Crowdstrike reported that an attacker, likely based in China, used AI-powered hacking tools to breach multiple South Korean financial institutions between late September and early October 2026.
The breach resulted in the theft of large amounts of data, with more than 25,000 records containing names, contact details, income, and credit limits stolen from Shinhan Bank alone, according to the Korean newspaper Khan.
The attacker used ARTEX, a Chinese open-source tool first posted on GitHub in July, which employs AI language models for automated penetration testing. This means the tool can identify security flaws autonomously, significantly reducing the time and expertise required for such attacks.
The AI models used in ARTEX included DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6. Researchers found Claude Code session logs on the attacker's open directories, showing searches for Telegram groups to sell stolen data, indicating a clear intent to monetize the breach.
"The case shows how AI tools can let a single person pull off massive breaches in a short window," said Crowdstrike, highlighting the cybersecurity risk experts have warned about for months. This incident underscores the growing threat posed by AI-driven hacking tools in the hands of a single attacker.
Just days earlier, Anthropic documented that GLM-5.3 can write exploits nearly on par with Mythos Preview, Anthropic's frontier model and the one that sparked the entire debate in late March 2026. This development raises concerns about the rapid advancement of AI capabilities in cybersecurity threats.
Crowdstrike did not say how the breach was detected or what specific measures are being taken to prevent similar attacks. South Korea's financial regulator has held an emergency meeting, and President Lee Jae Myung has called for a thorough investigation into the incident. The situation highlights the urgent need for stronger cybersecurity measures in the face of AI-driven threats.
Source: thedecoder