Financially Motivated Hacker Uses Agentic AI to Breach Multiple South Korean Finance Targets
CrowdStrike says a financially motivated operator used agentic AI to breach South Korean banks and steal data.
CrowdStrike reported a financially motivated campaign, active from late September to early October 2026, that used the ARTEX penetration-testing platform and commercial large language models against South Korean financial organizations. Exposed infrastructure showed ARTEX backed by DeepSeek V4.1 Flash, with separate Claude Code sessions using Zhipu AI’s GLM-5.3 and Grok 4.6. Shinhan Bank reported roughly 25,000 customers’ personal information compromised, and KB Kookmin Bank reported 119 affected customers; a broader figure of nine banks is not confirmed for this operator. CrowdStrike has moderate confidence the unidentified operator is Chinese-speaking, and self-reported alias YY remains unverified.