Safety & Security

CrowdStrike: AI Hacking Tool Let One Attacker Breach Korean Banks

CrowdStrike says a suspected Chinese-speaking lone attacker used the open-source AI tool ARTEX to breach multiple South Korean banks, stealing 25,000+ records from Shinhan Bank.

By Rebecca Stone5 min read

Updated

Why it matters

  • More than 25,000 customer records were stolen from Shinhan Bank alone, per CrowdStrike.
  • A suspected Chinese-speaking attacker, likely a single person, breached multiple South Korean financial institutions.
  • The attacker used ARTEX, an open-source AI-powered automated penetration-testing tool.
  • ARTEX runs on AI models including DeepSeek and GLM-5.3, CrowdStrike says.
  • CrowdStrike says the case shows AI tools can let one person carry out massive breaches.

A suspected Chinese-speaking attacker stole more than 25,000 customer records from Shinhan Bank alone, according to CrowdStrike — and the security firm says AI-powered tooling made the multi-bank campaign possible for what was likely a single operator.

The intrusion hit multiple South Korean financial institutions, not just one. CrowdStrike, which disclosed its findings in a report covered by The Decoder, identified the attacker through linguistic and operational indicators as a likely Chinese speaker. The company did not name every affected bank in the disclosed material, but it confirmed Shinhan Bank as a major victim, with the tally of stolen customer records there exceeding 25,000.

The weapon at the center of the case is ARTEX, an open-source tool that automates penetration testing using AI models including DeepSeek and GLM-5.3. ARTEX is not a bespoke implant built by a state laboratory. It is openly available, and it wraps large language models into a workflow that can probe, enumerate and exploit targets at machine speed. That combination — public availability plus automated offensive capability — is what CrowdStrike flags as the story's core problem.

Why does one attacker with ARTEX change the threat model?

CrowdStrike's assessment is blunt: the case shows how AI tools can let a single person pull off massive breaches. That sentence carries weight because it inverts a long-standing assumption in enterprise defense.

For years, security teams sized their adversaries by headcount. Opportunistic criminals worked alone and hit soft targets. Coordinated campaigns against hardened financial institutions implied a crew — reconnaissance specialists, exploit developers, operators, money mules. Staffing was a natural ceiling on how much damage one actor could do.

ARTEX removes part of that ceiling. The tasks that once required a team — mapping a target's infrastructure, triaging vulnerabilities, chaining exploits into a working intrusion path — are exactly the tasks penetration-testing AI models are built to automate. One person supervising an automated pipeline can now generate the volume of activity that previously signaled an organized group.

For South Korean banks, the stakes are direct. Financial institutions hold exactly the kind of concentrated customer data — identities, account relationships, contact records — that turns a single breach into tens of thousands of individual exposures. The 25,000-plus records taken from Shinhan Bank represent the downstream cost of one operator running one open-source tool.

What is ARTEX, and why does 'open source' matter here?

ARTEX is described by CrowdStrike as an open-source automated penetration-testing tool that uses AI models such as DeepSeek and GLM-5.3. Each element of that description matters.

Open source. The code is freely available. There is no procurement barrier, no underground purchase, no developer relationship to trace. Any actor who can download a repository can arm themselves.

Automated penetration testing. Penetration testing itself is a legitimate, defensive-adjacent discipline — security professionals use it to find holes before criminals do. ARTEX's significance is that it points that same automated capability at live targets and runs it without a professional in the loop requiring time, salary or expertise per step.

AI-native. The tool leans on large language models, including DeepSeek and GLM-5.3, to drive its attack logic. These are general-purpose models repurposed for offensive work. The attacker did not need to train anything; the model capabilities arrived ready to use.

The result is an asymmetry. Defensive teams still cost what they always cost. Offensive capacity has become downloadable.

What did the attacker actually take?

At Shinhan Bank, the confirmed figure is more than 25,000 customer records. CrowdStrike reported the theft as part of its investigation into the broader campaign against South Korean financial institutions.

The attribution signal — a suspected Chinese-speaking attacker — comes from CrowdStrike's analysis of the operator behind the intrusions. The company framed the identity assessment as a suspicion grounded in its investigative indicators, not as a confirmed government attribution, and the disclosed reporting does not establish state sponsorship.

What does this mean for banks and regulators?

The incident lands at a moment when policymakers are still arguing about how to govern offensive AI capabilities. CrowdStrike's case study offers the concrete data point that debate has lacked: not a lab demonstration, but a real campaign against real banks, with a real record count.

Three implications follow directly from the disclosed facts.

  • Volume without headcount. A likely single attacker reached multi-institution scale. Defensive planning that assumes small actors stay small no longer holds.

  • Commodity tooling, institutional targets. An open-source tool with public AI models was sufficient to engage hardened financial-sector victims — the attack surface is not limited to unprepared small businesses.

  • Record-level impact. More than 25,000 customer records from one bank alone quantify the blast radius of a single automated intrusion.

For security teams, CrowdStrike's findings argue for monitoring that keys on behavior rather than on assumed adversary profiles. If one person can produce the operational footprint of a team, then sizing the threat by its apparent scale will mislead.

What comes next?

CrowdStrike presents the case as evidence of a shift already underway, not a hypothetical: AI tooling has lowered the barrier to large-scale breaches far enough that a lone, suspected Chinese-speaking attacker could hit multiple South Korean financial institutions and walk away with over 25,000 customer records from Shinhan Bank. As automated penetration tools like ARTEX and the models behind them — DeepSeek, GLM-5.3 — remain publicly available, the question for defenders is no longer whether AI-assisted intrusions will scale, but how quickly incident-response capacity can adapt to adversaries who no longer need a team.

Original: khan.co.kr

Share this article:

More from Rebecca Stone

Rebecca Stone

Show full bio

Correspondent covering consumer brands and retail at AI In Context.

213 articles

Related articles

  1. OpenAI Bans Korean-Language Accounts Tied to Malware Development
  2. OpenAI Disrupts Cambodia-Based Scam Network That Used ChatGPT
  3. OpenAI Bans Accounts Linked to DPRK Threat Actors Using AI for Intrusion Research
  4. OpenAI Bans Cambodia-Based Accounts Running AI Dating Scams
  5. Five Agent Vulnerabilities in Five Months Expose Structural Flaw in MCP

« Previous articleNext article »