One AI-assisted attacker breached multiple South Korean banks

A suspected Chinese-speaking attacker used an AI-powered penetration-testing tool in a series of breaches affecting South Korean financial institutions. At Shinhan Bank alone, more than 25,000 records were stolen, while researchers found evidence that the attacker searched for ways to sell the data.

WTF Index TERMINATOR
◄ Terminator 4 Idiocracy 0 ►

AI-assisted automated penetration testing helped one attacker breach multiple banks and steal sensitive customer data.

One AI-assisted attacker breached multiple South Korean banks

A suspected Chinese-speaking attacker broke into multiple South Korean financial institutions between late September and early October 2026, stealing large amounts of data. The reported incident highlights how AI-powered tools can help a single person find and exploit security weaknesses across organizations.

Customer records were among the stolen data

At Shinhan Bank alone, more than 25,000 records were taken. The records included names, contact details, income, and credit limits, according to the Korean newspaper Khan.

The reported information spans both identifying details and financial data. Its theft could therefore expose people to risks tied to their personal and financial circumstances. The source does not describe how the stolen records were used or whether they were sold.

South Korea's financial regulator held an emergency meeting after the breaches. President Lee Jae Myung called for a thorough investigation, indicating that authorities are examining the incident and its impact.

How ARTEX was used

The attacker used ARTEX, a Chinese open-source tool first posted on GitHub in July. ARTEX uses AI language models for automated penetration testing: it searches for security flaws on its own.

The models behind the tool were DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6. Automated testing can take on parts of the work involved in finding weaknesses, which may allow an attacker to move through that process faster.

Researchers also found Claude Code session logs in the attacker's open directories. The logs showed searches for Telegram groups to sell stolen data. That evidence points to an apparent interest in monetizing the information, though the source does not confirm that any sale took place.

Why the incident has drawn attention

Crowdstrike says the case shows how AI tools can enable a single person to carry out large breaches in a short period. That matters because automated tools can help concentrate work that might otherwise require more time or people.

The report connects the South Korean breaches to wider concerns about AI-assisted cyberattacks. The risk is not simply that AI exists, but that tools designed to automate security testing may also be used to identify weaknesses for an attack.

Just days earlier, Anthropic documented that GLM-5.3 can write exploits nearly on par with Mythos Preview, Anthropic's frontier model. The source says Mythos Preview sparked the entire debate in late March 2026. This comparison adds context to why the capabilities of AI models are receiving scrutiny, while the reported bank incident shows a concrete case involving an AI-powered tool.

What is known, and what remains open

The available account identifies the suspected language background of the attacker, the tool and models used, the affected sector, and the scale and type of records stolen at Shinhan Bank. It also reports the response by South Korean officials and the data-sale searches found in session logs.

It does not identify the other financial institutions, explain how the attacker gained access, or say whether the data was ultimately offered for sale. Those details matter to understanding the full scope of the breach, but they are not established in the report.

For now, the incident illustrates a difficult security challenge: tools that automate the search for flaws can also support attacks. The investigation will need to clarify how the breaches unfolded and what happened to the stolen records.