AI Hacking Tools Let One Attacker Breach Korean Banks

AI Hacking Tools Let One Attacker Breach Korean Banks

A wave of breaches at South Korean financial institutions appears to have been the work of a very small operation, quite possibly a single person. According to a new report from security firm Crowdstrike, the attacker relied on AI-driven hacking tools to do work that would normally take a larger team. The case adds real-world evidence to a debate that has so far been driven mostly by lab tests and warnings.

What happened

Between late September and early October 2026, an attacker hit several financial institutions in South Korea and took large amounts of data. Crowdstrike believes the person behind it is likely Chinese-speaking and likely acted alone. Neither point has been confirmed.

The best-documented damage so far is at Shinhan Bank. The Korean newspaper Khan reports that more than 25,000 records were stolen there alone. Those records contained customers' names, contact details, income and credit limits. That is enough information for targeted fraud, phishing or identity theft.

The political response was quick. South Korea's financial regulator called an emergency meeting, and President Lee Jae Myung ordered a thorough investigation. For a country that has made AI a national priority, including a state-backed push for a homegrown model, the incident shows how quickly the same technology can be turned against its own banks.

The toolkit: open source, off-the-shelf models

The core of the attack was ARTEX, a Chinese open-source tool that first appeared on GitHub in July. ARTEX automates penetration testing. Penetration testing is the practice of probing systems for weaknesses, normally done by security teams with permission. Instead of a human working through each step, the tool uses AI language models to find security flaws on its own.

In this case, three models were driving ARTEX:

  1. DeepSeek v4.1-flash
  2. GLM-5.3
  3. Grok 4.6

Crowdstrike's researchers also found Claude Code session logs in directories the attacker had left open. Claude Code is Anthropic's coding agent. The logs show searches for Telegram groups where stolen data could be sold. That detail matters. It suggests the AI assistance did not stop at breaking in. It also extended to the work of turning stolen data into money.

None of this required custom malware or a state-sized budget. The tool was public, and the models are commercially available or openly distributed. That is the uncomfortable part of the story.

Why Crowdstrike is worried

Crowdstrike's main point is about scale. AI tools can let one person carry out large breaches in a short period of time. Security experts have warned about exactly this for months. The worry was never that AI would invent brand-new attack techniques overnight. The worry was that it would compress the time, skill and labor needed to run known ones at scale.

The timing makes the report harder to dismiss. Just days before, Anthropic had published findings showing that GLM-5.3 can write exploits almost as well as Mythos Preview. Mythos Preview is Anthropic's own frontier model, and it set off the wider debate about AI-enabled hacking in late March 2026. GLM-5.3 is one of the three models used in the South Korean attacks.

Put the two findings together, and a pattern emerges. Exploit-writing ability that recently looked like a frontier-lab concern is now present in models that attackers are already using in the wild.

Why It Matters

This case suggests the gap between "AI could enable attacks" and "AI did enable attacks" has largely closed. The bigger shift is economic. If one operator with an open-source tool can hit several banks in roughly two weeks, defenders can no longer assume that large breaches require large, well-resourced groups.

It also complicates the safety picture. Restrictions on one vendor's model offer limited protection when attackers can switch between DeepSeek, GLM and Grok inside the same framework. That puts more weight on the defensive side, where vendors are already moving. Examples include Crowdstrike's own work to train AI to attack and defend and Anthropic's effort to give vetted defenders broader access to its models.

What to watch next: whether South Korea's investigation confirms the single-attacker theory, whether more institutions disclose losses, and how GitHub and model providers respond to dual-use tools like ARTEX. It is also worth watching whether regulators elsewhere treat this as a template and start asking banks to test against AI-driven attacks specifically.