AI-assisted cyberattacks in South Korea have exposed tens of thousands of customer and corporate records at seven financial institutions, with some intrusions taking up to 68 hours to detect. A CrowdStrike investigation on October 7 found traces of ARTEX and Claude Code in attacks carried out from late September into early October.
Key takeaways
- Seven financial firms reported compromised customer, corporate or personnel data.
- CrowdStrike recovered AI-tool records and Chinese-language prompts.
- South Korean regulators ordered checks at around 500 companies.
- The breaches have caused no demonstrated financial contagion or direct theft of bank funds.
According to Cryptopolitan, the evidence included publicly accessible server directories containing the attackers’ own tool records. The findings connect the breaches to AI-assisted activity, while CrowdStrike’s assessment of the operator’s language and motives carries only moderate confidence.
AI cyberattacks in South Korea leave a trail of tool records
CrowdStrike researcher Ashley Campion found Claude Code session records, memory files and configurations linked to ARTEX, an open-source penetration-testing tool developed in China. The recovered material also included Chinese-language prompts.
Alongside large language models, the campaign relied on ARTEX—a tool circulated mainly within Chinese-speaking GitHub communities—to breach South Korean financial institutions and extract data.
Each of the seven affected firms reported a different scale of exposure. Shinhan Bank disclosed 25,727 compromised records, while KB Kookmin and Hana Bank reported 119 and 89 records, respectively. BNK Busan reported that information tied to 11 outsourced developers had been exposed.
Yegaram Savings Bank notified roughly 40,000 affected customers. Welcome Savings Bank disclosed a breach involving 2,200 corporate records, and Hyundai Capital confirmed that 146 loan agents were affected.
Attribution stays uncertain as detection timelines vary
CrowdStrike assessed with moderate confidence that the operator was Chinese-speaking and financially motivated.
That assessment rests on the Chinese-built tooling and recovered Chinese-language prompts, rather than on attribution to a named adversary.
Detection times differed sharply across the banks. Shinhan identified its intrusion within 15 hours, Hana took almost 42 hours, and KB Kookmin detected its breach after 68 hours.
Regulators reverse network-rule plans and order inspections
South Korea canceled plans to expand exemptions from its network-separation rules and ordered security inspections of around 500 companies. At an October 4 meeting, FSC Chairman Lee Eog-weon called for greater vigilance.
Reports out of Korea indicated that hackers focused on weaker external services rather than the banks’ own internal systems. Regulators are now prioritizing tighter security measures, closer scrutiny of third-party vendors, and faster institutional responses to contain how far an attack can spread.
These AI-assisted incidents in South Korea echo wider research pointing to faster-moving adversarial activity. The IMF’s June report found that AI-enabled adversary activity rose 89% between 2024 and 2025, while the average breakout time fell to 29 minutes.
“AI can help attackers find vulnerabilities and exploit them faster, leaving banks less time to respond,” BIS researchers Juan Carlos Crisanto, Adrien Currat and Jeffery Yong wrote in their September paper. They added: “This window to detect, decide on and respond to such attacks has narrowed dramatically.”
Financial contagion has not yet followed the data losses
The Korean breaches have caused no demonstrated financial contagion or direct theft of bank funds. Broader research nevertheless identifies shared technology providers and financial connections as routes through which cyber incidents can spread.
The OECD cautions about these transmission channels, tying breaches to outcomes like deposit withdrawals, tighter lending, declining valuations, and rising borrowing costs, while the BIS voices similar concerns about banks’ shared dependence on the same cloud and AI providers.
PwC’s survey labeled for 2027 found that 84% of security and finance leaders expected cybersecurity budgets to increase. Only 22% would permit AI to operate fully autonomously in defense.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

