FULL STORY

Korean Banks Hit: The AI Agent Attack Mystery

A wave of hacks hit multiple Korean banks, reportedly involving a Chinese AI agent in what may be the first AI-driven intrusions into global finance. CrowdStrike later said the attacks may have been carried out by a single 26-year-old suspect.

2026-10-07 ~ 2026-10-09 · 2 episodes · 11 posts

Episode 1 · Korean Banks Hacked with Chinese AI Agent in Possible First (2026-10-07, 2 posts)

Hackers used a Chinese AI agent to attack major Korean banks in what may be the first AI-driven intrusion into global finance, WSJ reports. President Lee Jae-myung ordered a swift investigation into signs of AI use in the attacks.

Episode 2 · CrowdStrike: Solo Attacker Used AI Toolchain to Hit Multiple South Korean Banks (2026-10-08, 9 posts)

CrowdStrike has released a report suggesting that last week's cyberattacks on several major Korean banks may have been carried out by a single individual. According to @TechNadu, the attacks involved at least 9 Korean banks, and the suspect is reportedly just 26 years old and allegedly used AI tools to carry out the intrusions.

Confirmed

  • Per the CrowdStrike report relayed by @Nunki08, @SOhEigeartaigh and others, the attacker combined the open-source AI penetration testing tool ARTEX with multiple models including DeepSeek v4.1-Flash, GLM-5.3, Grok 4.6, and Claude.
  • @TechNadu cites the report noting that ARTEX-related attack traces and Claude Code session logs exposed the attacker's trail, even containing information that could pinpoint their identity — becoming key to solving the case.
  • The suspect is 26 years old, and the targets included at least 9 Korean banks.

Why it matters

  • The incident is seen as a landmark case of AI tools lowering the barrier to cyberattacks: a single person can launch attacks against major financial institutions using a multi-model toolchain.
  • It also illustrates the double-edged nature of AI use — the Claude Code session logs became a crucial source of accountability evidence, showing that AI-assisted attacks still leave traceable digital footprints.