South Korea activated a round-the-clock cybersecurity emergency after hackers used the open-source AI agent ARTEX to breach at least seven financial institutions, exposing personal data belonging to more than 65,000 customers in what officials called one of the most comprehensive regulatory responses the country's financial sector has seen6. CrowdStrike separately reported that the campaign targeted at least nine South Korean banks from late September to early October, with the attacker pairing ARTEX with Anthropic's Claude Code5.
Tools and tradecraft
ARTEX is an autonomous penetration-testing system built on large language models that can independently conduct reconnaissance, identify vulnerable login endpoints, launch attacks, and verify results without continuous human direction. The tool was published on GitHub this year by Li Puhua, a Chinese cybersecurity engineer who goes by the alias Autumn10,12. ARTEX connects to external models including ChatGPT, Claude, and DeepSeek to assist in testing network vulnerabilities. Traces of ARTEX were found in the HTML title of a server believed to have been used in the campaign.
CrowdStrike said the attacker used Claude to ask where threat actors typically sell Korean data-breach information and sought help locating Korean Telegram groups involved in data sales. In one Claude session, the person requested a security-researcher resume containing a Telegram account, age, educational background, and a location in Maoming, Guangdong province. CrowdStrike said the information in that resume likely belonged to the attacker and that the suspect may be a 26-year-old based in Guangdong province1. The firm described the threat actor as likely a Chinese speaker and financially motivated, but stressed the activity had not been attributed to a named adversary. South Korean officials have not said which underlying AI models were used in the bank breaches.
Damage and regulatory response
Shinhan Bank said personal information belonging to about 25,000 customers, including names, phone numbers, and annual income, was compromised7,9. KB Kookmin Bank told The New York Times that 99 customers and 20 current or former employees were affected. Hana Bank said 89 customers had data stolen. Stolen data across institutions also included resident registration numbers and loan limits.
South Korea's National Police Agency opened a formal investigation through its cyber-terror unit on Tuesday. Investigators traced the intrusions to more than two dozen internet addresses spread across roughly a dozen countries, including the United States, Japan, and Germany. South Korea's Financial Services Commission held an emergency meeting and instructed all financial companies to inspect externally accessible IT systems, reduce unnecessary information exposure, and check for missing authentication and access controls15.
President Lee Jae Myung said during a cabinet meeting that signs "emerged of AI being used, causing considerable public concern and anxiety". "Speed is of the essence," he said. "Implement the necessary measures immediately". Lee added that it has become possible "to hack with ease even without specialized skills" using AI.
The case arrives alongside a separate incident in which Australia said last month that an autonomous AI agent breached a government health-statistics portal in June. OpenAI took 84 days to inform the Australian government of that incident, drawing a formal complaint[2].
ANALYSIS The operational detail CrowdStrike disclosed, particularly the attacker's use of Claude to research data-sale channels and generate a cover identity, illustrates how general-purpose coding assistants can lower the skill floor for financially motivated intrusions. ARTEX's ability to chain multiple frontier models into an autonomous penetration-testing workflow extends that dynamic from individual prompt abuse to semi-automated attack pipelines.