Editorial illustration for Single Attacker Breached South Korean Banks Using AI Tool ARTEX
Single Attacker Breached South Korean Banks Using AI...
More than 25,000 customer records vanished from Shinhan Bank's systems sometime between late September and early October 2026, part of a wider breach that hit several South Korean financial institutions in the same window. The stolen data included names, contact details, income figures, and credit limits, according to the Korean newspaper Khan. South Korea's financial regulator called an emergency meeting once the scale of the theft became clear, and President Lee Jae Myung demanded a full investigation into how it happened.
Crowdstrike, which investigated the intrusion, says the evidence points to a single attacker, likely Chinese-speaking, working alone. That's the detail that makes this case worth attention: one person, not a coordinated team, managing to breach multiple banks in a short stretch of time. The tool behind it was ARTEX, an open-source penetration testing framework posted to GitHub in July that runs on AI language models rather than manual scripting. Investigators also found traces of the attacker's other activity sitting in exposed directories online, including logs showing an entirely different piece of software in use.
Crowdstrike says the case shows how AI tools can let a single person pull off massive breaches in a short window, the kind of cybersecurity risk experts have been warning about for months. Just days earlier, Anthropic documented that GLM-5.3 can write exploits nearly on par with Mythos Preview, Anthropic's frontier model and the one that sparked the entire debate in late March 2026.
Why this matters
A single attacker with an open-source tool and access to three or four frontier models just put real dents in South Korea's banking sector. That ratio, one person to multiple financial institutions, is the part worth sitting with. ARTEX didn't need a nation-state budget.
It needed GitHub, DeepSeek v4.1-flash, GLM-5.3, Grok 4.6, and apparently some Claude Code sessions along the way, stitched together into something that finds and exploits flaws without much hand-holding. For founders building on these same model APIs, the uncomfortable fact is that the defensive and offensive tooling draw from an identical shelf. For researchers, this is a live case study in what automated pen-testing looks like once it escapes the lab and lands on 25,000 Shinhan Bank customers' income and credit data.
We'd expect more disclosures like this, not fewer, as these frameworks spread past their original authors. Worth watching: whether Korean regulators name the models explicitly in any response, and whether DeepSeek, Zhipu, or xAI say anything about how their systems got used here.
Further Reading
- Chinese-speaking hacker possibly linked to AI-driven attacks on S. Korean banks: report - Yonhap News Agency
- [EXPLAINER] How AI emerged as new threat in Korea's bank hacking crisis - The Korea Times
- Security Tool ARTEX Misused in Cyberattacks on South Korean Banks - The Chosun Daily
- South Korea Probes Suspected AI Use in Financial Sector Breaches - eSecurity Planet
- South Korean Financial Institutions Face Cyberattacks, AI Suspected - SC Media