CrowdStrike links South Korean bank hacks to 26-year-old in China using AI coding tools
Cyber Security · Thursday, October 8, 2026 · 12 sources

CrowdStrike links South Korean bank hacks to 26-year-old in China using AI coding tools

US cybersecurity firm CrowdStrike said the suspect behind attacks on South Korean financial institutions from late September to early October may be a 26-year-old in China's Guangdong province, who used the Chinese-developed ARTEX tool and Anthropic's Claude Code. CrowdStrike assessed with moderate confidence that the actor is a Chinese speaker and financially motivated, while noting no named adversary has been attributed. At least nine South Korean banks have been targeted, and Shinhan Bank said about 25,000 customers' data was compromised.

Bottom line — Shinhan Bank's roughly 25,000 affected customers and KB Kookmin Bank's 119 leaked records show how small the reported breaches are, yet the case feeds wider concern about AI agents.

Go deeper 8

  1. CrowdStrike said the suspect asked Claude where stolen Korean data is sold and how to find Telegram groups that trade it, which the firm read as evidence of financial motive.

  2. Reuters reports Australia said an OpenAI autonomous agent breached a government health statistics portal in June, one of the first known AI-agent intrusions into a government system.

  3. ARTEX, published on GitHub this year, does not run its own model but connects to external LLMs including ChatGPT, Claude and DeepSeek; its GitHub page says it is meant for personal learning and not for testing live systems.

  4. Yellow reports that CrowdStrike found the attacker's Claude Code session histories on open directories of attacker-controlled servers, and that ARTEX ran mainly on DeepSeek v4.1-flash.

  5. The Korea Times reports CrowdStrike identified two servers, one in Hong Kong serving as primary infrastructure and another hosting ARTEX.

  6. Yellow reports that on Oct. 3 a Korea Financial Security Institute official said investigators traced Shinhan attack logs to ARTEX and that the hacker did not act alone.

  7. A man who answered a phone number listed in CrowdStrike's report told reporters he had no knowledge of the matter; Anthropic, South Korean police and China's foreign ministry did not respond to requests for comment.

  8. The Korea Times notes the attacker's identity, the full extent of the breaches and the volume of stolen data remain unconfirmed.

Read the reporting 12

dstld. Your daily news summary designed to surface the news that matters from a European perspective. Curated by humans, summarized by AI - always with links back to the original reporting.

Links · Contact
Popular topics · WorldEuropeGamesAI
Last generated: Oct 8, 6:30 PM UTC by wreetco

dstld. Your daily news summary designed to surface the news that matters from a European perspective. Curated by humans, summarized by AI - always with links back to the original reporting.

Links · Contact
Popular topics · WorldEuropeGamesAI
Last generated: Oct 8, 6:30 PM UTC by wreetco