Solo Hacker Used AI Tools to Breach South Korean Financial Organizations and Steal Data
Suspected lone Chinese-speaking hacker used ARTEX AI pentest tool to breach Shinhan, Kookmin, Hana and other South Korean financial firms, stealing customer data.
A suspected lone operator used ARTEX, an open-source China-developed agentic penetration-testing tool, to breach multiple South Korean financial organizations between late September and early October 2026. Victims include Shinhan Bank, Kookmin Bank, Hana Bank, BNK Busan Bank, Hyundai Capital, and several savings banks and online lenders, though core banking platforms were not compromised. CrowdStrike found exposed Claude Code session records and ARTEX configs on actor infrastructure, showing use of DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6 as AI backends. CrowdStrike assessed with moderate confidence the actor was Chinese-speaking and financially motivated, and not linked to a known threat group.