CrowdStrike says a likely lone, Chinese-speaking attacker used AI pentesting tools to breach several South Korean banks
The intruder relied on the open-source ARTEX tool, running mainly on DeepSeek v4.1-flash through Claude Code sessions. More than 25,000 records were reportedly stolen at Shinhan Bank alone.

Evidence: Independent reports. Security stories run only with a named disclosure or independent reporting behind them.
CrowdStrike reports that a suspected Chinese-speaking attacker broke into several South Korean financial institutions between late September and early October. The attacker used ARTEX, a Chinese open-source tool first posted on GitHub in July that uses language models to run penetration tests automatically. According to Yonhap, published by The Korea Times, the attacker mainly used DeepSeek v4.1-flash, with GLM-5.3 and Grok 4.6 as supplements, through Claude Code sessions. The compromised systems included one bank's loan inquiry service for financial brokers and another bank's mobile work-support system for employees. The Decoder, citing the Korean newspaper Khan, reports that more than 25,000 records were stolen at Shinhan Bank alone, including names, contact details, income and credit limits. CrowdStrike says the attacker's main infrastructure was a server in Hong Kong. Claude Code logs found in the attacker's open directories show the attacker asking about marketplaces and Telegram groups for selling stolen Korean data. In one session, the attacker requested a security researcher resume listing an age of 26 and study at South China University of Technology. South Korea's financial regulator held an emergency meeting, and President Lee Jae Myung called for a thorough investigation. The attacker's identity, the full scope of the intrusions and the amount of stolen data are still unconfirmed. CrowdStrike says the case shows how AI tools can let a single person carry out large breaches in a short time.
Sources
- CrowdStrike.comUnknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance
- The Korea TimesChinese-speaking hacker possibly linked to AI-driven attacks on S. Korean banks: report - The Korea Times
- The DecoderAI-powered hacking tools enabled a likely single attacker to breach multiple South Korean banks