CrowdStrike [1] said a single person in China likely used artificial intelligence tools to attack South Korean financial organizations, resulting in data theft. The cybersecurity firm assessed with moderate confidence that the attacker was likely a Chinese speaker and financially motivated, based on the use of the China-developed ARTEX penetration-testing tool and observed Chinese-language prompts, according to the report [2].
The company said the activity has not been attributed to a named adversary. At least nine South Korean banks have disclosed or been reported by local media as targets since late September, according to the report [3].
CrowdStrike [4] said the campaign relied on ARTEX, an open-source penetration-testing tool developed in China, alongside large language models. ARTEX is a recently released open-source agentic pentesting tool, according to the report.
Agentic AI refers to software that can carry out tasks on its own, according to the company.
Adam Meyers, CrowdStrike's senior vice president of counter adversary operations, told reporters on Oct. 8 that the case demonstrates what one person can do. CrowdStrike said the number of affected organizations remains unconfirmed.
Hana Bank reported that 89 customers were affected, according to the report [5].
According to industry reports cited by CrowdStrike, an attacker reportedly broke into a loan-processing service used by financial brokers at one bank. In another case, the attacker reportedly compromised a mobile system used by employees, the report said [6].
South Korean police said earlier this week that they had opened an investigation, while South Korean President Lee Jae Myung called for strong response measures, according to officials [7]. The investigation is ongoing and no charges have been announced.
South Korea's Financial Services Commission and Financial Supervisory Service on Tuesday urged consumers to watch for phishing and loan scams after the breaches. The agencies also launched a month-long special response period intended to prevent criminals from exploiting stolen personal information.
South Korean regulators have told lenders to open help desks and tighten fraud checks while police investigate, according to the agencies. The stolen data included some customers' annual income and personal-loan limits, the kind of detail that fuels convincing scams, according to The Wall Street Journal [8].
The Financial Services Commission and Financial Supervisory Service said consumers should report suspicious messages and avoid clicking links from unknown sources. The agencies did not provide specific details on the number of potential victims.
CrowdStrike said the attacker used two servers: one based in Hong Kong that served as the main base, and another that ran the ARTEX tool and was likely responsible for the South Korean attacks.
Claude Code sessions showed the attacker searching for places where stolen South Korean data could be sold, the report said. According to the company, the attacker asked Claude for help finding Telegram groups where Korean data breaches are traded [9].
CrowdStrike said the suspect was likely a 26-year-old who used a Chinese-developed AI agent and Anthropic's Claude Code. The Epoch Times said it reached out to Anthropic, DeepSeek, xAI and Zhipu AI for comment and did not receive responses by the time of publication.
Asked about the CrowdStrike report, Chinese Foreign Ministry spokesperson Mao Ning told reporters on Oct. 8 that she was not familiar with it, according to China's Ministry of Foreign Affairs. "China opposes hacking activities and fights these activities in accordance with the law," Mao said.
Mao said China rejects the spread of disinformation driven by a political agenda, and said AI has a significant impact on cybersecurity and that the international community needs to step up cooperation and dialogue. She also called for new international rules to protect cybersecurity.
The investigation by South Korean police is ongoing and no charges have been announced, officials said. CrowdStrike Intelligence assesses that adversaries will likely continue to experiment with implementing AI tooling in their operations to enhance their operational tempo and capabilities, according to the report [5].