AI Likely Used By China-Based Hacker to Hit South Korean Banks, CrowdStrike Report Says
10/11/2026 // Chase Codewell // Views

U.S. cybersecurity company CrowdStrike said a single person in China likely used artificial intelligence tools to attack South Korean financial organizations, resulting in data theft, according to a company report released Wednesday.

CrowdStrike [1] said a single person in China likely used artificial intelligence tools to attack South Korean financial organizations, resulting in data theft. The cybersecurity firm assessed with moderate confidence that the attacker was likely a Chinese speaker and financially motivated, based on the use of the China-developed ARTEX penetration-testing tool and observed Chinese-language prompts, according to the report [2].

The company said the activity has not been attributed to a named adversary. At least nine South Korean banks have disclosed or been reported by local media as targets since late September, according to the report [3].

Report Describes AI-Assisted Tradecraft

CrowdStrike [4] said the campaign relied on ARTEX, an open-source penetration-testing tool developed in China, alongside large language models. ARTEX is a recently released open-source agentic pentesting tool, according to the report.

Agentic AI refers to software that can carry out tasks on its own, according to the company.

Adam Meyers, CrowdStrike's senior vice president of counter adversary operations, told reporters on Oct. 8 that the case demonstrates what one person can do. CrowdStrike said the number of affected organizations remains unconfirmed.

Breaches Reported at South Korean Lenders

Hana Bank reported that 89 customers were affected, according to the report [5].

According to industry reports cited by CrowdStrike, an attacker reportedly broke into a loan-processing service used by financial brokers at one bank. In another case, the attacker reportedly compromised a mobile system used by employees, the report said [6].

South Korean police said earlier this week that they had opened an investigation, while South Korean President Lee Jae Myung called for strong response measures, according to officials [7]. The investigation is ongoing and no charges have been announced.

Regulators Urge Fraud Precautions

South Korea's Financial Services Commission and Financial Supervisory Service on Tuesday urged consumers to watch for phishing and loan scams after the breaches. The agencies also launched a month-long special response period intended to prevent criminals from exploiting stolen personal information.

South Korean regulators have told lenders to open help desks and tighten fraud checks while police investigate, according to the agencies. The stolen data included some customers' annual income and personal-loan limits, the kind of detail that fuels convincing scams, according to The Wall Street Journal [8].

The Financial Services Commission and Financial Supervisory Service said consumers should report suspicious messages and avoid clicking links from unknown sources. The agencies did not provide specific details on the number of potential victims.

Servers and AI Models Cited in Report

CrowdStrike said the attacker used two servers: one based in Hong Kong that served as the main base, and another that ran the ARTEX tool and was likely responsible for the South Korean attacks.

Claude Code sessions showed the attacker searching for places where stolen South Korean data could be sold, the report said. According to the company, the attacker asked Claude for help finding Telegram groups where Korean data breaches are traded [9].

CrowdStrike said the suspect was likely a 26-year-old who used a Chinese-developed AI agent and Anthropic's Claude Code. The Epoch Times said it reached out to Anthropic, DeepSeek, xAI and Zhipu AI for comment and did not receive responses by the time of publication.

Chinese Foreign Ministry Responds

Asked about the CrowdStrike report, Chinese Foreign Ministry spokesperson Mao Ning told reporters on Oct. 8 that she was not familiar with it, according to China's Ministry of Foreign Affairs. "China opposes hacking activities and fights these activities in accordance with the law," Mao said.

Mao said China rejects the spread of disinformation driven by a political agenda, and said AI has a significant impact on cybersecurity and that the international community needs to step up cooperation and dialogue. She also called for new international rules to protect cybersecurity.

The investigation by South Korean police is ongoing and no charges have been announced, officials said. CrowdStrike Intelligence assesses that adversaries will likely continue to experiment with implementing AI tooling in their operations to enhance their operational tempo and capabilities, according to the report [5].

References

  1. China-Based Hacker Likely Used AI to Hit South Korean Banks .... https://www.theepochtimes.com/world/china-based-hacker-likely-used-ai-to-hit-south-korean-banks-crowdstrike-report-6101574
  2. S Korean banks likely hacked by China-based actor: CrowdStrike. https://www.taipeitimes.com/News/front/archives/2026/10/09/2003865655
  3. South Korea Bank Hacks: 26-Year-Old in China Suspected. https://www.analyticsinsight.net/news/south-korea-bank-hacks-26-year-old-in-china-suspected
  4. CrowdStrike: Hacker Used ARTEX Agent on Korean Finance Firms. https://fourweekmba.com/ai-crowdstrike-hacker-used-artex-agent-on-korean-finance-firms/
  5. CrowdStrike finds possible bank hacker's CV among exposed AI logs. https://www.theregister.com/cyber-crime/2026/10/08/crowdstrike-finds-possible-bank-hackers-cv-among-exposed-ai-logs/5301908
  6. Chinese-speaking hacker possibly linked to AI-driven attacks on.... https://en.yna.co.kr/view/AEN20261008002200320
  7. China-based hacker used AI agent, Claude Code to target South.... https://www.geo.tv/latest/685630-china-based-hacker-used-ai-agent-claude-code-to-target-south-korean-banks-crowdstrike
  8. Chinese AI agent Artex just hacked 68,000 South Korean bank customers. https://www.naturalnews.com/2026-10-07-chinese-ai-agent-hacked-sk-bank-customers.html
  9. China-based suspect in South Korea bank hacks used AI, Claude.... https://www.businesstimes.com.sg/companies-markets/banking-finance/china-based-suspect-south-korea-bank-hacks-used-ai-claude-tools-crowdstrike-report

Explainer Infographic

Ask BrightAnswers.ai


Take Action:
Support Natural News by linking to this article from your website.
Permalink to this article:
Copy
Embed article link:
Copy
Reprinting this article:
Non-commercial use is permitted with credit to NaturalNews.com (including a clickable link).
Please contact us for more information.
Free Email Alerts
Get independent news alerts on natural cures, food lab tests, cannabis medicine, science, robotics, drones, privacy and more.
App Store
Android App
Brighteon.AI

This site is part of the Natural News Network © 2022 All Rights Reserved. Privacy | Terms All content posted on this site is commentary or opinion and is protected under Free Speech. Truth Publishing International, LTD. is not responsible for content written by contributing authors. The information on this site is provided for educational and entertainment purposes only. It is not intended as a substitute for professional advice of any kind. Truth Publishing assumes no responsibility for the use or misuse of this material. Your use of this website indicates your agreement to these terms and those published here. All trademarks, registered trademarks and servicemarks mentioned on this site are the property of their respective owners.

This site uses cookies
Natural News uses cookies to improve your experience on our site. By using this site, you agree to our privacy policy.
Learn More
Close
Get 100% real, uncensored news delivered straight to your inbox
You can unsubscribe at any time. Your email privacy is completely protected.