South Korean banks breached with AI agents, CrowdStrike says
CrowdStrike says a single operator ran intrusions at South Korean banks — including Shinhan and KB Kookmin — using the open-source ARTEX agent driven by DeepSeek, Claude Code, GLM and Grok.
A single operator used an open-source AI penetration-testing agent and a mix of commercial large language models to run intrusions against multiple South Korean banks in late September and early October, according to CrowdStrike. The firm found the operation after the attacker left infrastructure exposed: open directories holding Claude Code session histories, ARTEX configuration files, and Claude memory files were readable on the internet.
As of writing, CrowdStrike has not published a public technical writeup we could link; the details below come from reporting at Bleeping Computer and Reuters, carried by iTnews, both citing CrowdStrike's analysis. Treat the specifics as single-vendor findings until the report is public.
The tooling
ARTEX is an open-source agentic pentest suite published on GitHub this year by a China-based developer. It is not a model itself — it orchestrates external LLMs. CrowdStrike reported that this operator ran ARTEX with DeepSeek v4.1-flash as the primary backend, supplemented by GLM-5.3 (Zhipu AI) and Grok 4.6, with the DeepSeek access routed through a reseller proxy (xcai[.]pro). The exposed directories also showed Claude Code sessions and memory files in use. After public reporting tied ARTEX to real-world attacks, its developer reportedly made the project closed-source and halted updates.
The practitioner takeaway CrowdStrike pushes: the AI layer let one person chain reconnaissance, exploitation and post-exploitation across several targets at a pace that normally needs a team. The reporting notes the report does not explain how the actor first gained access.
What's confirmed, what's not
Attribution is thin and should stay that way. CrowdStrike's own language, as relayed: "While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated" — an assessment held with moderate confidence. A résumé and a possible profile (a 26-year-old in Guangdong) turned up in the attacker's records, but CrowdStrike flagged that lead as unreliable, with an inconsistent date of birth. No named group. No indictment. Do not repeat the suspect profile as fact.
Confirmed impact comes from the banks themselves, not the vendor:
- Shinhan Bank said personal information of roughly 25,000 customers was compromised.
- KB Kookmin Bank reported 119 customers' personal data leaked.
- Hana Bank appears in the scope of a probe said to cover seven financial firms; no breach figure has been confirmed for it.
Reporting also describes client personal data and credit-card information exposed, some system outages, and an emergency government meeting; President Lee Jae Myung called for stronger protection of critical IT systems. One detail worth flagging: the operator reportedly asked Claude to suggest Telegram groups for selling Korean breach data — but investigators found no concrete monetization plan in the records.
What to do today
This is threat intel, not a patch drop, but there are concrete moves:
- If you run internet-facing services in finance or any high-value sector, hunt for agentic-tool fingerprints in logs — high-tempo, scripted request patterns that chain enumeration into exploitation faster than a human would.
- Review exposed open directories on your own perimeter; this operation was unmasked precisely because the attacker left session logs world-readable. Turn that lesson inward.
- Treat broker/third-party portals and employee mobile-work systems as first-class attack surface — those were the reported entry points at two banks.
- Don't over-index on the "AI" headline. The underlying intrusions still relied on ordinary access that nobody has yet explained. Fix the boring exposure.
Context
This is the latest in a run of stories where AI agents show up inside offensive operations rather than as the subject of a demo. We've covered AI agents used to run SQL injection against government sites, a vendor's own eval harness taking unintended actions after an internet cutoff, and OpenAI's agents scraping Wikimedia. The pattern is consistent: the novelty is operator leverage, not a new class of bug. Until CrowdStrike publishes, this remains one firm's read of one exposed toolkit — useful, but not yet the full picture.