, Incident, CrowdStrike
South Korea bank hack: AI tool used, says CrowdStrike
A security firm says an attacker used ready-made AI tools to hit Korean banks in a few weeks, then asked the AI for a CV listing the results.
- Shinhan Bank breach on 30 Sep 2026, then attacks on other banks, says Korea's regulator
- CrowdStrike links it to ARTEX, a free Chinese AI hacking-test tool
- ARTEX's author stopped public releases on 8 Oct, saying it was misused
The facts
- Confirmed
South Korea's financial regulator says Shinhan Bank had a data breach on 30 Sep, followed by cyberattacks on other big lenders such as KB Kookmin. It called an emergency meeting with banks on 2 Oct.
Financial Services Commission (Korea) press note: emergency response meeting, 2 Oct 2026 (in Korean) - Reported
CrowdStrike says, with moderate confidence, that a Chinese-speaking attacker out for money used ARTEX, a free Chinese-made AI tool built for testing security, plus AI models such as DeepSeek, to break into Korean financial firms and take data.
“the threat actor is likely a Chinese speaker and financially motivated”
Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance (CrowdStrike, 7 Oct 2026) - Confirmed
ARTEX's author posted a notice saying bad actors misused the tool for cyberattacks, that the author had nothing to do with them, and that ARTEX will get no more updates and is now closed to the public.
“ARTEX 项目将不再更新,并转为闭源”
ARTEX security statement, Autumn-27 GitHub profile, 8 Oct 2026 (in Chinese)
Behind the headline
- Confirmed
CrowdStrike says the attacker left its own AI chat logs open on its servers. In them, it asked Claude where stolen Korean data is usually sold, and asked for a CV that listed the hack's results. CrowdStrike says it cannot prove the CV details are really the attacker's.
“asked Claude where threat actors typically sell Korean data breach information”
Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance (CrowdStrike, 7 Oct 2026)
What the labels mean
- Confirmed
- The company or person involved says it, or an official document shows it.
- Reported
- Someone who looked into it firsthand, like a researcher or security firm, says it on the record. The people involved haven't confirmed it.