INDEX 50 flat todaySPLIT OF THE DAY Analyst values Anthropic at $150 billion ahead of reported $2 trillion IPO60 STORIES · 302 REACTIONSANTI-AI 73% · PRO-AI 14% · MIDDLE GROUND 13%LATEST Developer releases Claude Code plugin to shorten verbose replies
Breaking15 sources0 reactions

Suspected Chinese-speaking hacker used AI tool to breach South Korean banks

12 DoomStory toneCyberattack realized, AI misuse enabling large-scale breach
15 sources · The New York Times · The Decoder · Benzinga
  • Doom: ARTEX tool using DeepSeek and GLM-5.3 AI models automated attacks on South Korean banks
  • Doom: More than 25,000 Shinhan Bank customer records stolen; 68,000 total customers affected
  • Doom: CrowdStrike says AI tools may have allowed a single attacker to breach multiple institutions
  • Doom: South Korean officials warn AI enables hacking without specialized technical skills
  • Doom: South Korean megachurches also investigating suspected AI-linked cyberattacks
  • Neutral: Anthropic's Claude named in some coverage as an AI model linked to the attacker
The story in full

A suspected Chinese-speaking attacker hacked multiple South Korean financial institutions, with CrowdStrike attributing the campaign in a report published around October 8, 2026. At Shinhan Bank alone, more than 25,000 customer records were stolen, and South Korean President figures cited a total of 68,000 customers affected. The attacker used ARTEX, an open-source automated penetration-testing tool that runs AI models including DeepSeek and GLM-5.3. South Korean megachurches were also reported to be probing suspected AI-linked attacks.

CrowdStrike's assessment is that AI-assisted tooling allowed what officials believe may have been a single actor to carry out breaches that would previously have required specialized skills. South Korean officials stated that AI models enable attackers to hack with ease even without technical expertise. Separately, Anthropic's Claude was named in Benzinga coverage as another AI model involved, though CrowdStrike's detailed account centered on ARTEX, DeepSeek, and GLM-5.3.

Analysis

380 words

Around October 6 to 8, 2026, CrowdStrike published a report attributing a series of cyberattacks on multiple South Korean financial institutions to a suspected Chinese-speaking actor. The attacker used ARTEX, an open-source automated penetration-testing tool that incorporates AI models including DeepSeek and GLM-5.3. Shinhan Bank alone lost more than 25,000 customer records, and South Korean officials placed the total number of affected customers across institutions at 68,000. Some coverage, including from Benzinga, named Anthropic's Claude as an additional AI model linked to the attacker, though CrowdStrike's detailed account focused on ARTEX, DeepSeek, and GLM-5.3. South Korean megachurches separately announced they were investigating suspected AI-linked attacks around the same period.

The CrowdStrike assessment carries a specific and significant claim: AI-assisted tooling may have allowed what officials believe was a single actor to compromise multiple institutions, achieving a scale and technical sophistication that would previously have required a team with specialized skills. South Korean officials stated directly that AI models now enable attackers to hack with ease even without deep technical expertise. That framing matters because it shifts the conversation from AI being a marginal efficiency boost to potentially being a barrier-lowering force in offensive cyber operations, raising questions about how financial regulators, security vendors, and governments should respond when the skill floor for serious attacks drops.

None of the three camps, Pro-AI, Anti-AI, and Middle Ground, have published reactions to this specific story yet. Anti-AI voices would typically treat this as confirmation that freely available AI models carry real-world harm potential, pointing to the use of open-source tools and Chinese-developed models as evidence that the risks of wide AI access outweigh the benefits. Pro-AI voices would typically argue that the problem lies with inadequate cybersecurity defenses and the open-source distribution of penetration-testing tools, not with AI development itself, and that the same AI capabilities also power the defensive systems catching these attacks. Middle Ground observers would likely call for targeted regulatory focus on how AI is packaged into offensive tooling, rather than broad restrictions on AI models generally.

The most consequential near-term developments to watch are any formal attribution statement from South Korean or allied government agencies naming the actor more specifically, and any regulatory or legislative response from South Korea's financial supervisory bodies regarding AI-assisted threat disclosure requirements for banks.

Where do you stand?

Add your take

0 reader votes

Sign in with Google to pick a side and post. Your vote moves the story's Doom / Boom score.

Sources

17 articles from 15 outlets
  1. The New York TimesHacker Used Chinese-Developed A.I. Tool to Target South Korean Banks, CrowdStrike Says
  2. The DecoderAI-powered hacking tools enabled a likely single attacker to breach multiple South Korean banks
  3. BenzingaCrowdStrike Says Suspected Chinese Hacker Used Anthropic's Claude, AI Agent to Steal South Korean Bank Da
  4. South China Morning PostAnthropic’s Claude AI gets Chinese-language options settings
  5. South China Morning PostAnthropic’s Claude AI gets Chinese-language options settings
  6. The Chronicle PHSuspected Chinese-speaking hacker uses AI to breach South Korean banks – report
  7. Operativ Məlumat MərkəziChinese-speaking hacker used AI to breach South Korean banks, report says
  8. Anadolu AjansıSuspected Chinese-speaking hacker uses AI to breach South Korean banks: Report
  9. QuartzSouth Korean president warns AI used in bank hacks affecting 68,000
  10. WSJThe Morning Risk Report: Hackers Use Chinese AI Tool to Hit South Korean Banks, Exposing New Risk
  11. 1470 & 100.3 WMBDSouth Korean megachurches probe suspected AI-linked cyberattacks
  12. Aaj English TVSouth Korean megachurches probe suspected AI-linked cyberattacks
  13. The Mighty 790 KFGOSouth Korean megachurches probe suspected AI-linked cyberattacks
  14. ReutersSouth Korean megachurches probe suspected AI-linked cyberattacks
  15. The Record from Recorded Future NewsSouth Korean officials believe AI agents were used to hack several banks
  16. Tom's HardwareHackers suspected of using AI agents for cyberattacks on South Korean banks, exposing data from about 25,000 customers — officials believe AI models enable actors 'to hack with ease even without specialized skills'
  17. WSJHackers Use Chinese AI Tool to Hit South Korean Banks, Exposing New Risk