⚡ Uncle Cat AI Radar
SafetyAgentsIndustry

AI Agents Linked to Breaches at South Korean Banks

CrowdStrike says an attacker used an open-source penetration agent and several language models in intrusions across South Korean financial institutions.

CrowdStrike has linked a suspected campaign against South Korean financial institutions to ARTEX, an open-source AI-assisted penetration-testing tool, together with several large language models. The company said the activity affected multiple organisations between late September and early October, while the findings were disclosed in a report released during the current edition window.

The attacker allegedly combined ARTEX with DeepSeek V4.1-Flash, GLM-5.3 and Grok 4.6 through Claude Code sessions. CrowdStrike’s analysis of exposed infrastructure reportedly included tool configuration files, model-session histories and memory files. The operator appears to have used AI for reconnaissance, vulnerability discovery, attack-path planning and operational scripting rather than for a single isolated task.

South Korean banks had already reported breaches involving peripheral systems, including a loan-inquiry service used by brokers and an employee-support application. Shinhan Bank said roughly 25,000 customers were affected, while other institutions reported smaller exposures. Investigators have not confirmed the attacker’s identity, the total number of victims or whether every incident in the wider wave came from the same operator.

The significance is less about proving that AI independently hacked a bank than about documenting a plausible workflow in which one operator can coordinate specialised tools and general-purpose models across several targets. It also exposes a defensive weakness: externally reachable business-support systems may be less protected than core banking infrastructure. The campaign remains an attribution case, not a settled verdict on model responsibility, but it gives financial-sector defenders a concrete playbook to test against.

Sources