Skip to main content

Morning Overview

CrowdStrike says a hacker used Claude agents and the ARTEX AI suite against South Korean banks as Shinhan, KB Kookmin and Hana reported breaches

CrowdStrike Intelligence says one financially motivated, probably Chinese-speaking operator ran a string of intrusions into South Korean financial firms between late September and early October 2026 with an open-source agentic pentesting tool called ARTEX, working through Claude Code sessions. In the same weeks Shinhan Bank, KB Kookmin Bank and Hana Bank each disclosed that customer records had leaked.

The company’s own report does not name a single bank; the link between the tooling and the three lenders was drawn through the overlap in targets, as BleepingComputer’s reporting describes it.

CrowdStrike’s October 7 evidence: ARTEX, Claude Code logs and DeepSeek

CrowdStrike’s October 7, 2026 report describes ARTEX as a recently released, China-developed open-source tool for automated penetration testing. The firm saw the string “ARTEX” in HTML files on an attacker-controlled server at 38.244.50[.]120, and a second, Hong Kong-based address held open directories full of Claude Code session histories, ARTEX configuration files and Claude memory files. Those directories are how the analysts reconstructed what the operator asked for, and a CLAUDE.md file in one of them carried a Chinese-language pentesting prompt telling the model how to conduct testing.

The primary language model behind the ARTEX instance was DeepSeek v4.1-flash, reached, CrowdStrike judges, through an API reseller at xcai[.]pro. GLM-5.3 from Zhipu AI and Grok 4.6 were added in other Claude Code sessions.

The firm assesses with moderate confidence that the actor is a Chinese speaker and financially motivated, and it does not attribute the activity to a named adversary. Its summary line is that AI tooling “can enable a financially motivated threat actor to conduct multiple intrusions within a short time span.”

Shinhan, KB Kookmin and Hana: three disclosures of different sizes

The three banks reported very different exposures. Per Yonhap’s October 3 report, Shinhan disclosed on October 1 that about 25,000 customers were affected, with names, phone numbers, annual income and borrowing limits exposed; KB Kookmin reported on October 2 that the data of 119 customers had leaked; Hana’s count was 89 customers. BleepingComputer’s October 5 account of the South Korean probe adds that Hana’s incident was limited in scope after its sales-support system was compromised, and that KB Kookmin’s leak involved credit card information.

iTnews’s October 8 report counts at least nine South Korean banks that had disclosed attacks or been reported by local media as targets since late September. CrowdStrike itself describes two unnamed entry points: a loan progress inquiry service that financial brokers use at one bank, and an employee mobile work-support system at another. It says the number of affected organizations remains unconfirmed.

Linking an AI toolkit to the bank breaches, and the official response

Yonhap reported in early October that a server used in the attacks carried an HTML page title with a Chinese-language string associated with ARTEX AI. Neither the banks nor the authorities had confirmed ARTEX’s use in the Shinhan breach at that point, and the string alone did not identify an operator. CrowdStrike’s report then supplied the infrastructure, and BleepingComputer says the overlap between the targets and those in earlier reporting let researchers link the activity with high confidence.

South Korea’s Financial Services Commission held an emergency meeting after a series of attacks on financial institutions and told firms to inspect externally reachable systems. According to BleepingComputer, President Lee Jae Myung ordered a thorough investigation into leaks at financial and public institutions. The commission also issued a consumer alert on October 6 warning customers of affected firms about phishing and loan scams, as Infosecurity Magazine reported.

Motive, an unreliable résumé and a closed-source tool

One session log gives the clearest view of motive. The operator asked Claude where Korean breach data is usually sold and for help finding Korean Telegram data-sales groups, though BleepingComputer notes the records suggest no specific plan to monetize the stolen data. In another session the operator asked for a security-researcher résumé listing the ARTEX results, and the prompt contained a name, age, education and a location in Maoming, Guangdong. CrowdStrike said the details likely belong to the operator but cannot be definitively tied to him, and because the stated birth year changed, BleepingComputer reports the details were judged too unreliable to confirm an identity.

After the attack use came to light, BleepingComputer reports, the ARTEX developer made the project closed-source and stopped updates, but English- and Korean-language derivatives of the existing code already circulate. According to iTnews, Anthropic and South Korean police had not responded to requests for comment when it published.

The figure that stays open is the victim count: Shinhan’s 25,000, KB Kookmin’s 119 and Hana’s 89 come from the banks and local media, while CrowdStrike, the only party with the attacker’s own logs, has not said how many organizations were hit.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview


Morning Overview is reader-supported. Some links in our articles are affiliate links, and we may earn a commission at no extra cost to you. As an Amazon Associate I earn from qualifying purchases. Full disclosure.