A suspected Chinese-speaking attacker breached multiple South Korean financial institutions between late September and early October 2026. The attacker stole large amounts of data during the campaign. Shinhan Bank alone suffered the theft of more than 25,000 records containing names, contact details, income, and credit limits, according to Korean newspaper Khan.
South Korea's financial regulator held an emergency meeting following the incidents. President Lee Jae Myung called for a thorough investigation into the security breaches.
Attacker used open source AI
The attacker utilized ARTEX, a Chinese open-source tool first posted on GitHub in July. The software uses artificial intelligence language models for automated penetration testing to find security flaws on its own. The models behind ARTEX included DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6.
Researchers discovered Claude Code session logs on the attacker's open directories. These logs displayed searches for Telegram groups to sell the stolen data.

Crowdstrike highlights breach risks
Crowdstrike reported that the case demonstrates how artificial intelligence tools can enable a single person to execute massive breaches in a short window. Cybersecurity experts have warned about this specific risk for months.
Anthropic documented just days earlier that GLM-5.3 can write exploits nearly on par with Mythos Preview. Mythos Preview is Anthropic's frontier model that sparked the industry debate in late March 2026.
The financial regulator and investigators are continuing their work on the case.



