MediumII Cyber Warfare & Critical Infrastructure8 October 2026, Thursday
CrowdStrike links Korean bank hacks to a China-based AI agent
A CrowdStrike report published on 7 October says the attacker who breached South Korean financial institutions between late September and early October used the open-source ARTEX agent together with commercial language models. The company assessed with moderate confidence that the perpetrator is a Chinese speaker driven by financial gain.
According to the report as described by Security Affairs on 9 October, the attacker entered an application-tracking service used by loan brokers at one bank and a mobile work-support system for employees at another. DeepSeek v4.1-flash served as the main model, with GLM-5.3 and Grok 4.6 used in additional sessions; DeepSeek was accessed through a reseller. CrowdStrike gained visibility through the attacker's own mistake. Exposed directories contained Claude Code session histories, ARTEX configuration files and memory files.
According to the same files, the operator asked the model where Korean data was sold and about sales groups on Telegram; the stolen data was being prepared for sale. iTnews reported on 8 October that at least 9 Korean banks had disclosed being targeted, or had been reported as targets, since late September. Shinhan said data on about 25,000 customers had been exposed and KB Kookmin 119. A Korea Herald report on 5 October had given 153 for KB Kookmin, and the discrepancy has not been resolved.
CrowdStrike did not attribute the activity to a known group. The identity of the suspect pointed to in the report could not be independently verified. ARTEX's developer has closed the source code and stopped updates, but copies in circulation remain usable. Korean police opened an investigation in the week of 8 October.
Talay assessment
Bottom line
The Korean wave shows that agent-based AI let a single profit-driven operator probe more than 9 banks within a few weeks. Attribution points to an individual rather than a state, which means regulatory tightening rather than a diplomatic crisis between Seoul and Beijing. The likeliest path is Korea imposing mandatory audits and external-access restrictions on banks' ancillary systems.
Likely effects
- Korean bankingNegativeWeeks
The attacks targeted loan-broker and employee applications rather than core banking systems; the audit burden shifts to these ancillary systems.
- AI providersUncertain1–6 months
The use of at least 4 different models in one operation puts pressure on model providers to detect abuse and close accounts.
- Turkish financial institutionsNegative1–6 months
External web services opened to loan brokers and field staff create the same cheap entry point at Turkish banks.
Possibilities, ranked
- 1Regulatory tightening60%
Korean financial regulators introduce mandatory audits and external-access restrictions for ancillary systems, and new leak disclosures decline.
Watch: A Financial Services Commission rule on ancillary system security
- 2Wave continues30%
Other operators try the same method with circulating ARTEX copies and new leaks are disclosed at more than 9 institutions.
Watch: New breach notifications from Korean banks
- 3Perpetrator caught10%
Korean police identify the suspect in cooperation with Chinese authorities and a case is filed.
Watch: An investigation statement from the Korean National Police Agency
Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.
Market reaction
Indicators affected
- Banks targeted▼ 9+
- Shinhan customer records▼ 25,000