Read as article
Suspect Behind South Korea Bank Hacks Used AI Agent
By @sharedot · · 6 pages
- AI Frontier
- AI Agents
- Cybersecurity
CrowdStrike says a 26-year-old in China's Guangdong province likely used an ARTEX AI agent and Claude Code to attack at least nine South Korean banks.
One Human, One AI Agent, Nine Banks
At least nine South Korean banks have disclosed, or been reported by local media as, targets of cyberattacks since late September. According to a CrowdStrike report published Wednesday, the suspect is likely a China-based 26-year-old who combined ARTEX — a Chinese-developed open-source penetration-testing agent — with Anthropic's Claude Code and other large language models. CrowdStrike's Adam Meyers, senior vice president of counter adversary operations, told reporters this was an example of a human adversary leveraging AI agents to conduct widespread attacks, 'allowing one human to target many customers in a very short period of time using the power of AI.'
Why It's a First for AI Agents
This case is among the clearest demonstrations that a single financially motivated individual — not a named state adversary — can weaponize agentic AI against financial institutions at scale. It follows Australia's disclosure last month that an OpenAI autonomous agent breached a government health statistics portal in June, one of the first known instances of an AI agent hacking a government system. Both incidents are forcing cyber insurers to rethink whether autonomous AI systems fit traditional policy definitions of a cyber attacker, and who bears liability for AI-generated actions that cause a loss.
The Evidence Left in the Sessions
CrowdStrike says it assessed with moderate confidence that the threat actor is a Chinese speaker acting for financial gain, based on use of the Chinese-developed ARTEX tool and observed Chinese-language prompts. During the campaign, the individual asked Claude where threat actors typically sell Korean data-breach information and sought help finding Korean Telegram data-sales groups. In another session, the person asked Claude to draft a security researcher resume containing a Telegram account, age, education and a location in Maoming, Guangdong province — details CrowdStrike reports likely belonged to the attacker.
The Fallout and What Comes Next
Shinhan Bank said last week that personal information of about 25,000 customers was compromised, while KB Kookmin Bank said the personal information of 119 customers was leaked. South Korean police launched a probe this week and President Lee Jae Myung called for a robust response. China's foreign ministry spokesperson Mao Ning said the ministry was not familiar with the case and that China has consistently opposed hacking; a man who answered a number published by CrowdStrike said he had no knowledge of the matter. Anthropic and South Korean police did not respond to requests for comment, and attribution of the activity to a named adversary remains open.