Compare AIFind AIAI NewsAI How-To
About Us
PrivacyTermsFAQContactContact
AIB Inc.Company info
© 2026 AIB Inc.

South Korean Banks Targeted in AI-Assisted Campaign

South Korean Banks Targeted in AI-Assisted Campaign

Firstpost·Friday, October 9, 2026
  • •CrowdStrike linked a suspected 26-year-old China-based hacker to attacks on South Korean financial organizations using AI tools.
  • •Nearly nine South Korean banks were reported targeted; Shinhan disclosed data exposure affecting about 25,000 customers.
  • •Investigators found Claude Code records and ARTEX files; CrowdStrike described a two-server setup involving a Hong Kong IP address.
  • •CrowdStrike linked a suspected 26-year-old China-based hacker to attacks on South Korean financial organizations using AI tools.
  • •Nearly nine South Korean banks were reported targeted; Shinhan disclosed data exposure affecting about 25,000 customers.
  • •Investigators found Claude Code records and ARTEX files; CrowdStrike described a two-server setup involving a Hong Kong IP address.
  • •CrowdStrike linked a suspected 26-year-old China-based hacker to attacks on South Korean financial organizations using AI tools.
  • •Nearly nine South Korean banks were reported targeted; Shinhan disclosed data exposure affecting about 25,000 customers.
  • •Investigators found Claude Code records and ARTEX files; CrowdStrike described a two-server setup involving a Hong Kong IP address.
  • •CrowdStrike linked a suspected 26-year-old China-based hacker to attacks on South Korean financial organizations using AI tools.
  • •Nearly nine South Korean banks were reported targeted; Shinhan disclosed data exposure affecting about 25,000 customers.
  • •Investigators found Claude Code records and ARTEX files; CrowdStrike described a two-server setup involving a Hong Kong IP address.

CrowdStrike said a 26-year-old suspect, believed to be based in China’s Guangdong province, allegedly used a Chinese-developed AI agent and Anthropic’s Claude Code in a campaign targeting South Korean financial organizations. The cybersecurity company published its report on Wednesday after investigating attacks on South Korean banks.

Nearly nine South Korean banks have disclosed or been reported by local media as targets since late September. South Korean police opened a probe this week, and President Lee Jae Myung called for stringent safety measures. Shinhan Bank said personal information belonging to about 25,000 customers was compromised; KB Kookmin Bank said information for 119 customers was leaked.

CrowdStrike analyzed AI coding tool sessions and infrastructure linked to the campaign. An investigation of an IP address connected to the attack found open directories containing Claude Code session histories, ARTEX configuration files and Claude memory files. They indicated that from late September 2026 to early October 2026, the suspect targeted South Korean financial organizations with extensive activity using ARTEX and other large language models. The targets overlapped with organizations identified in the Korean attacks.

The campaign used a two-server architecture, according to CrowdStrike: an IP address based in Hong Kong served as the primary attacker-controlled infrastructure and hosted an ARTEX instance likely responsible for the attacks in Korea. CrowdStrike said the activity combined agentic AI tools with traditional offensive capabilities and showed how AI tools can help a financially motivated threat actor conduct multiple intrusions within a short time span.

CrowdStrike said a 26-year-old suspect, believed to be based in China’s Guangdong province, allegedly used a Chinese-developed AI agent and Anthropic’s Claude Code in a campaign targeting South Korean financial organizations. The cybersecurity company published its report on Wednesday after investigating attacks on South Korean banks.

Nearly nine South Korean banks have disclosed or been reported by local media as targets since late September. South Korean police opened a probe this week, and President Lee Jae Myung called for stringent safety measures. Shinhan Bank said personal information belonging to about 25,000 customers was compromised; KB Kookmin Bank said information for 119 customers was leaked.

CrowdStrike analyzed AI coding tool sessions and infrastructure linked to the campaign. An investigation of an IP address connected to the attack found open directories containing Claude Code session histories, ARTEX configuration files and Claude memory files. They indicated that from late September 2026 to early October 2026, the suspect targeted South Korean financial organizations with extensive activity using ARTEX and other large language models. The targets overlapped with organizations identified in the Korean attacks.

The campaign used a two-server architecture, according to CrowdStrike: an IP address based in Hong Kong served as the primary attacker-controlled infrastructure and hosted an ARTEX instance likely responsible for the attacks in Korea. CrowdStrike said the activity combined agentic AI tools with traditional offensive capabilities and showed how AI tools can help a financially motivated threat actor conduct multiple intrusions within a short time span.

Read original (English)·Oct 8, 2026
Security#crowdstrike#south korean banks#claude code#artex#agentic ai#cybersecurity#customer data#guangdong