Image: CrowdStrike
Hackers used a free, publicly available AI tool to break into South Korean banks and lenders, according to new research from CrowdStrike. The security firm says the attacker leaned on AI to run several break-ins within a short span, and got away with customer data.
The tool is called ARTEX. It's an open-source "penetration testing" system developed in China. Penetration testing is hacking with permission: companies hire experts to attack their own systems so they can find weak spots before criminals do. ARTEX hands much of that job to AI agents, programs that plan and carry out steps on their own.
In the wrong hands, the same tool simply becomes a hacking tool. CrowdStrike says ARTEX ran mainly on DeepSeek V4.1 Flash, a Chinese AI model. The attacker also used Anthropic's Claude Code assistant in other sessions, along with GLM-5.3 and xAI's Grok 4.6.
CrowdStrike pieced this together from the attacker's own mistakes. Two servers linked to the campaign had folders left open to the internet. Inside were AI chat logs, ARTEX settings and a Chinese-language instruction file telling the AI how to attack.
The logs also show the attacker asking Claude where stolen Korean data is usually sold, and for help finding Telegram groups that trade it.
The break-ins themselves were low-tech. South Korea's Kyunghyang Shinmun reports the attackers skipped customers' online and mobile banking. Instead, they went after side systems, like a loan-progress tool that Shinhan Bank's loan brokers use and an internal work app for KB Kookmin Bank staff.
According to the paper, the attackers fed random values into the broker tool to guess valid customer numbers, then pulled contact details. It's the digital version of trying every key on a ring, which AI makes fast and tireless.
Citing financial authorities, the paper says Shinhan lost 25,727 items of personal data, including names, contact details, annual income and loan limits. KB Kookmin and Hana Bank lost data on 119 and 89 customers. BNK Busan Bank, savings banks, Hyundai Capital and two peer-to-peer lenders were also hit. CrowdStrike says the full number of victims is still unconfirmed.
So who did it? Nobody knows for sure. CrowdStrike hasn't tied the attack to any known group. It believes, with moderate confidence, that the attacker speaks Chinese and wants money, based on the Chinese tool and Chinese-language prompts.
The logs even include a request to Claude for a résumé boasting about the attack, along with personal details. CrowdStrike says those details likely belong to the attacker but can't prove it, so we aren't repeating them. Korean officials also warn that a Chinese-made, open-source tool doesn't prove the attacker's nationality.
The timing is the striking part. ARTEX first appeared publicly in late July, according to the Go package index, so it was weaponized against major banks in about two months. Its own instructions ban using it on any live website or system, even with permission. That rule clearly didn't stop anyone, and the tool's GitHub page now shows a "page not found" error.
For ordinary people, the main risk comes next. Korean regulators fear stolen names, incomes and loan limits will fuel convincing scam calls posing as loan offers. If a "lender" contacts you knowing your finances, hang up and call your bank's official number yourself.
For companies, the lesson is to guard the back doors too. Partner portals and staff apps need the same login protections and limits on repeated guessing as the main banking app.
CrowdStrike expects more criminals to try AI tools to work faster. This case suggests they don't need to be experts to do it.

Comments