FULL STORY
Korean Banks Hit: The AI Agent Attack Mystery
A wave of hacks hit multiple Korean banks, reportedly involving a Chinese AI agent in what may be the first AI-driven intrusions into global finance. CrowdStrike later said the attacks may have been carried out by a single 26-year-old suspect.
2026-10-07 ~ 2026-10-09 · 2 episodes · 11 posts
Episode 1 · Korean Banks Hacked with Chinese AI Agent in Possible First (2026-10-07, 2 posts)
Hackers used a Chinese AI agent to attack major Korean banks in what may be the first AI-driven intrusion into global finance, WSJ reports. President Lee Jae-myung ordered a swift investigation into signs of AI use in the attacks.
- South Korea Probes Whether AI Models Were Used in Bank Hacks Leaking Customer Data — GaryMarcus · 2026-10-07
- Hackers used a Chinese AI agent to attack South Korea's biggest banks, WSJ reports — deanwball · 2026-10-07
Episode 2 · CrowdStrike: Solo Attacker Used AI Toolchain to Hit Multiple South Korean Banks (2026-10-08, 9 posts)
CrowdStrike has released a report suggesting that last week's cyberattacks on several major Korean banks may have been carried out by a single individual. According to @TechNadu, the attacks involved at least 9 Korean banks, and the suspect is reportedly just 26 years old and allegedly used AI tools to carry out the intrusions.
Confirmed
- Per the CrowdStrike report relayed by @Nunki08, @SOhEigeartaigh and others, the attacker combined the open-source AI penetration testing tool ARTEX with multiple models including DeepSeek v4.1-Flash, GLM-5.3, Grok 4.6, and Claude.
- @TechNadu cites the report noting that ARTEX-related attack traces and Claude Code session logs exposed the attacker's trail, even containing information that could pinpoint their identity — becoming key to solving the case.
- The suspect is 26 years old, and the targets included at least 9 Korean banks.
Why it matters
- The incident is seen as a landmark case of AI tools lowering the barrier to cyberattacks: a single person can launch attacks against major financial institutions using a multi-model toolchain.
- It also illustrates the double-edged nature of AI use — the Claude Code session logs became a crucial source of accountability evidence, showing that AI-assisted attacks still leave traceable digital footprints.
- CrowdStrike: 26-year-old hacker hit 9 Korean banks, Claude Code sessions exposed clues — TechNadu · 2026-10-08
- CrowdStrike Links Korean Bank Hacks to ARTEX and Claude Code Sessions — TechNadu · 2026-10-08
- CrowdStrike: South Korea bank hack may have been a single attacker wielding ARTEX and multiple AI models — S_OhEigeartaigh · 2026-10-08
- CrowdStrike: South Korea bank hack may be one person wielding ARTEX plus multiple AI models — Nunki08 · 2026-10-08
- One hacker took down South Korea's biggest banks using AI tools, CrowdStrike report finds — connoraxiotes · 2026-10-08
- AI security scan: ARTEX + Claude Code used against Korean banks, npm worm, LMCache RCE — brucemacv · 2026-10-08
- CrowdStrike: South Korea bank hacks may be work of one person using ARTEX, DeepSeek, GLM, Grok and Claude Code — dyn___ · 2026-10-09
- Korean bank hackers asked Claude where to sell stolen data; ARTEX agent tied to 7-bank breach — rohanpaul_ai · 2026-10-09
- CrowdStrike: unknown actor used AI-driven ARTEX pentest tool against South Korean finance — rohanpaul_ai · 2026-10-09