Korean bank hackers asked Claude where to sell stolen data; ARTEX agent tied to 7-bank breach
rohanpaul_ai · x · 2026-10-09
- The attacker who breached South Korean banks asked Claude where stolen Korean data could be sold.
- Officials believe an open-source Chinese agent helped breach at least 7 South Korean financial institutions.
- The attacker's own Claude Code session histories, Claude memory files and ARTEX configurations sat in open directories, offering a direct view of how the AI-assisted intrusion campaign was run.
- ARTEX, a recently released Chinese open-source agentic pentesting tool, ran on DeepSeek v4.1-flash, likely via an API reseller, from a host probably used in the Korean attacks.
More from Safety
- We're putting too much faith in AI's ability to say no — nordicinst · 2026-10-09
- MIT Tech Review: We're putting too much faith in AI's ability to say no — MIT Tech Review AI · 2026-10-09
- 'Dystopian': Co-op latest firm to put staff under AI surveillance — marigo · 2026-10-09
- Anthropic's first policy update in over a year bans sustained cruelty toward Claude — AlexTensor · 2026-10-09
- OpenAI exposes Russian and Iranian ops that planted fake stories in real news outlets — The Decoder · 2026-10-09
- Ex-UK AISI comms officer goes independent and questions why AI companies don't act on their own warnings — AaronBergman18 · 2026-10-09