South Korean banks were likely hacked by a China-based actor using an AI agent, CrowdStrike says
CRWD•CrowdStrike said a likely China-based 26-year-old used a Chinese-developed AI agent and Anthropic’s Claude Code in cyberattacks targeting at least nine South Korean banks since late September. Shinhan Bank said about 25,000 customers’ personal information was compromised, while KB Kookmin Bank reported 119 customer records leaked.
1. Attacks targeted banks
CrowdStrike said the suspect was likely based in China’s Guangdong province and used ARTEX, a Chinese-developed open-source penetration-testing tool, alongside large language models such as Claude. The attacks have targeted at least nine South Korean banks since late September, prompting police to open an investigation.
2. Customer information exposed
Shinhan Bank said personal information belonging to about 25,000 customers was compromised. KB Kookmin Bank said information belonging to 119 customers was leaked.
3. CrowdStrike assessment
CrowdStrike said the actor was likely Chinese-speaking and financially motivated, based with moderate confidence on ARTEX and Chinese-language prompts. The company said the person also asked Claude about selling Korean breach data and requested a security researcher resume containing personal details that likely belonged to the attacker.




