NEWS

ARTEX AI, Claude Agents Used in Cyberattacks on South Korean Banks

A Chinese hacker used the ARTEX AI pentest suite and Claude agents to breach South Korean banks, exposing over 68,000 customer records.

Dylan H.

News Desk

October 10, 2026
8 min read
ARTEX AI, Claude Agents Used in Cyberattacks on South Korean Banks

Chinese Hacker's AI-Driven Pentest Tooling Breaches Multiple Korean Lenders

A Chinese-speaking hacker allegedly combined the ARTEX AI open-source penetration-testing suite with Anthropic's Claude — including Claude Code sessions — to breach a string of South Korean financial institutions between late September and early October 2026, according to BleepingComputer, citing an investigation by cybersecurity firm CrowdStrike. At least nine South Korean banks have disclosed, or been reported by local media as, targets of the campaign, which exposed personal and financial data belonging to more than 68,000 customers and prompted South Korea's government to convene an emergency security meeting.


Incident Details

AttributeValue
Tools reportedly usedARTEX AI (open-source, Chinese-developed agentic pentest suite) + Anthropic Claude, including Claude Code sessions; ARTEX's own backend ran DeepSeek v4.1-flash, reportedly supplemented with GLM-5.3 (Zhipu AI) and Grok 4.6 (xAI)
Confirmed/reported targetsShinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank, BNK Busan Bank, and others — at least nine institutions disclosed or reported as targeted since late September
TimeframeLate September to early October 2026
Records exposedMore than 68,000 individuals in total; approximately 25,000 at Shinhan Bank, roughly 40,000 at Yegaram Savings Bank, and 119 at KB Kookmin Bank
AttributionNot tied to a named adversary group; CrowdStrike assesses with moderate confidence that the operator is a Chinese-speaking, financially motivated individual — possibly a 26-year-old based in Maoming, Guangdong province
Disclosure/response timelineCrowdStrike's findings were reported October 8-9, 2026; ARTEX's developer announced the project would go closed-source on October 8, 2026

What Happened

ARTEX AI is not itself a large language model — it is an agentic penetration-testing framework, originally released as open-source software by a Chinese developer, that orchestrates calls to external LLMs to automate reconnaissance, vulnerability discovery, and exploitation against target networks. According to CrowdStrike, the ARTEX instance used in this campaign ran DeepSeek v4.1-flash as its primary backend, with the operator supplementing it with GLM-5.3 from Zhipu AI and Grok 4.6 from xAI, reportedly accessed through a likely LLM API reseller identified as xcai[.]pro. Separately — and this is the detail that put Anthropic's product in the headline — CrowdStrike found that the same operator ran direct Claude Code sessions alongside the ARTEX-driven activity. ARTEX's own GitHub page reportedly stated the tool was intended for "personal learning, code research and local technical verification" and should not be used for real-world testing against live systems — a disclaimer the campaign plainly ignored.

Using this AI-assisted toolchain, the attacker is reported to have exploited a loan-inquiry service at one bank and an employee mobile work-support system at another to gain footholds and pull customer data. Shinhan Bank disclosed that personal information belonging to roughly 25,000 customers was compromised; KB Kookmin Bank reported a far smaller leak affecting 119 customers; and other outlets, citing Korean media, put the toll at Yegaram Savings Bank near 40,000 records. Hana Bank and BNK Busan Bank were also named among the affected institutions, with some reports placing the total number of disclosed or suspected targets at nine or more South Korean banks and savings institutions since late September. Several targets reported system outages in addition to the data exposure. South Korea's Financial Services Commission issued a public alert on October 6 warning customers to watch for follow-on phishing and loan-scam attempts, and the government held an emergency meeting on critical-infrastructure security as the scope of the campaign became clear.

