Suspected lone attacker used AI hacking tools to breach multiple South Korean banks
Overview
A suspected single, Chinese-speaking attacker reportedly breached several South Korean financial institutions in late September and early October 2026, stealing over 25,000 records from Shinhan Bank alone, according to Korean newspaper Khan.
The records reportedly included names, contact details, income, and credit limits.
A CrowdStrike report reportedly indicates the whole campaign may have been carried out by one person, who used ARTEX, a Chinese open-source tool posted on GitHub in July that uses AI language models to automatically find security flaws. Social media posts citing the CrowdStrike report say the attacker also combined DeepSeek v4.1-Flash, GLM-5.3, Grok 4.6, and Claude Code; these model claims come from secondary reporting and have not been independently confirmed here.
AIWritten by AI from the articles below · overview updated Oct 8, 8:59 PM ET
Check the sources:
Article timeline
Follow the coverage from different perspectives. Times are ET.
- The DecoderAI hacking tools let a likely single attacker breach multiple South Korean banks
A suspected Chinese-speaking attacker breached several South Korean financial institutions between late September and early October 2026, reportedly stealing over 25,000 records from Shinhan Bank alone. The attacker used ARTEX, a Chinese open-source tool that uses AI language models to automate finding security flaws, and models named in the report include DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6.
- Andrew CurranSingle Attacker Reportedly Used Multiple AI Tools in South Korean Bank Cyberattack
Last week, several of South Korea's largest banks were hit by a cyberattack. A CrowdStrike report reportedly indicates the entire attack may have been carried out by one person. The attacker reportedly combined the open-source AI penetration tool ARTEX, DeepSeek v4.1-Flash, GLM-5.3, Grok 4.6, and Claude Code.
Heat trend
Not enough continuous observations to show a trend yet.