insight into the operator’s tooling, including a Chinese-language instruction file directing an AI system to conduct penetration-testing activity. [\\[1\\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)\n\nThe company identified a two-server setup involving a Hong Kong-based address and another server hosting an ARTEX instance. CrowdStrike said the ARTEX system used DeepSeek V4.1-Flash as its primary model backend, while the operator also used GLM-5.3 from Zhipu AI and Grok 4.6 in separate Claude Code sessions. [\\[1\\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)[\\[3\\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)\n\nAt one affected bank, CrowdStrike said the attacker reportedly breached a loan-progress inquiry service used by financial brokers. At another, the attacker compromised an employee mobile work-support system. [\\[1\\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)\n\n## What the Evidence Shows\n\nCrowdStrike assessed with moderate confidence that the operator was Chinese-speaking and financially motivated, citing Chinese-language prompts and the use of the China-developed ARTEX tool. The company did not attribute the activity to a named adversary. [\\[1\\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)\n\nThe exposed AI sessions included a request to create a résumé for a security researcher. The prompt contained a name, a Chinese university, a Guangdong location and conflicting age information, but CrowdStrike said it could not definitively connect those details to the attacker. [\\[1\\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)[\\[3\\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)\n\nPolice are investigating whether the operation was conducted by one individual or an organized group. Authorities identified 28 IP addresses connected to the attacks, while noting that many appeared to conceal the operator’s actual location. [\\[3\\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)\n\n## Response in South Korea\n\nThe attacks have prompted a broader investigation into cybersecurity controls surrounding banks and other financial firms. The National Assembly’s Policy Affairs Committee approved plans to summon the heads of five major commercial banks for an October 19 parliamentary audit. [\\[3\\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)\n\nSouth Korea’s Financial Services Commission has discussed easing network-separation rules for cybersecurity purposes, allowing financial institutions to use external AI and security services to identify vulnerabilities more quickly. [\\[3\\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)\n\nFinancial Services Commission Chairman Lee Eog-weon acknowledged that the government’s initial response had been inadequate and said AI would ultimately be needed to defend against attacks conducted with AI tools. [\\[3\\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)\n\n## Why ARTEX Matters\n\nARTEX is an open-source agentic security tool rather than a standalone language model. In the South Korean campaign, it operated alongside commercial and open-source models, allowing the operator to combine automated penetration-testing workflows with general-purpose AI systems. [\\[1\\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)[\\[2\\]](https://www.theinformation.com/briefings/south-korean-banks-hacked-using-chinese-ai-agent-researchers-say)\n\nCrowdStrike’s findings do not establish that the models independently conducted the breaches. They show that an operator used AI-enabled tooling as part of a broader intrusion process that also relied on attacker-controlled infrastructure, proxy addresses and other offensive techniques. [\\[1\\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)\n\nThe report documents the use of agentic AI tooling across multiple financial intrusions in a short period, while the identity, motive and full scope of the operation remain under investigation. [\\[1\\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)[\\[3\\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)\n\n## Companies mentioned\n\n## Further sources\n\n[\\[1\\] CrowdStrike, “Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean … ↗](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)\n\n[\\[2\\] The Information, “South Korean Banks Were Hacked Using Chinese AI Agent, Resear… ↗](https://www.theinformation.com/briefings/south-korean-banks-hacked-using-chinese-ai-agent-researchers-say)\n\n[\\[3\\] The Korea Times, “Korea intensifies efforts to track hackers behind bank cybera… ↗](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)\n\n[\\[4\\] The Korea Times, “AI-powered attacks on banks expose technological lag in Korea… ↗](https://www.koreatimes.co.kr/business/banking-finance/20261005/ai-powered-attacks-on-banks-expose-technological-lag-in-koreas-financial-cyber-defenses)\n\nThe stories that matter, in one email. Free — unsubscribe anytime.", "url": "https://wpnews.pro/news/crowdstrike-links-south-korean-bank-breaches-to-ai-agent-artex", "canonical_source": "https://mlq.ai/news/crowdstrike-links-south-korean-bank-breaches-to-ai-agent-artex/", "published_at": "2026-10-09 14:24:08.881325+00:00", "updated_at": "2026-10-09 14:24:11.274815+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "artificial-intelligence", "large-language-models"], "entities": ["CrowdStrike", "ARTEX", "Shinhan Bank", "KB Kookmin Bank", "Hana Bank", "DeepSeek", "Zhipu AI", "Anthropic"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/crowdstrike-links-south-korean-bank-breaches-to-ai-agent-artex", "markdown": "https://wpnews.pro/news/crowdstrike-links-south-korean-bank-breaches-to-ai-agent-artex.md", "text": "https://wpnews.pro/news/crowdstrike-links-south-korean-bank-breaches-to-ai-agent-artex.txt", "jsonld": "https://wpnews.pro/news/crowdstrike-links-south-korean-bank-breaches-to-ai-agent-artex.jsonld"}}