⌁AI·CYBER·BRIEF▌
AI Threats7 min read

CrowdStrike links Korean bank breaches to an open-source AI pentesting agent

An attacker used AI agents to work through weakly protected broker and staff portals at several Korean banks. The fix is basic: inventory and lock down side doors.

Between late September and early October 2026, an attacker broke into customer-lookup and staff systems at several South Korean banks, exposing data on roughly 25,000 Shinhan Bank customers and smaller numbers at other lenders. On October 7, CrowdStrike reported that the operator likely used ARTEX, an open-source AI "agentic" penetration-testing tool, together with several large language models. For most IT teams the lesson is not AI itself: it is the side doors — partner portals and internal tools reachable from the internet with weak authentication — that AI tools now find and work through faster.

What happened, in plain English

Banks in South Korea work with outside loan brokers, who use a separate web service to check how a customer's loan application is progressing. That service, and similar "side" systems such as an employees' mobile work app, sat on the internet next to the banks' main online banking — but were far less well protected.

According to Korean reporting summarised by American Banker, an attacker spent about 30 hours from September 28 feeding customer numbers into Shinhan Bank's broker lookup service and getting past a phone-verification step. Shinhan's own notice says an "unauthorized outsider" reached the service "through abnormal means." The bank said about 25,000 customers were affected; reported data includes names, phone numbers, annual incomes and calculated borrowing limits (other Korean outlets also mention resident registration numbers). KB Kookmin (119 customers), Hana (89), BNK Busan and Yegaram Savings Bank were also reported hit, each far smaller. Core internet and mobile banking were not reported as breached, and regulators have reported no confirmed customer losses.

What makes this case different is how it was done. The attacker used ARTEX, a penetration-testing tool — software built to test systems for weaknesses, the way a locksmith tests locks — that hands much of the work to AI "agents": programs that use a large language model (LLM), the technology behind chatbots, to decide and carry out next steps on their own. Think of a burglar who no longer walks the street trying every door, but sends a tireless assistant to do it and report back which ones open.

CrowdStrike found this because the attacker left folders on their own servers open to the internet, including logs of their AI coding sessions.

Are you affected? What to do now

Customers of the named Korean banks should follow their bank's notices. Korea's financial regulator warned that fraudsters could use stolen income and loan data to make fake loan offers look legitimate, so treat unexpected loan offers with suspicion.

For IT teams elsewhere, there is no patch to install — this was not a software bug in a product you run. But the weakness is common, and the Korean regulator's response is a good checklist for anyone. On October 2, South Korea's Financial Services Commission (FSC) ordered banks and card companies to check "all IT systems accessible from outside their networks," reduce what they expose, and make sure no route reaches internal data without authentication.

  • Inventory every internet-facing system, not only the customer website: partner and broker portals, supplier lookups, staff mobile apps, test and legacy pages. The FSC told firms to include systems "regardless of whether they are customer-facing."
  • Check how each one authenticates. Can someone get data just by typing in an ID number or account number? Is the verification step bound to the session, or can it be skipped? BNK Busan said some of its pages had "insufficient session validation."
  • Limit what partners can see. The FSC's follow-up order said personal credit data should not be "unnecessarily stored or viewable" by staff or outside personnel such as loan recruiters.
  • Rate-limit and alert on lookups. Thousands of sequential or random ID queries over hours is a pattern your web application firewall (WAF) or logs can catch. Review the last few weeks of logs for partner portals.
  • Ask your suppliers and partners the same questions about any portal that holds your customers' data.
  • Brief helpdesk and customer-facing staff on follow-up fraud: realistic loan or refund offers that quote real personal details.
  • Indicators: CrowdStrike published ten IP addresses (nine proxies and the server that hosted ARTEX) in its report. They are useful mainly to Korean financial firms and threat-hunting teams; the infrastructure may already have changed.

If your organisation has no partner portals and keeps a tight inventory of what faces the internet, there is little new to do beyond confirming that inventory is current.

The expert view

Strip away the AI label and the intrusion is old-fashioned: weakly authenticated, internet-exposed lookup services that return sensitive records when given valid identifiers. Insecure direct object reference and enumeration flaws have been on web-security checklists for two decades. What changed is the cost of finding and working them. CrowdStrike's assessment is that AI tooling "can enable a financially motivated threat actor to conduct multiple intrusions within a short time span." Several institutions hit within roughly a week fits that description.

The tooling is the genuinely new part. ARTEX is, in CrowdStrike's words, "a recently released open-source agentic penetration testing (pentesting) tool developed in China." CrowdStrike says the instance used DeepSeek v4.1-flash as its primary model, likely reached through an API reseller, with GLM-5.3 and Grok 4.6 used in other sessions. The operator also ran Claude Code sessions, whose histories recorded ARTEX activity against Korean targets as well as questions about where Korean breach data is sold and how to find Korean Telegram data-sale groups. Spreading the work across several vendors' models, partly through a reseller, also means no single AI provider sees the whole operation. CrowdStrike's own wording stays hedged: the attacker's server hosts "the ARTEX instance likely responsible for the described Korean attacks."

Attribution is cautious. CrowdStrike has not tied the activity to a named group; it assesses with moderate confidence that the actor is "likely a Chinese speaker and financially motivated," based on the Chinese-developed tool and Chinese-language prompts. It found personal details in one session that "likely belong to the threat actor" but says it cannot definitively associate them with the attacker. Korean investigators are more careful still: according to the Korea JoongAng Daily, the National Police Agency's National Office of Investigation opened a formal case on October 6 with 28 cyberterrorism investigators, the Financial Supervisory Service has traced 19 attacker IP addresses in 12 countries, and most experts quoted note that an open-source tool cannot identify who used it. No regulator has publicly named ARTEX as the cause.

Much is still unknown. CrowdStrike says the number of affected organisations "remains unconfirmed," and reports range from four or five confirmed bank leaks to at least seven institutions targeted. Accounts of the entry method differ (enumeration versus credential stuffing). And we do not know how much of the work the AI agents did versus the operator — the sessions show a human directing the tools.

The policy signal is worth noting. The FSC did not issue AI-specific rules; it ordered basic exposure and authentication hygiene, with checks due by October 8 according to Yonhap. Lawmakers have also approved summoning the heads of five major banks to an October 19 parliamentary audit, The Register reports, citing The Korea Times. That is the right reading: defenders cannot out-speed an attacker who automates reconnaissance, but they can shrink what is reachable and make every reachable door ask for proof. For readers following our coverage, this sits alongside the Zammad case and the Gambit campaign's agentic attack economics: the AI is the accelerator, the unguarded system is still the cause.

Official sources

Get the daily brief

AI + security signal by email: headlines, a two-line summary, a link. No noise, no spam.

How often