AI-assisted attacks hit South Korean banks after Claude Code logs were left exposed

AI-assisted attacks hit South Korean banks after Claude Code logs were left exposed

N
News Editor
2026-10-08 10:15:28
Several major financial institutions in South Korea, including Shinhan Bank, KB Kookmin Bank and Hana Bank, were hit by a string of cyberattacks that exposed the personal data of tens of thousands of customers. A report released by CrowdStrike on Oct. 7 said the activity may have been carried out by a single attacker, despite the scale and complexity of the incidents. According to the investigation, the attacker used ARTEX, an open-source agentic penetration testing tool developed in China, and tied it to several AI models and services, including DeepSeek, Zhipu AI’s GLM, xAI’s Grok and Claude Code. The campaign reportedly targeted a loan-status inquiry service used by financial intermediaries and a mobile office system used by bank staff between late September and early October 2026. The inquiry took an unusual turn when researchers found that the attacker had failed to disable directory listing on a server under their control. That mistake exposed Claude Code session records, configuration files and memory files, allowing investigators to see how the AI tools were configured and what prompts had been used. Among the exposed requests were questions about where stolen South Korean data is typically sold and a request for help drafting a cybersecurity researcher résumé. CrowdStrike said it has not formally attributed the incident to any specific individual or hacking group.

Several major financial institutions in South Korea were hit by cyberattacks in recent days, including Shinhan Bank, KB Kookmin Bank and Hana Bank, with the incidents exposing the personal data of tens of thousands of customers. CrowdStrike said in a report released on Oct. 7 that the operation, while broad in scope, may have been run by a single attacker.

The security firm said the attacker used ARTEX, an open-source AI penetration testing tool, together with DeepSeek, GLM, Grok and Claude Code. Investigators later found that the attacker had left directory listing enabled on a server, exposing AI chat logs and configuration files, including records of requests made to Claude.

Attack activity ran from late September to early October 2026

According to CrowdStrike, the campaign took place from late September to early October 2026. The attacker is suspected of breaching a loan-status inquiry service used by financial intermediaries as well as a mobile office system used by employees at financial institutions, then using that access to obtain and steal sensitive data.

Before the report was published, observers had already noted overlapping IP addresses across the attacks on different victims. Investigators also found the ARTEX name on a server believed to be under the attacker’s control, pointing to a link between the incidents.

CrowdStrike said the attacker used a two-server setup. One server in Hong Kong handled the main operations, while another hosted ARTEX and was used for penetration testing and attack activity aimed at South Korean financial institutions.

ARTEX was tied to several AI models

ARTEX was described as an open-source agentic penetration testing tool developed in China. It was originally built to help security researchers identify system flaws, but the report said it can also be abused by malicious users.

The investigation found that the attacker did not rely on a single model. Instead, several models were integrated into the workflow. CrowdStrike said ARTEX used DeepSeek v4.1-Flash as its main language model backend, while Claude Code sessions also involved Zhipu AI’s GLM-5.3 and xAI’s Grok 4.6.

CrowdStrike said the combination of AI agents and conventional attack techniques allowed the attacker to move against multiple financial institutions in a short period, showing how AI tools are changing both the speed of cybercrime and the skill threshold required to carry it out.

Open directory listing exposed Claude Code files

CrowdStrike said the attacker failed to properly restrict file access on a controlled server, allowing outsiders to browse a large number of files tied to the operation through open directory listing.

Those files included Claude Code’s CLAUDE.md instruction file, Claude memory files, ARTEX configuration files and records from earlier Claude Code sessions. That gave researchers a direct view into how the attacker configured the AI tools, set up the attack environment and what was asked of the models at different stages.

The investigation also found prompts asking Claude where hackers typically sell information obtained from South Korean data breaches and for help locating Korean data-trading groups on Telegram. Based on those exchanges, CrowdStrike said the motive may be tied to selling stolen data for financial gain.

In effect, the attacker used AI to look for weaknesses in financial institutions, then exposed the entire AI-driven workflow because of a basic security mistake on their own infrastructure.

A résumé prompt left behind personal clues

CrowdStrike also found a Claude Code conversation in which the attacker asked the AI to help draft a résumé for a cybersecurity researcher and to present activity involving ARTEX as work achievements.

The résumé-generation prompt included personal details such as a name, phone number, Telegram handle, age, education and place of residence. The material said the person was 26 years old, had an educational background at South China University of Technology and was linked to Maoming in Guangdong province.

Researchers also found that the birth date provided in the same prompt did not match the stated age of 26. In addition, CrowdStrike identified other Claude Code sessions using the same Telegram account that involved vulnerability research on a Telegram NFT gift trading platform and suspected attack activity targeting a Chinese payments platform.

CrowdStrike said it cannot confirm that the personal details in the résumé belong to the attacker and has not formally attributed the incident to any specific person or hacking group. Information circulating online about the identity should therefore be treated as unverified leads rather than a confirmed attribution.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.