AI Tool Helped a Hacker Breach South Korean Banks
CrowdStrike found that a string of breaches at South Korean banks was likely carried out by a single person using an AI tool that scans for vulnerabilities automatically.
Cybersecurity firm CrowdStrike says a string of breaches at South Korean banks was most likely the work of one hacker, not a group. The attacker used ARTEX, an open source tool that automatically scans for vulnerabilities using AI models, running it on DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6. Those models come from Chinese labs and from xAI. In the attacker's open file directories, researchers also found session logs from Claude Code, Anthropic's coding tool. The logs show searches for Telegram groups to sell the stolen data on. Shinhan Bank alone, one of the banks hit, leaked more than 25,000 records with names, contact details, income, and credit limits. The attacks took place in late September and early October 2026.
This is not a story about AI being dangerous on its own. CrowdStrike's point is that a swarm of available agents and models now lets a single person reach a scale of breach that used to require a whole team. It's also worth noting that DeepSeek and GLM, Chinese models that usually lag well behind Anthropic's models in real-world work, turned out to be good enough for this kind of vulnerability scan, because the task does not call for deep reasoning.
Source: the-decoder.com
Free course
Stop reading about AI — start building with it
The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.
Start free →
Author
Evgenii Arsentev
PhD · Chief Executive Officer, digital health
Articles · Latest articles