
AI-powered hacking tools enabled a likely single attacker to breach multiple South Korean banks
Quick Answer
A suspected Chinese-speaking hacker exploited AI-powered tools, including ARTEX, to breach multiple South Korean banks, stealing over 25,000 records from Shinhan Bank.
Quick Take
The attack highlights the cybersecurity risks posed by advanced AI models like GLM-5.3, which can autonomously identify security vulnerabilities.
Key Points
- The attacker breached multiple South Korean banks between late September and early October 2026.
- Over 25,000 records were stolen from Shinhan Bank, including personal and financial information.
- ARTEX, an AI tool, automates penetration testing, identifying security flaws independently.
- Crowdstrike warns that AI tools enable single attackers to execute large-scale breaches quickly.
- Claude Code session logs indicated the attacker sought Telegram groups to sell stolen data.
📖 Reader Mode
~1 min readCrowdstrike reports on an infrastructure hack in South Korea. A suspected Chinese-speaking attacker hit multiple South Korean financial institutions between late September and early October 2026, stealing large amounts of data. At Shinhan Bank alone, more than 25,000 records with names, contact details, income, and credit limits were stolen, according to Korean newspaper Khan. South Korea's financial regulator held an emergency meeting. President Lee Jae Myung called for a thorough investigation.
The attacker used ARTEX, a Chinese open-source tool first posted on GitHub in July that uses AI language models for automated penetration testing, meaning it finds security flaws on its own. The models behind it were DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6. Researchers found Claude Code session logs on the attacker's open directories, showing searches for Telegram groups to sell stolen data.
Crowdstrike says the case shows how AI tools can let a single person pull off massive breaches in a short window, the kind of cybersecurity risk experts have been warning about for months. Just days earlier, Anthropic documented that GLM-5.3 can write exploits nearly on par with Mythos Preview, Anthropic's frontier model and the one that sparked the entire debate in late March 2026.
— Originally published at the-decoder.com
Want this in your inbox every morning?
Daily brief at your local 8am — bilingual EN/中文, free.
More from The Decoder
See more →
An AI model programmed nonstop for 19 days on a single MirrorCode task that cost $2,600 to run
Epoch AI's MirrorCode benchmark reveals Claude Opus 4.7 as the leader with a 56% solve rate, reconstructing a 16,000-line toolkit in 14 hours. Despite this, all models tested struggle with the most complex tasks, highlighting limitations in current AI capabilities. The single task consumed $2,600 over 19 days, raising questions about cost-effectiveness in AI development.

