AI tool used in attacks on South Korean banks
Cybersecurity firm CrowdStrike says an attacker combined a tool developed in China with language models.
An unknown attacker used an AI-driven penetration-testing programme in a campaign against South Korean financial institutions, according to CrowdStrike. South Korean authorities are investigating data breaches at several banks, but the perpetrator and their motive have not yet been established.
CrowdStrike says the campaign ran from late September to early October 2026. According to the security firm, the attacker used ARTEX, an open-source programme for automated penetration testing developed in China, together with large language models.
Files examined by CrowdStrike included configurations and session data from AI programmes. The company says this indicates that the attacker used AI for reconnaissance, writing code and processing information. That does not mean the attacks were carried out fully autonomously.
South Korean authorities are investigating data breaches at, among others, Hana Bank, KB Kookmin Bank and Shinhan Bank. Yonhap reports that financial regulators and law-enforcement agencies are examining the incidents. CrowdStrike says that at least one bank's service for tracking loan applications by financial intermediaries was compromised.
CrowdStrike has not linked the campaign to any known hacking group. The company refers to an unknown party and describes indications of a Chinese-speaking user. That is not evidence that the Chinese government or an organisation based in China is behind the attacks.
The case is relevant to banks outside South Korea because AI tools can lower the threshold for certain parts of cyberattacks. At the same time, access to systems, stolen login details, vulnerable software and human error remain decisive. AI does not automatically replace the rest of the attack chain.
The initial findings come from a commercial cybersecurity firm that is itself involved in threat research. South Korean investigations may still revise the scale of the data breaches, the techniques used and the identity of the attacker. For now, the main finding is that AI tools were present in the infrastructure under investigation.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The technical findings are based directly on CrowdStrike, while the bank investigations are based on Yonhap. The text explicitly preserves the important uncertainty surrounding the identity of the attacker and possible state involvement.
- confirmed CrowdStrike says ARTEX and large language models were used in attacks on South Korean financial institutions. — This is stated in CrowdStrike's threat report. source
- confirmed South Korean authorities are investigating incidents at Hana Bank, KB Kookmin Bank and Shinhan Bank. — Yonhap names these banks and the investigations by the authorities. source
- confirmed There is no confirmed link to the Chinese government or to a specific hacking group. — CrowdStrike describes an unknown actor; the sources report no proven state attribution. source
Editor's note
The use of ARTEX and language models is a finding by CrowdStrike; South Korean authorities are investigating the bank incidents. There is no confirmed attribution to China or to a specific hacking group.Sources
More on this in Dutch media
- NOS — „kunstmatige intelligentie”
- Het Parool — „kunstmatige intelligentie”
- NRC — „kunstmatige intelligentie”