CrowdStrike links AI tools to intrusions targeting South Korean finance
The cybersecurity firm says an unidentified actor used ARTEX and large language models in a campaign against financial organizations. The actor’s identity and the campaign’s full reach remain unconfirmed.
CrowdStrike reported on October 7 that an unidentified actor used an AI-powered testing tool and large language models in intrusions targeting financial organizations in South Korea from late September to early October. The finding gives investigators a technical account of the campaign as several banks confront customer-data breaches, but it does not establish who carried out the attacks or how many organizations were affected.
The cybersecurity firm said it found attacker-controlled infrastructure and examined exposed directories containing Claude Code session histories, configuration files for ARTEX and memory files. ARTEX is an open-source penetration-testing tool developed in China. CrowdStrike said the actor used it alongside large language models, but the available findings do not show that AI alone enabled any particular breach.
What CrowdStrike found in the attack infrastructure
CrowdStrike described two servers associated with the activity. It identified a Hong Kong-based address as the actor’s primary infrastructure and another server hosting ARTEX, which it assessed was likely used in the attacks on South Korean financial organizations. Those observations concern infrastructure examined by the firm; they do not, by themselves, identify the person or group operating it.
In CrowdStrike’s analysis, the ARTEX instance used DeepSeek v4.1-flash as its main large-language-model backend. The firm also found GLM-5.3 and Grok 4.6 in other Claude Code sessions. Naming the tools helps describe the workflow the firm observed, but does not establish which tool was decisive in obtaining access or taking data.
Industry reports cited by CrowdStrike described a breach of one bank’s loan-progress inquiry service used by financial brokers and a compromise of another bank’s employee mobile work-support system. Those service details come from the reports CrowdStrike cited; the firm’s separate analysis examined the infrastructure and files associated with the wider activity. CrowdStrike said the total number of affected organizations was still unconfirmed.
What South Korean banks have disclosed
Seoul Economic Daily reported on October 2 that KB Kookmin Bank said personal and credit information belonging to 119 customers had leaked from a mobile work-support system used by employees. The bank said the incident was unrelated to customer transactions through internet or mobile banking and pledged to compensate losses. The report also said Hana Bank disclosed a leak involving 89 customers after abnormal access to an operations support system; Hana said it blocked the affected servers and access routes.
The same newspaper reported that about 25,000 Shinhan Bank customers were affected by an earlier incident. Its reporting cited experts who found traces associated with ARTEX while cautioning against assigning the attack to a particular country. It also reported that police opened a pre-charge investigation on October 2 into leaks involving Shinhan, KB Kookmin, Hana and Busan banks. Those publicly reported incidents provide context, but the available evidence does not establish their full overlap with the campaign CrowdStrike analyzed.
In an October 1 filing with the US Securities and Exchange Commission, Shinhan Financial Group said an external party had accessed certain Shinhan Bank services and obtained customer information. It said the bank was investigating jointly with authorities and outside cybersecurity experts. At the time of that filing, Shinhan said it could not reasonably quantify the incident’s specific impact on its financial condition, results or business activities. The bank said it was reviewing its security framework and measures to prevent further unauthorized access.
What remains uncertain about the attacker
CrowdStrike assessed, with moderate confidence, that the actor was likely Chinese-speaking and financially motivated. It cited use of the Chinese-developed ARTEX tool and Chinese-language prompts, but did not attribute the activity to a named adversary. A language assessment and a tool’s place of development do not establish the attacker’s nationality or location.
The firm said reviewed sessions included questions about marketplaces for stolen South Korean data and Telegram groups involved in selling such information. It treated those queries as consistent with a possible financial motive. CrowdStrike also cautioned that personal details appearing in one session could not definitively be tied to the actor, leaving the operator’s identity unresolved.
The amount of data taken across the activity, the number of organizations reached and the relationship between individual bank incidents remain open. CrowdStrike’s technical analysis and the banks’ disclosures give different parts of the picture: the former describes observed tools and infrastructure, while the latter records known customer impacts and continuing investigations. Further findings from the banks or investigators would be needed to determine the campaign’s full scope.
Sources and context
- Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean FinanceCrowdStrike
- AI Hacking Hits KB, Hana, Busan Banks After Shinhan BreachSeoul Economic Daily
- Cybersecurity Incident at Shinhan Bank (Form 6-K)U.S. Securities and Exchange Commission (filing by Shinhan Financial Group)
AI-assisted article checked against the listed sources. NewsJaws did not conduct interviews or attend the reported events.
About NewsJaws Desk
AI-assisted reporting and explainers reviewed against the linked source documents. No claim of on-scene reporting or original interviews.