CrowdStrike links Chinese AI tool to South Korean bank breaches
- Doom: Suspected Chinese-speaking attacker stole over 25,000 customer records from Shinhan Bank alone
- Doom: South Korean president cited 68,000 total customers affected across multiple breached banks
- Doom: CrowdStrike identified ARTEX, an open-source AI penetration tool using DeepSeek and GLM-5.3, as the attack method
- Doom: Officials warned AI models allow attackers to hack without specialized skills
- Doom: South Korean megachurches also probing suspected AI-linked cyberattacks around the same period
The story in full
A suspected Chinese-speaking attacker hacked multiple South Korean financial institutions using ARTEX, an open-source automated penetration-testing tool that runs AI models including DeepSeek and GLM-5.3, according to CrowdStrike. At Shinhan Bank alone, more than 25,000 customer records were stolen, with a separate figure of 68,000 affected customers cited by South Korea's president. The attacks were reported across the period of October 6 to 9, 2026.
CrowdStrike assessed that the case demonstrates how AI-assisted tools can allow a single actor to carry out large-scale intrusions without specialized skills, a concern South Korean officials echoed publicly. Separately, Reuters and several outlets reported that South Korean megachurches were also probing suspected AI-linked cyberattacks, suggesting the same methods may have been applied beyond the banking sector. Anthropic's Claude was named by Benzinga alongside DeepSeek as models involved, though the primary tool identified by CrowdStrike is ARTEX.
Analysis
407 wordsBetween October 6 and 9, 2026, a suspected Chinese-speaking attacker breached multiple South Korean financial institutions using ARTEX, an open-source automated penetration-testing tool that runs AI models including DeepSeek and GLM-5.3. CrowdStrike attributed the intrusions to this toolset and reported that more than 25,000 customer records were stolen from Shinhan Bank alone. South Korea's president cited a broader figure of 68,000 customers affected across the several banks targeted. Separately, South Korean megachurches disclosed that they were also investigating suspected AI-linked cyberattacks around the same period, raising the possibility that the same methods extended beyond the financial sector. Anthropic's Claude was named alongside DeepSeek in some reporting, though CrowdStrike's primary finding centers on ARTEX.
The case matters because it offers one of the most concrete documented examples of AI-assisted tooling being used in a real-world, large-scale intrusion against named institutions. CrowdStrike's assessment, echoed by South Korean officials, is that ARTEX allowed a single actor to carry out sophisticated attacks without requiring deep technical expertise. That claim, if it holds up under further scrutiny, shifts the conversation about AI-enabled threats from theoretical to operational. The genuinely disputed question is how much credit the AI components deserve versus the underlying vulnerabilities in the targeted systems, and whether open-source penetration tools with AI wrappers represent a qualitatively new threat or simply a faster version of existing ones.
None of the three camps, Pro-AI, Anti-AI, and Middle Ground, have published specific reactions to this story yet. The Anti-AI camp would typically treat this as confirmation of warnings that widely accessible AI models lower the barrier to harmful activity and that deploying powerful models as open-source or lightly governed tools creates foreseeable risks. The Pro-AI camp would likely argue that the problem lies in inadequate security practices at the targeted institutions and in the misuse of tools rather than in AI development itself, and might note that defenders also use the same category of AI-assisted tools. The Middle Ground camp would probably call for targeted regulation of high-risk AI applications in offensive security contexts while resisting broad restrictions on the underlying models.
The argument is likely to sharpen once formal attribution findings are published by South Korean authorities or CrowdStrike releases a fuller technical report. Any regulatory response from Seoul, or a policy move by the developers or platforms hosting ARTEX and the models it uses, would also clarify how governments and the AI industry intend to respond to this category of threat.
Where do you stand?
Add your take
0 reader votesSign in with Google to pick a side and post. Your vote moves the story's Doom / Boom score.
Sources
19 articles from 17 outlets- The InformationSouth Korean Banks Were Hacked Using Chinese AI Agent, Researchers Say
- The New York TimesHacker Used Chinese-Developed A.I. Tool to Target South Korean Banks, CrowdStrike Says
- The DecoderAI-powered hacking tools enabled a likely single attacker to breach multiple South Korean banks
- BenzingaCrowdStrike Says Suspected Chinese Hacker Used Anthropic's Claude, AI Agent to Steal South Korean Bank Da
- South China Morning PostAnthropic’s Claude AI gets Chinese-language options settings
- South China Morning PostAnthropic’s Claude AI gets Chinese-language options settings
- The Chronicle PHSuspected Chinese-speaking hacker uses AI to breach South Korean banks – report
- Operativ Məlumat MərkəziChinese-speaking hacker used AI to breach South Korean banks, report says
- Anadolu AjansıSuspected Chinese-speaking hacker uses AI to breach South Korean banks: Report
- QuartzSouth Korean president warns AI used in bank hacks affecting 68,000
- WSJThe Morning Risk Report: Hackers Use Chinese AI Tool to Hit South Korean Banks, Exposing New Risk
- 1470 & 100.3 WMBDSouth Korean megachurches probe suspected AI-linked cyberattacks
- Aaj English TVSouth Korean megachurches probe suspected AI-linked cyberattacks
- The Mighty 790 KFGOSouth Korean megachurches probe suspected AI-linked cyberattacks
- ReutersSouth Korean megachurches probe suspected AI-linked cyberattacks
- NDTV ProfitHackers Turn To Chinese AI Agent To Target South Korea's Biggest Banks, Raising Security Concerns
- The Record from Recorded Future NewsSouth Korean officials believe AI agents were used to hack several banks
- Tom's HardwareHackers suspected of using AI agents for cyberattacks on South Korean banks, exposing data from about 25,000 customers — officials believe AI models enable actors 'to hack with ease even without specialized skills'
- WSJHackers Use Chinese AI Tool to Hit South Korean Banks, Exposing New Risk

