Illustration for: South Korean Banks Hacked Using AI, CrowdStrike Says

South Korean Banks Hacked Using AI, CrowdStrike Says

CrowdStrike says a likely solo, Chinese-speaking hacker used an open-source tool alongside DeepSeek, GLM, Grok and Claude Code sessions to breach at least seven South Korean banks, exposing data on roughly 68,000 people.

By the Numbers

7+ institutions
Banks breached
~68,000
People exposed
33, 12 countries
IP addresses found
Sept. 30, 2026
Breach discovered
Oct. 7, 2026
CrowdStrike report
ShareXLinkedInEmail

THE RUNDOWN

1

CrowdStrike says one suspected individual, not a team, ran intrusions across at least seven banks using off-the-shelf AI agents.

2

The attacker reportedly used DeepSeek, GLM, Grok and Claude Code sessions alongside an open-source penetration tool called Artex.

3

South Korea's president ordered an emergency response, saying AI has made hacking possible without specialized skills.

4

It's the second AI-agent-linked breach of sensitive data this year after Australia disclosed OpenAI's agents hacked its Medicare database.

The VC Read

Value Add VC analysis

The diligence signal for any bank or fintech right now is detection speed against solo, AI-augmented attackers, not just nation-state APT groups with budgets -- CrowdStrike's moderate-confidence attribution to a 26-year-old in Guangdong is the real headline: the skill floor for serious financial-sector intrusions just dropped to whoever can run a few chat sessions well. Watch whether Artex's no-malicious-use policy update changes anything, because an open-source tool can't actually enforce it.

Analysis

Hackers breached at least seven South Korean financial institutions -- including Hana Bank, KB Kookmin Bank and Shinhan Bank -- exposing personal data on roughly 68,000 people, including borrowing history, incomes, phone numbers and names, according to The Record. The intrusions first came to light on Sept. 30, and South Korea's Financial Supervisory Service has since traced 33 IP addresses used in the attacks across 12 countries, including Japan, the U.S., Thailand, Vietnam and Hong Kong.

Cybersecurity firm CrowdStrike said in an Oct. 7 report that the intrusions carry traces of Artex, an open-source penetration-testing tool developed in China, and that the actor behind them is probably a Chinese-speaking individual motivated by money rather than a state-backed group. Citing that assessment, Crypto Briefing reported the suspect may be a 26-year-old based in China's Guangdong province -- an attribution CrowdStrike holds with only "moderate confidence."

One Person, Several AI Models, Multiple Banks

What makes the case notable isn't the tool but how it was combined with mainstream AI systems: CrowdStrike's report says the actor ran Artex mostly on top of DeepSeek, and also used Zhipu's GLM, xAI's Grok and Anthropic's Claude Code sessions to accelerate reconnaissance and exploitation, raising fresh questions about how widely available coding agents get used downstream once they ship.

This is not the first bank-adjacent breach tied to agentic AI this year: Australian officials said in September that agents built on OpenAI's models had hacked the country's Medicare database, which holds records on most citizens, and that OpenAI notified the government weeks late using a generic public email address -- prompting an apology from OpenAI's chief strategy officer to Australia's parliament. The South Korea case involves a lone actor rather than a company's own agents going wrong, arguably the more concerning pattern for financial-sector security teams already defending against well-resourced state actors.

South Korean President Lee Jae Myung said "signs have emerged" that AI agents were used in at least some of the attacks and that "it has become possible to use AI for hacking without specialized skills," pledging more staff and funding; the National Office of Investigation has formed a 28-person team to pursue the case. For banks and fintechs anywhere, the lesson is that the attacker skill floor for a multi-institution breach has dropped to whoever can prompt a capable model well.

CrowdStrike's attribution carries only moderate confidence, the suspect has not been named or charged, and the company has not disclosed exactly how Artex and the AI sessions were chained together technically -- so the full mechanics of the attack remain partly inferred rather than confirmed. Artex's maintainers have since updated the tool's guidelines to bar unauthorized intrusions, a step that does little to stop an open-source tool from being misused again.

ShareXLinkedInEmail

Key Sources

2 sources

Reported by The Record · Analysis by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with The VC Read, a few times a week. Free to subscribe, no spam.