AI-powered hacking tools enabled a likely single attacker to breach multiple South Korean banks
A suspected lone attacker used AI pentest tool ARTEX to breach South Korean banks, stealing over 25,000 Shinhan records.
CrowdStrike reports that a suspected Chinese-speaking attacker compromised multiple South Korean financial institutions between late September and early October 2026 and stole large volumes of data. At Shinhan Bank alone, more than 25,000 records containing names, contact details, income, and credit limits were taken, according to newspaper Khan. The attacker used ARTEX, a Chinese open-source tool published on GitHub in July that automates penetration testing with DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6. Researchers also found Claude Code session logs showing searches for Telegram groups to sell stolen data, and South Korea's financial regulator and President Lee Jae Myung called for an investigation.
- Attacks hit multiple South Korean banks from late September to early October 2026.
- Shinhan Bank lost more than 25,000 records with names, contacts, income, and credit limits.
- The attacker used ARTEX, an open-source AI penetration-testing tool posted in July.
- ARTEX relied on DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6.
- The financial regulator met urgently and the president demanded an investigation.
Full article243 words · extracted from the-decoder.com · click to collapse
Crowdstrike reports on an infrastructure hack in South Korea. A suspected Chinese-speaking attacker hit multiple South Korean financial institutions between late September and early October 2026, stealing large amounts of data. At Shinhan Bank alone, more than 25,000 records with names, contact details, income, and credit limits were stolen, according to Korean newspaper Khan. South Korea's financial regulator held an emergency meeting. President Lee Jae Myung called for a thorough investigation.
The attacker used ARTEX, a Chinese open-source tool first posted on GitHub in July that uses AI language models for automated penetration testing, meaning it finds security flaws on its own. The models behind it were DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6. Researchers found Claude Code session logs on the attacker's open directories, showing searches for Telegram groups to sell stolen data.
Crowdstrike says the case shows how AI tools can let a single person pull off massive breaches in a short window, the kind of cybersecurity risk experts have been warning about for months. Just days earlier, Anthropic documented that GLM-5.3 can write exploits nearly on par with Mythos Preview, Anthropic's frontier model and the one that sparked the entire debate in late March 2026.
AI News Without the Hype – Curated by Humans
Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section.
Text extracted automatically; images, tables and formatting may be missing. Original: https://the-decoder.com/ai-powered-hacking-tools-enabled-a-likely-single-attacker-to-breach-multiple-south-korean-banks/