One Operator, a Nine-Week-Old AI Tool, and Seven Korean Financial Firms. The AI Didn't Open a New Hole.
The version of this story that travelled fastest was the simple one. An AI hacked South Korea's banks. The version that holds up is messier, and more useful to anyone who has to defend a system.
On 7 October, CrowdStrike published an analysis of a campaign against South Korean financial institutions that ran from late September into early October. The firm found exposed directories on servers it says the threat actor controlled. Inside them were Claude Code session histories, configuration files for a tool called ARTEX, and Claude memory files. That is a rarer thing than the headlines suggested. Not a vendor describing what AI could do, but an attacker's own working files left out in the open.
What CrowdStrike actually found
ARTEX is an open-source, agentic penetration-testing tool developed in China. It is not a model. It connects to external large language models and runs a planner with parallel worker agents behind it. CrowdStrike traced a two-server setup. A Hong Kong address served as the actor's primary infrastructure; a second address hosted the ARTEX instance that CrowdStrike says is "likely responsible for the described Korean attacks."
That instance ran DeepSeek v4.1-flash as its main model backend. The actor supplemented it with Zhipu AI's GLM-5.3 and xAI's Grok 4.6 across additional Claude Code sessions, and likely reached DeepSeek through a third-party API reseller. Nine proxy addresses were logged as well. CrowdStrike assessed with moderate confidence that the actor is likely a Chinese speaker and financially motivated, based on the Chinese-developed tool and Chinese-language prompts. It did not attribute the activity to a named adversary, and it named no bank.
The personal detail that got picked up everywhere came from one session in which the user asked the AI to draft a security researcher's resume. The prompt carried a Telegram handle, an age of 26, an educational background at South China University of Technology, and a location in Maoming, Guangdong. The same handle turned up in sessions probing a Telegram-based NFT gift marketplace. CrowdStrike says the details likely belong to the actor and, in the same breath, that the available information cannot definitively associate them with the threat actor. Press coverage compressed those two sentences into a nationality. That is a language call becoming an identity, and the gap matters.
The stack was younger than the attack
Here is the part that should worry a security team more than any attribution fight. Set against the late-September start that Korean reporting gives the campaign, the whole toolchain was brand new.
ARTEX had its first release on 26 July, about nine weeks earlier, and its latest version on 24 September. DeepSeek v4.1-flash shipped on 10 September, GLM-5.3 on 18 August, Grok 4.6 on 14 August. Every component was between a few days and nine weeks old. None of it was exotic. ARTEX is free, and by 8 October a GitHub search found 23 public repositories created between 2 and 8 October that identify themselves as copies, mirrors, or Korean and English builds of it. The original project page now shows as unreachable. Removing a repository does not recall an open-source tool.
That is the economics of the thing. A defence strategy built on knowing the attacker's tool goes stale in weeks. What stays put is the behaviour at your front door.
Where the attacker got in, and where they didn't
The intrusions did not go through core banking. Korean reporting, which CrowdStrike relays rather than confirms, describes two entry points: a loan progress inquiry service used by financial brokers at one bank, and an employee mobile work-support system at another. Both are the kind of peripheral, internet-facing asset that sits low on an inventory list and high on nobody's risk register.
The method was almost boring. At the broker service, the attacker is reported to have fed in values to guess valid customer numbers, then pulled the associated records. The Straits Times, citing a Korea Herald report, said the attacker worked around tightly secured core systems and into non-core ones such as sales-support platforms. Woori Bank and NH NongHyup Bank detected attempts and blocked them, with no confirmed leaks.
The damage numbers moved as more firms disclosed. Shinhan Bank reported about 25,000 customers affected, later given as 25,729. Yegaram Savings Bank reported about 40,000. Welcome Savings Bank 2,200. Hyundai Capital 146. KB Kookmin 119 in one account and 153 in another. Hana Bank 89. BNK Busan 11 outsourced workers. Added up, Korean reporting lands near 66,000 to 68,000 people, plus about 2,200 corporate records. Those figures come from press accounts, not from CrowdStrike, and the units differ by firm, so treat the total as a size, not a count.
