At least seven financial institutions in South Korea suffered data breaches from late September to early October, including Shinhan Bank, KB Kookmin Bank and Hana Bank. Among the disclosed cases, about 25,000 customers at Shinhan Bank and roughly 40,000 customers at Yegaram Savings Bank were affected. The leaked information included names, phone numbers, annual income and loan limits. No theft of funds has been identified so far.
Attacks targeted peripheral banking systems
The intrusions mainly hit peripheral business systems used by banks, including loan inquiry services for loan brokers and mobile work systems used by employees. Because several of the attacks involved overlapping IP addresses, South Korean regulators suspect the incidents were carried out by the same attacker.
Lee Jae-myung and CrowdStrike pointed to AI use
On Oct. 6, South Korean President Lee Jae-myung said the attacks may have used AI. On Oct. 7, cybersecurity company CrowdStrike published more detailed evidence.
Investigators said the attacker used two servers. One was located in Hong Kong and was used to control the operation. The other ran ARTEX, an open-source AI penetration testing system. Because some server directories were left exposed, investigators were able to obtain ARTEX configuration files, Claude Code chat logs and AI memory files.
Configuration files showed use of several large models
According to the findings, ARTEX can connect to different large language models, automatically look for vulnerabilities, plan testing steps and call security tools. The configuration files showed the attacker mainly used DeepSeek v4.1-flash to run ARTEX. In addition, the attacker used Claude Code and, in other sessions, called GLM-5.3 and Grok 4.6.
Chat logs exposed other activity and apparent identity clues
The Claude Code chat logs also revealed other activity. The attacker asked where leaked data from South Korea is usually sold and how to find related Telegram trading groups. The attacker also asked AI to draft a resume for a security researcher and requested that it include penetration testing results achieved with ARTEX.
In the prompts used for that resume, the attacker left details including an age of 26, Maoming in Guangdong, South China University of Technology, a phone number and a Telegram account. The listed date of birth did not match the stated age. CrowdStrike said the attacker may use Chinese and may be financially motivated, but the person’s real identity has not been confirmed.
Telegram account holder denied involvement
On Oct. 8, South Korea’s Kyunghyang Shinmun contacted the user of the Telegram account mentioned above. The person said he worked at a convenience store in Henan and claimed someone had deliberately used his information to frame him. Reporters, however, found that the same account also appeared on administrator lists for two Telegram communities linked to DDoS attacks.
That claim has not been verified, and South Korean police are still investigating.

