# CrowdStrike Links South Korean Bank Breaches to AI Agent ARTEX

> Source: <https://mlq.ai/news/crowdstrike-links-south-korean-bank-breaches-to-ai-agent-artex/>
> Published: 2026-10-09 14:24:08.881325+00:00

# CrowdStrike Links South Korean Bank Breaches to AI Agent ARTEX

- CrowdStrike identified ARTEX, a China-developed open-source agentic penetration-testing tool, in infrastructure linked to attacks on South Korean financial organizations. <sup>[\[1\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)</sup>
- Shinhan Bank reported that about 25,000 customers had personal information exposed, including names, phone numbers, annual income and loan limits. <sup>[\[2\]](https://www.theinformation.com/briefings/south-korean-banks-hacked-using-chinese-ai-agent-researchers-say)</sup><sup>[\[3\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)</sup>
- South Korean media reported that seven financial firms were affected and that more than 67,000 people may have been exposed. <sup>[\[4\]](https://www.koreatimes.co.kr/business/banking-finance/20261005/ai-powered-attacks-on-banks-expose-technological-lag-in-koreas-financial-cyber-defenses)</sup>
- The operator used DeepSeek V4.1-Flash, Zhipu AI’s GLM-5.3, Grok 4.6 and Anthropic’s Claude Code during the activity. <sup>[\[1\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)</sup><sup>[\[3\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)</sup>

CrowdStrike has linked a series of recent breaches at South Korean financial institutions to an unidentified operator who used ARTEX, an open-source artificial-intelligence penetration-testing agent developed in China. The cybersecurity company said the campaign was active from late September to early October 2026 and resulted in data exfiltration from financial organizations. [\[1\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)

Shinhan Bank said about 25,000 customers were affected. The exposed information included names, phone numbers, annual income and loan limits, according to South Korean reporting. KB Kookmin Bank reported 119 affected customers, while Hana Bank reported exposure involving 89 customers. [\[3\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)

South Korean media reported that seven financial firms had suffered information leaks and that more than 67,000 people may have been affected. CrowdStrike said in its own assessment that the number of organizations involved remained unconfirmed. [\[1\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)[\[4\]](https://www.koreatimes.co.kr/business/banking-finance/20261005/ai-powered-attacks-on-banks-expose-technological-lag-in-koreas-financial-cyber-defenses)

## The Campaign

CrowdStrike said investigators found open directories containing Claude Code session histories, ARTEX configuration files and Claude memory files on infrastructure associated with the attacks. The material provided insight into the operator’s tooling, including a Chinese-language instruction file directing an AI system to conduct penetration-testing activity. [\[1\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)

The company identified a two-server setup involving a Hong Kong-based address and another server hosting an ARTEX instance. CrowdStrike said the ARTEX system used DeepSeek V4.1-Flash as its primary model backend, while the operator also used GLM-5.3 from Zhipu AI and Grok 4.6 in separate Claude Code sessions. [\[1\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)[\[3\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)

At one affected bank, CrowdStrike said the attacker reportedly breached a loan-progress inquiry service used by financial brokers. At another, the attacker compromised an employee mobile work-support system. [\[1\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)

## What the Evidence Shows

CrowdStrike assessed with moderate confidence that the operator was Chinese-speaking and financially motivated, citing Chinese-language prompts and the use of the China-developed ARTEX tool. The company did not attribute the activity to a named adversary. [\[1\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)

The exposed AI sessions included a request to create a résumé for a security researcher. The prompt contained a name, a Chinese university, a Guangdong location and conflicting age information, but CrowdStrike said it could not definitively connect those details to the attacker. [\[1\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)[\[3\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)

Police are investigating whether the operation was conducted by one individual or an organized group. Authorities identified 28 IP addresses connected to the attacks, while noting that many appeared to conceal the operator’s actual location. [\[3\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)

## Response in South Korea

The attacks have prompted a broader investigation into cybersecurity controls surrounding banks and other financial firms. The National Assembly’s Policy Affairs Committee approved plans to summon the heads of five major commercial banks for an October 19 parliamentary audit. [\[3\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)

South Korea’s Financial Services Commission has discussed easing network-separation rules for cybersecurity purposes, allowing financial institutions to use external AI and security services to identify vulnerabilities more quickly. [\[3\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)

Financial Services Commission Chairman Lee Eog-weon acknowledged that the government’s initial response had been inadequate and said AI would ultimately be needed to defend against attacks conducted with AI tools. [\[3\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)

## Why ARTEX Matters

ARTEX is an open-source agentic security tool rather than a standalone language model. In the South Korean campaign, it operated alongside commercial and open-source models, allowing the operator to combine automated penetration-testing workflows with general-purpose AI systems. [\[1\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)[\[2\]](https://www.theinformation.com/briefings/south-korean-banks-hacked-using-chinese-ai-agent-researchers-say)

CrowdStrike’s findings do not establish that the models independently conducted the breaches. They show that an operator used AI-enabled tooling as part of a broader intrusion process that also relied on attacker-controlled infrastructure, proxy addresses and other offensive techniques. [\[1\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)

The report documents the use of agentic AI tooling across multiple financial intrusions in a short period, while the identity, motive and full scope of the operation remain under investigation. [\[1\]](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)[\[3\]](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)

## Companies mentioned

## Further sources

[\[1\] CrowdStrike, “Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean … ↗](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)

[\[2\] The Information, “South Korean Banks Were Hacked Using Chinese AI Agent, Resear… ↗](https://www.theinformation.com/briefings/south-korean-banks-hacked-using-chinese-ai-agent-researchers-say)

[\[3\] The Korea Times, “Korea intensifies efforts to track hackers behind bank cybera… ↗](https://www.koreatimes.co.kr/economy/20261008/korea-intensifies-efforts-to-track-bank-cyberattacks)

[\[4\] The Korea Times, “AI-powered attacks on banks expose technological lag in Korea… ↗](https://www.koreatimes.co.kr/business/banking-finance/20261005/ai-powered-attacks-on-banks-expose-technological-lag-in-koreas-financial-cyber-defenses)

The stories that matter, in one email. Free — unsubscribe anytime.
