An individual hacker leveraged an AI-based penetration testing tool, ARTEX, to infiltrate multiple financial institutions in South Korea, resulting in the theft of sensitive customer and employee information. This incident occurred between late September and early October 2026, targeting various banks and online financial services, showcasing how open-source AI tools can facilitate large-scale cyber intrusions by a single operator.
Extent of the Breach
The breaches impacted several financial entities, including banks, savings banks, capital firms, and online lenders. Notably, systems less protected than core banking platforms were compromised. At Shinhan Bank, for instance, the hacker accessed a service used for loan progress inquiries by financial brokers, while Kookmin Bank’s internal mobile work-support system was also infiltrated. The attack extended to other organizations like Hana Bank, BNK Busan Bank, and Hyundai Capital, but the total number of affected entities remains uncertain.
CrowdStrike analysts identified the tools and infrastructure used in these attacks, revealing ARTEX configuration files and other artifacts. These findings provide insights into the hacker’s strategies, AI model choices, and operational workflow. Although not linked to any known threat group, the hacker is suspected to be financially motivated and possibly Chinese-speaking.
ARTEX and Its Role
ARTEX, developed in China, is an open-source penetration testing tool typically used by security teams for system testing and vulnerability assessment. However, in this case, the tool was repurposed for malicious activities against South Korean financial entities. Released on GitHub in July 2026, ARTEX quickly transitioned from a public project to a tool for real-world cyber attacks. The breaches primarily targeted connected services with weaker security controls, avoiding core banking systems.
The method involved entering random values into a loan-broker service to identify valid customer numbers, then extracting related data. This approach highlights how systems with smaller, yet valuable data sets became targets for the hacker.
AI-Driven Cybercrime and Future Implications
CrowdStrike’s investigation revealed a two-server setup, with one server in Hong Kong serving as the main infrastructure and another hosting the ARTEX instance involved in the breaches. The ARTEX system utilized multiple AI models, including DeepSeek v4.1-flash and GLM-5.3, indicating the hacker’s use of AI for diverse tasks such as research and command generation, rather than relying on a single service.
The exposed sessions also showed attempts to determine where to sell the stolen data, suggesting financial gain as the primary motive. This case underscores the growing role of AI in reducing the time and expertise needed for coordinated cyber attacks, enabling even lone actors to execute complex intrusions.
For financial institutions, this incident emphasizes the need for comprehensive security measures beyond core banking systems. This includes securing broker portals, employee systems, and support services, implementing strong authentication, and monitoring for unusual activities.
The evolving landscape of AI-assisted cybercrime demands that organizations stay vigilant and adapt their security strategies to counter new threats effectively.
