At a Glance
| Actor | Unnamed; likely a Chinese-speaking, financially motivated individual (moderate confidence) |
| Activity | AI-assisted intrusions and data theft |
| Targets | South Korean banks and financial firms |
| Scale | About 68,000 records at seven firms, per Korean press reports; total not confirmed |
| Law enforcement | Regulators opened on-site probes; no arrests announced |
| Sources | CrowdStrike Intelligence; KED Global |
TL;DR
A suspected Chinese-speaking attacker used AI agents to breach several South Korean banks within weeks. CrowdStrike found the attacker’s Claude Code logs and ARTEX settings on open servers. The logs also show interest in selling the stolen data.
What Happened
The campaign ran from late September to early October 2026. At one bank, the attacker reportedly breached a loan inquiry service used by brokers. At another, the target was an employee mobile work system.
CrowdStrike then found open directories on attacker servers. They held Claude Code session histories, ARTEX config files, and Claude memory files. ARTEX ran mainly on DeepSeek, with GLM and Grok used in other sessions. A Chinese-language prompt told the AI how to run its pentests.
The attacker also asked Claude where to sell Korean breach data. In addition, they sought help finding Korean data-sale groups on Telegram.
Who Is Behind It
CrowdStrike has not named a group. It assesses “with moderate confidence” that the attacker is a Chinese speaker and financially motivated. The logs contain personal details that “likely belong to the threat actor.” However, CrowdStrike says it “cannot definitively associate these details” with that person. No one has been charged.
Impact and Scale
KED Global reports nearly 70,000 records exposed at seven firms. Kookmin Bank reported a suspected leak affecting 119 clients, and Hana Bank also reported leaks. Shinhan pledged full compensation. CrowdStrike notes the total number of victims “remains unconfirmed.”
What Comes Next
Korean authorities have warned financial firms to prepare for more attacks. CrowdStrike expects adversaries to keep testing AI tools “to enhance their operational tempo.” Banks should patch exposed web services, enforce MFA on employee apps, and watch for the bursts of automated probing that agentic tools such as the ARTEX AI tool produce.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!