One detail cuts against the idea that spending alone is the answer. Shinhan spent 40.59 billion won on information security this year, the lowest of Korea's top four commercial banks, and took the largest hit. But the regulator's own line was that the difference is about how well a security framework covered the exposed service, not the size of the budget. The common denominator in the systems that fell was simpler: a lookup that answered a caller who offered little more than an identifier, and a staff app sitting on the open internet.
What the evidence does not show
The AI claim and the victim claim in this story do not have the same footing, and most coverage ran them together.
CrowdStrike's case for the AI rests on files it says it saw itself. Its account of which banks were hit rests on industry reporting, hedged with "reportedly" and "purportedly," and pinned to a single press footnote. The firm's report names no bank and counts no victim. Its strongest sentence, that the organisations in the actor's files overlap with those in the press, is the one a reader can least check.
The effect claim is separate, and untested. CrowdStrike writes that the activity "demonstrates how AI tooling can enable a financially motivated threat actor to conduct multiple intrusions within a short time span." It gives no count of intrusions, no comparison against pre-AI methods, and no root cause for any breach. What it can show, if its description is right, is which tool and which models an actor used. It does not claim to show that a bank fell because of them.
The tool's own page pushes back too. ARTEX's README says it is for personal study and local technical verification and must not be used against any online system, and its licence does not enforce that. The "pentesting" label is the author's description; the disclaimer is the author's request. Neither is a control on a user.
Why the cost of trying collapsed
Strip away the AI framing and the picture is a single operator probing many doors at once. Adam Meyers, CrowdStrike's senior vice president of counter adversary operations, put it plainly: "While capabilities were not terribly sophisticated they were effective." On a call with reporters he added that this "allows one human to target many customers in a very short period of time using the power of AI."
The regional numbers say the same thing at scale. South Korea logged 1,236 cyber incidents in the first half of the year, up 20 percent year on year, with distributed-denial-of-service reports up 56.7 percent and ransomware up 76.8 percent. Japan recorded more incidents in the first nine months of 2026 than in all of last year, with 86 in September alone, up about 18 percent from August. "AI doesn't get tired," said Nobuo Miwa of Tokyo security firm S&J Corp. "My view is that Japan is essentially being subjected to carpet bombing." Nine South Korean banks and two mega-churches were probing attacks; in Japan, Daiwa Securities, SoftBank and the Lawson convenience chain were hit.
The response is now institutional. Korea's Financial Services Commission ordered a 12-point cybersecurity self-assessment and began weighing a relaxation of network separation rules so banks can use external AI services to hunt vulnerabilities faster. Its chairman, Lee Eog-weon, conceded the early response was inadequate "even in some very basic areas," and framed the logic bluntly: "To prevent attacks using AI, we ultimately have no choice but to use AI in defending them." Japan's digital transformation minister convened ministries. Korean lawmakers approved summoning the heads of the five largest commercial banks to a 19 October parliamentary audit. Fitch's Karen Wu expects "regulatory penalties, customer compensation costs, and a sector-wide increase in cybersecurity spending."
The uncomfortable read is that the AI did not open a new kind of hole. It lowered the cost of trying every ordinary one. A free tool released nine weeks earlier, a model released weeks before that, and one person willing to point them at a broker portal. The control that holds against that is not a cleverer model. It is per-record authentication on every lookup, real sign-in beyond a password on staff and partner paths, rate limiting, and logs that would tell you within a day that a machine had been asking all night.
The security teams that came through this clean were not the ones with the newest AI. They were the ones whose external-facing services stopped handing over data to anyone who could guess a number.
That is the part of this story worth carrying into next quarter. AI agents compress the time between an idea and an intrusion, but they land on whatever your edge exposes. At DMC, we work with companies that have to inventory that edge and close it down before someone else finds it first: the broker portals, the staff apps, the supplier-hosted services nobody owns, the API that answers a stranger. If your security plan still assumes an attacker needs a team and a month, let's talk.