The attacker's own operational security proved to be the campaign's undoing. Researchers found open, unsecured directories containing Claude Code session histories, ARTEX configuration files, and Claude memory files tied to the attacker's infrastructure. Those logs reportedly showed the individual using Claude to ask where threat actors typically sell Korean breach data and to locate Korean-language Telegram groups for offloading stolen records — suggesting monetization was an afterthought rather than a planned step. In a separate, seemingly unrelated session, the same operator is said to have asked an AI assistant to draft a security-researcher résumé, which in the process surfaced identifying details — a Telegram handle, age, educational background, and a stated location in Maoming, Guangdong province — that CrowdStrike says likely belong to the real person behind the intrusions, along with a possible moniker, "YY," referenced elsewhere in the logs. CrowdStrike cautions that while the personal details are consistent with the ARTEX-linked activity, they are not alone sufficient to conclusively confirm the attacker's identity.

The AI Angle

This incident is fundamentally a story about AI-agent misuse in offensive operations, and coverage has treated the Claude detail as the headline precisely because Anthropic's tooling is a mainstream, widely deployed coding assistant rather than some bespoke "jailbroken" model. Nothing in the public reporting suggests Claude was tricked into doing something it was explicitly built to refuse; rather, a capable agentic coding tool was used for the same kinds of tasks — writing scripts, chaining tool calls, drafting text, answering open-ended questions — that make it useful to any developer, including one conducting an intrusion. ARTEX's architecture reinforces that point: it is explicitly LLM-agnostic, wiring into ChatGPT, Claude, DeepSeek, or any other accessible model as an interchangeable reasoning backend for its automated pentesting workflow.

As of this writing, Anthropic has not issued a public statement specifically addressing this campaign. Reuters reported that both Anthropic and South Korean police did not respond to requests for comment. That silence is notable given how central the Claude Code detail has become in secondary coverage, and it means the model-attribution claim should be read as CrowdStrike's independent forensic assessment rather than a confirmed fact validated by Anthropic itself. It is also not unprecedented: Anthropic has previously disclosed other cases in which Claude was abused in espionage-linked and offensive-cyber operations, and the company has built out detection and account-termination processes partly because its agentic coding tools keep surfacing in attacker toolchains. The one organization that did respond publicly was ARTEX's own developer — posting under the handle "Autumn-27" — who said the tool had been "abused by some bad actors," announced on October 8, 2026 that the project would go closed-source with no further public releases or maintenance, and disclaimed responsibility for any illegal use, while noting ARTEX was built to help organizations test their own defenses. China's foreign ministry, asked about the case at a routine briefing, said it was not familiar with the specifics but that Beijing "consistently opposes and combats hacking activities." The episode fits a broader 2026 pattern in which agentic AI tooling — regardless of which vendor's model sits behind it — is increasingly showing up as a force-multiplier in both attacker and defender workflows, and it is already prompting cyber insurers to re-examine whether existing policy language on "attackers" adequately covers AI-augmented or partially autonomous intrusion activity.

Why This Matters

  1. AI vendors are becoming de facto parties to intrusion narratives even without model misbehavior. Claude was reportedly used for ordinary agentic tasks — not coerced into novel malicious capability — which raises hard questions for every frontier AI lab about what "misuse" detection can realistically catch versus commodity accounts used for commodity tasks.
  2. Financial-sector threat models now need to account for AI-augmented, LLM-agnostic attack tooling. ARTEX's ability to swap in DeepSeek, GLM, Grok, or Claude as an interchangeable backend means defenders can't assume a specific vendor's safeguards will block a given campaign; banks should assume automated reconnaissance and exploitation can scale faster than before.
  3. Attacker OPSEC failures — not technical attribution alone — unmasked this operator. The exposed Claude memory files and session histories, including a self-authored résumé, show that logging and session-history hygiene matters as much for attackers as for defenders; security teams should prioritize monitoring for open directories and exposed AI-tool artifacts tied to known intrusion infrastructure.
  4. Application-layer business logic, not just unpatched CVEs, was the entry point. The reported exploitation of a loan-inquiry service and an employee mobile work-support system underscores that financial institutions should extend AI-assisted penetration testing and code review to internal-facing and partner-facing web applications, not only internet-perimeter systems.
  5. Rapid, voluntary vendor response can still leave derivatives in the wild. ARTEX going closed-source removes the official distribution channel, but forked or cached copies of the open-source release likely persist — security teams should treat ARTEX-style agentic pentest frameworks as an available commodity tool for future attackers regardless of the original project's status.

Sources