CrowdStrike said a large-scale cyber campaign that began in late September 2026 and targeted South Korean financial institutions used ARTEX, an open-source AI agent tool developed in China, together with large language models including DeepSeek v4.1-flash and Anthropic’s Claude Code. During the investigation, the security firm said it also found that the attacker had exposed conversations with Claude through a misconfigured public directory, revealing personal details that could point to the operator’s identity.
Campaign began in late September and hit multiple Korean banks
In a report released on Oct. 7, 2026, CrowdStrike said the attacks on South Korea’s financial sector started in late September. Statements from affected banks showed that Shinhan Bank confirmed illegal access to personal data belonging to about 25,000 customers, while Kookmin Bank said 119 customers had personal information exposed.
The targets included a loan progress inquiry system and an employee mobile work support platform. South Korea’s banking sector had already faced a string of intrusions, and the government had previously said traces of a Chinese-language AI hacking tool had been found.
ARTEX was used with several AI models
According to CrowdStrike, the attacker primarily relied on ARTEX, described as an agent-based AI penetration testing tool developed in China. Its setup used DeepSeek v4.1-flash as the main backend and also called Zhipu AI’s GLM-5.3, xAI’s Grok 4.6, and Anthropic’s Claude Code.
CrowdStrike said that combination increased the speed and efficiency of automated vulnerability discovery and attack execution, adding another layer to the role generative AI now plays in both offense and defense.
Open directory exposed Claude session records
For all the sophistication in the attack chain, the operator appears to have made a basic infrastructure mistake. CrowdStrike said it found full Claude Code session logs, configuration files, and memory files in an open directory on a server controlled by the attacker, allowing researchers to reconstruct the workflow in detail.
The records showed prompts asking Claude where South Korean personal data could be sold and requests to search Telegram groups involved in trading Korean data.
Attacker asked Claude to write a cybersecurity résumé
One exchange stood out. The attacker asked Claude to help draft a personal résumé for a cybersecurity researcher and told the model to include the results of the ARTEX-based attack on Korean banks as part of that work history.
That prompt exposed a set of personal details, including:
- Alias: Y.Y
- Age and birth date: listed as 26 years old, with an initially provided birth date of 2007-09-22
- Education: South China University of Technology
- Location: Maoming, Guangdong, China
- Contact details: phone number 17820191556 and Telegram account @YY520CN
In effect, the same AI tooling used to support the intrusion also became a source of identifying clues.
Identity remains unverified as South Korea opens a task force probe
South Korean media reported that a journalist called the phone number listed in the report. A man in Henan who identified himself as a convenience store clerk denied any connection to the case. It remains unclear whether the résumé used the attacker’s real information, someone else’s identity, or fabricated details.
South Korean President Lee Jae-myung raised the case during a State Council meeting, saying AI-enabled cybercrime had caused significant public unease. Police in South Korea have since formed a dedicated task force to investigate.
CrowdStrike points to a Chinese-language user with financial motives
CrowdStrike said it could not determine the attacker’s ultimate attribution with complete certainty. Even so, the firm assessed with medium confidence that the operator was a Chinese-language user motivated by financial gain.
The company also warned that AI agent tools are lowering the barrier to advanced attacks and that threat actors are likely to use AI more often to accelerate operations, putting pressure on companies and financial institutions to strengthen cyber defenses.

