Chinese Hacker Deployed AI in Campaign Against South Korean Banks
A suspected Chinese attacker used ARTEX and Claude to breach South Korean banks and steal customer data.
CrowdStrike says a financially motivated, likely Chinese-speaking attacker used the open-source agentic tool ARTEX and Anthropic's Claude from late September to early October 2026 to find vulnerabilities and compromise South Korean financial firms. Attacker infrastructure used DeepSeek v4.1-flash as ARTEX's main model, plus GLM-5.3 and Grok 4.6, and Claude was asked to find Korean Telegram groups for selling stolen data. Shinhan Bank and Yegaram Savings Bank reported breaches affecting about 25,000 and 40,000 people. South Korea's Financial Services Commission warned customers on October 6 about phishing and loan scams.