South Korean Banks Were Hacked Using Chinese AI Agent, Researchers Say
Source: The Information (opens in a new tab) · Juro Osawa
Intel Summary
A cyberattack against South Korean financial institutions resulting in data leaks was executed using an open-source Chinese AI agent called Artex alongside Chinese large language models, according to an incident analysis published by cybersecurity firm CrowdStrike.
Why It Matters
The breach represents a concrete instance of autonomous AI agents and open-source models being deployed in active cyber operations against enterprise targets, signaling that automated offensive AI tools are actively threatening financial infrastructure.
Organizations & Entities
- China
- CrowdStrike
- South Korea
Topics
Related Intelligence
- ReportAlso involving CrowdStrike
AI-powered hacking tools enabled a likely single attacker to breach multiple South Korean banks
According to CrowdStrike, a suspected Chinese-speaking attacker breached multiple South Korean financial institutions using ARTEX, an open-source automated penetration testing tool powered by AI models including DeepSeek and GLM-5.3. The incident resulted in the theft of over 25,000 customer records from Shinhan Bank alone, demonstrating how AI-driven tooling enables individual actors to execute large-scale attacks.
The Decoder - ReportAlso involving South Korea
AI models used in bank cyber attacks, warns South Korea’s president
The Financial Times reports that South Korea's president, Lee Jae Myung, has issued a warning regarding artificial intelligence models being used in cyber attacks against banks, with government officials describing the emerging threat vector as an unprecedented crisis.
Financial Times (AI) - ReportAlso involving China
China races to build AI data centres across energy-rich hinterland
The Financial Times reports that China is accelerating the construction of artificial intelligence data centres across its energy-rich hinterland. Specifically, the region of Inner Mongolia has emerged as a key infrastructure base supporting the country's national AI capacity ambitions.
Financial Times (AI) - DevelopmentNewAlso involving CrowdStrike
Omdia publishes analysis on AI agent identity security requirements
Research firm Omdia highlights that securing AI agent identities requires layered defenses as machine identities expand across enterprise environments. The analysis follows identity security market consolidation, including Palo Alto Networks acquiring CyberArk Software, and recent ecosystem moves like Okta introducing an AI agent runtime gateway alongside forming the Blueprint Alliance with AWS and CrowdStrike. Claims are as reported; this summary makes no determination about accuracy or significance.
1 reporting source