The US security company CrowdStrike says an attacker used ARTEX, a freely available AI “agent” built to test networks for weaknesses, to break into South Korean financial firms and take data. Korean investigators had already linked the tool to a breach at Shinhan Bank, according to local reports. The case shows how off-the-shelf AI tools can let one person attack many targets quickly.
What CrowdStrike says (its own assessment)
In a blog post on 7 October, CrowdStrike said it had found infrastructure linked to “a targeted campaign against South Korean financial organizations that resulted in exfiltrated data”, active “from late September to early October 2026” [1]. Its evidence came from folders on attacker-controlled servers that had been left open to the internet. They held session histories from Claude Code (Anthropic’s coding assistant), memory files and ARTEX settings [1].
CrowdStrike describes ARTEX as “a recently released open-source agentic penetration testing (pentesting) tool developed in China” [1]. Penetration testing is the legitimate practice of attacking your own systems, with permission, to find holes. An “agentic” tool hands much of that work to AI models that plan and carry out steps. According to CrowdStrike, this ARTEX setup used DeepSeek v4.1-flash as its main model, with GLM-5.3 (from Zhipu AI) and Grok 4.6 used in other Claude Code sessions [1]. It says the attacker also asked Claude where stolen Korean data is typically sold [1].
CrowdStrike has not named a known group. It says the attacker is “likely a Chinese speaker and financially motivated”, an assessment made “with moderate confidence” based on the tool’s origin and Chinese-language prompts [1]. It adds: “the number of organizations affected remains unconfirmed” [1].
What Korean investigators and reporters say
Reported. On 3 October, The Herald Business quoted an official at the Korea Financial Security Institute. The official said tracing attack addresses and server logs at Shinhan Bank had turned up evidence of ARTEX [2]. The same official drew a line: “It is true that AI was used in the attacks, but the AI did not act independently without human involvement. A hacker used the AI as a tool” [2].
According to that report, the attacks hit staff- and partner-facing systems, not customer online banking. Shinhan said 25,729 people’s data was exposed through a loan-agent inquiry service, and KB Kookmin Bank reported 119 records leaked from an employee mobile work-support system. Yegaram Savings Bank posted a notice of a leak [2]. Reuters reports that at least nine South Korean banks have disclosed attacks or been reported as targets since late September, and that police have opened an inquiry [3]. CrowdStrike’s Adam Meyers told reporters the case “allows one human to target many customers in a very short period of time using the power of AI” [3].
The Hacker News reports that ARTEX’s developer, Autumn-27, says the attacks had nothing to do with them and has made the project closed source: it “will no longer be updated” [4].
For other recent work on how AI agents are attacked and misused, see TSN’s AI agent security roundup (post 20234). CrowdStrike is also one of the founding partners in Anthropic’s new critical-infrastructure programme (post 20097).
What this does not prove
- Who did it. CrowdStrike names no group, and its view of the attacker is held with “moderate confidence” [1].
- That AI ran the attacks by itself. Korea’s Financial Security Institute says a human used the AI as a tool [2].
- That every bank named was hit with ARTEX. CrowdStrike’s blog names no banks; the institute’s ARTEX finding came from Shinhan’s logs [1][2].
- The full scale. CrowdStrike says the number of victims is unconfirmed [1].
- That ARTEX’s developer or the AI model makers took part. They are tools that were misused; the developer denies involvement [4].
The Bottom Line
CrowdStrike’s evidence points to one financially motivated attacker who combined a free AI testing tool with commercial AI models to raid several Korean financial firms in a few weeks. The lesson for defenders is speed: tools built for legitimate testing can multiply what one person can do. For customers of the affected banks, the immediate risk is phishing and loan scams using leaked details.
Sources
- CrowdStrike Counter Adversary Operations, “Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance”, CrowdStrike blog, 7 October 2026 (company research; CrowdStrike’s own assessment). https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/
- Jeong Ho-won, “Exclusive: Chinese AI tool ARTEX used in wave of bank hacks, probe finds”, The Herald Business, 3 October 2026, 04:31 BST (12:31 KST) (reported; English version produced with AI translation, per the publisher). https://biz.heraldcorp.com/article/10892497
- Reuters, “South Korean banks were likely hacked by a China-based actor with an AI agent, CrowdStrike says”, 8 October 2026, as republished by Global Banking & Finance Review (reported). https://www.globalbankingandfinance.com/crowdstrike-china-based-suspect-used-ai-tools-south-korean/
- Ravie Lakshmanan, “ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms”, The Hacker News, 8 October 2026 (reported). https://thehackernews.com/2026/10/artex-ai-pentesting-tool-used-in-data.html

