China-Based Hacker Likely Used AI to Hit South Korean Banks: CrowdStrike Report

By Evgenia Filimianova
Evgenia Filimianova
Evgenia Filimianova
Evgenia Filimianova is a UK-based journalist covering a wide range of international stories, with a particular interest in foreign policy, economy, and UK politics.
October 9, 2026Updated: October 9, 2026

U.S. cybersecurity company CrowdStrike said a single person in China likely used artificial intelligence tools to attack South Korean financial organizations, resulting in data theft.

CrowdStrike said in a report on Wednesday that the campaign ran from late September to early October and used conventional hacking techniques with AI-assisted software.

It said the campaign relied on ARTEX, an open-source penetration-testing tool developed in China, along with large language models.

CrowdStrike assessed, with moderate confidence, that the attacker was likely a Chinese speaker and financially motivated, based on the use of the Chinese-developed ARTEX tool and Chinese-language prompts. It said the activity has not been attributed to a named adversary.

The case, according to CrowdStrike, demonstrates how cybercriminals employ AI agents, software that can carry out tasks on its own.

“The use of agentic AI tooling alongside traditional offensive capabilities highlights the continued evolution CrowdStrike has observed in adversarial tradecraft,” the report said.

At least nine South Korean banks have disclosed or been reported by local media as targets since late September.

Shinhan Bank said last week that the personal information of about 25,000 customers had been compromised, while KB Kookmin Bank said the personal information of 119 customers had also been leaked, Reuters reported.

South Korean police said earlier this week that it had opened an investigation, while South Korean President Lee Jae Myung called for strong response measures.

According to industry reports cited by CrowdStrike, an attacker reportedly broke into a loan-processing service used by financial brokers at one bank.

In another case, the attacker reportedly compromised a mobile system used by employees. CrowdStrike said the number of affected organizations remains unconfirmed.

South Korea’s Financial Services Commission and Financial Supervisory Service on Tuesday urged consumers to watch for phishing and loan scams after the breaches. The agencies also launched a month-long special response period to prevent criminals from exploiting stolen personal information.

Attacker’s Tools

CrowdStrike said the suspect was likely a 26-year-old who used a Chinese-developed AI agent and Anthropic’s Claude Code.

Adam Meyers, CrowdStrike’s senior vice president of counter adversary operations, told reporters on Oct. 8 that the case shows what one person can do.

“And this is significant because it allows one human to target many customers in a very short period of time using the power of AI,” he said.

CrowdStrike said the attacker used two servers. One, based in Hong Kong, served as the attacker’s main base. The other ran the ARTEX tool and was likely responsible for the South Korean attacks.

According to the report, the attacker used DeepSeek v4.1-flash as the main AI model behind the ARTEX system, GLM-5.3 from Zhipu AI, and Grok 4.6 in additional Claude Code sessions.

Claude Code sessions showed the attacker searching for places where stolen South Korean data could be sold, the report said. According to the company, the attacker asked Claude for help finding Telegram groups where Korean data breaches are traded.

The Epoch Times reached out to Anthropic (the developer of Claude), DeepSeek, xAI, and Zhipu AI for comment but did not receive responses by the time of publication.

Asked about the CrowdStrike report, Chinese Foreign Ministry spokesperson Mao Ning told reporters on Oct. 8 that she was not familiar with it.

“China opposes hacking activities and fights these activities in accordance with the law,” Mao said, according to China’s Ministry of Foreign Affairs.

Mao added that China rejects the spread of disinformation driven by a political agenda. She said AI has a significant impact on cybersecurity and that the international community needs to step up cooperation and dialogue. She also called for new international rules to protect cybersecurity.

 Reuters contributed to this report.