CrowdStrike says China-based suspect used AI tools in South Korean bank hacks CrowdStrike reported on Wednesday that a 26-year-old suspect in Guangdong province, China, used AI coding tools including Anthropic's Claude Code and the open-source ARTEX penetration-testing agent to hack at least nine South Korean banks between late September and early October 2026, with Shinhan Bank reporting about 25,000 customers' personal data compromised and KB Kookmin Bank reporting a leak affecting 119 customers. South Korean police launched a probe this week and President Lee Jae Myung called for robust response measures, while Anthropic, South Korean police and China's foreign ministry did not immediately respond to requests for comment. CrowdStrike identified the suspect through AI coding-tool sessions and infrastructure tied to the campaign, including a Claude session seeking Korean Telegram data-sales groups and a fabricated security-researcher resume listing Maoming, Guangdong. October 8, 2026, Inside AI — A string of cyberattacks on South Korean financial institutions has been linked to a 26-year-old suspect in Guangdong province, China , who allegedly used AI coding tools to orchestrate the intrusions, according to a new report from cybersecurity firm CrowdStrike . The attacks, which occurred between late September and early October, targeted at least nine South Korean banks, including Shinhan Bank and KB Kookmin Bank , compromising the personal data of thousands of customers. The case highlights the growing use of AI agents in cybercrime and raises urgent questions about the preparedness of financial institutions against such threats. CrowdStrike’s investigation, published on Wednesday, identified the suspect through AI coding-tool sessions and infrastructure tied to the campaign. The attacker allegedly employed ARTEX , a Chinese-developed open-source penetration testing tool, alongside large language models like Anthropic’s Claude Code . The report suggests the suspect is a Chinese speaker with financial motives, based on the use of ARTEX and Chinese-language prompts. The attacks come amid rising global concern over AI agents’ potential to breach secure systems. In June, an OpenAI autonomous agent breached a government health statistics portal in Australia, marking one of the first known instances of an AI agent hacking a government system. South Korean police launched a probe this week, and President Lee Jae Myung has called for robust response measures. Shinhan Bank disclosed that personal information of about 25,000 customers was compromised, while KB Kookmin Bank reported a leak affecting 119 customers . The scale of the breaches underscores the vulnerability of financial institutions to AI-driven attacks. Read: South Korea's Lee says AI appears to have been used in bank hacks CrowdStrike’s report detailed the suspect’s interactions with Claude. In one session, the individual asked where threat actors typically sell Korean data breach information and sought help finding Korean Telegram data sales groups. In another, the person requested Claude to create a security researcher resume, including details like a Telegram account, age, educational background, and a location in Maoming , a city in Guangdong. CrowdStrike believes this information likely belongs to the attacker. A man who answered a phone number provided by CrowdStrike in its report said he had no knowledge of the matter. Anthropic, South Korean police, and China’s foreign ministry did not immediately respond to requests for comment. ARTEX, published on GitHub this year by a Chinese security engineer with the handle Autumn , is an open-source AI agent for automated penetration testing. It connects to external LLMs such as ChatGPT, Claude, and DeepSeek to help organizations test for vulnerabilities. The tool’s GitHub page states it is intended for personal learning, code research, and local technical verification, and should not be used for real-world testing against online systems. The incident is likely to intensify scrutiny of AI agents and their potential for misuse. As AI tools become more accessible, the line between legitimate security testing and malicious activity blurs, posing challenges for law enforcement and cybersecurity professionals. Read: OpenAI Agent Breaches Australian Health Data Portal in June South Korean authorities have not yet named the suspect or confirmed CrowdStrike’s findings. The investigation is ongoing, and further details may emerge as police continue their probe.