A Single Attacker Armed With AI Tools Likely Hit Several South Korean Banks, CrowdStrike Says

a single attacker armed with ai tools likely hit several south korean banks crowdstrike says A lone attacker, a freely available open-source tool and three AI language models: according to CrowdStrike, that combination was probably all it took to infiltrate multiple South Korean financial institutions and make off with large volumes of data between late September and early October 2026.

A lone attacker, a freely available open-source tool and three AI language models: according to CrowdStrike, that combination was probably all it took to infiltrate multiple South Korean financial institutions and make off with large volumes of data between late September and early October 2026.

The scale of the losses is clearest at Shinhan Bank. Korean newspaper Khan reported that more than 25,000 records were taken from that bank alone, covering names, contact details, income and credit limits.

Authorities moved fast. South Korea’s financial regulator convened an emergency meeting, while President Lee Jae Myung demanded a thorough investigation.

The attack tool was sitting in plain sight on GitHub

Investigators suspect the attacker is Chinese-speaking. Rather than developing bespoke malware, they relied on ARTEX, a Chinese open-source tool that first appeared on GitHub in July.

ARTEX taps AI language models to run automated penetration testing. In practice, it hunts for security weaknesses by itself, with no need for a person to manually probe each system.

In this attack, it ran on three models: DeepSeek v4.1-flash, GLM-5.3 and Grok 4.6. Each comes from a different developer, yet all three had been connected to a single, publicly available tool.

Logs left exposed by the attacker

In directories the attacker had left open, researchers discovered Claude Code session logs. Those logs reveal searches for Telegram groups that could serve as outlets for selling the stolen data.

In other words, AI played a role beyond the intrusion itself, surfacing as well in the groundwork for offloading the stolen information.

A warning researchers have been sounding for months

According to CrowdStrike, the incident demonstrates how AI tools can empower one individual to pull off breaches of this magnitude within a brief period. It is precisely the scenario security experts have cautioned about for months.

The timing makes that caution difficult to dismiss. Only days before, Anthropic had documented that GLM-5.3 is capable of writing exploits nearly on par with Mythos Preview, Anthropic’s frontier model and the one that ignited the whole debate in late March 2026.

For anyone responsible for security at a bank, that is the point to dwell on. A model Anthropic had singled out for near-frontier exploit-writing ability was already built into an open-source tool on GitHub, and it apparently required just one attacker to turn it against Shinhan.