GMAsia
    🇹🇼Taiwan·AI News·8 Oct 2026·via Taipeitimes·Covered by 3 sources

    S Korean banks likely hacked by China-based actor: CrowdStrike

    Cyberattacks on at least nine South Korean banks have been linked by US cybersecurity company CrowdStrike to a China-based individual who allegedly used a Chinese-developed AI agent and Anthropic's Claude Code. CrowdStrike stated the suspect, believed to be a 26-year-old from Guangdong Province, leveraged AI tools to conduct widespread attacks, compromising customer data at Shinhan Bank and KB Kookmin Bank.

    Nexa's Summary

    This incident illustrates how AI agents, specifically open-source penetration testing tools like ARTEX combined with large language models such as Anthropic Claude, can amplify the reach of a single human attacker. CrowdStrike's analysis suggests the use of AI allowed one individual to target numerous customers in a short timeframe, raising concerns about the scalability of such attacks.

    The attribution of the attacks to a likely Chinese speaker, based on the use of the Chinese-developed ARTEX tool and observed Chinese-language prompts, suggests a potential financially motivated individual. CrowdStrike detailed how the attacker allegedly used Claude to research where to sell Korean data breach information and to find relevant Telegram groups, indicating a clear intent to monetize compromised data.

    The case highlights a growing security challenge for organizations: defending against adversaries who integrate AI agents into their operations. While ARTEX's GitHub page states its intended use for learning and research, its application in these attacks demonstrates the potential for misuse of such tools. The incident underscores the evolving landscape of cyber threats, where AI can serve as an enabler for more efficient and widespread campaigns.

    Share this article

    Go deeper
    Original reporting by TaipeitimesWe don't republish, read the full story →

    Related reading

    6 stories