⚡
Brief IA
›

South Korean Banks: AI-Assisted Hacking via ARTEX

💻 Code & Dev·Tom Levy·

South Korean Banks: AI-Assisted Hacking via ARTEX

South Korean Banks: AI-Assisted Hacking via ARTEX
⚡
Key Takeaways
1Several South Korean banks have been hacked by an attacker suspected of speaking Chinese
2The open-source tool ARTEX, using AI language models, was used for the intrusion
3Over 25,000 records were stolen from Shinhan Bank; the regulator and the South Korean president have responded
4Anthropic recently demonstrated that GLM-5.3 can generate exploits at a level close to Mythos Preview
💡Why it matters — This hack illustrates the ability of AI tools to amplify the impact of a lone attacker and the speed at which major breaches can occur.
⚡Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

A suspected Chinese-speaking attacker has targeted several financial institutions in South Korea. According to Crowdstrike, the open-source tool ARTEX, powered by language models, was used for the intrusion. At Shinhan Bank, over 25,000 records were stolen, prompting the regulator to hold an emergency meeting, and President Lee Jae Myung has called for an investigation.

Crowdstrike warns of the "lone wolf" power of AI tools

Crowdstrike believes this incident illustrates how AI tools can enable a single individual to carry out major attacks in a short amount of time, a risk that experts have been discussing for several months. Just days before this hack, Anthropic demonstrated that GLM-5.3 is capable of generating exploits at a level close to Mythos Preview, its most advanced model, which sparked debate in late March 2026.

ARTEX used for automated penetration testing

According to Crowdstrike, the attacker utilized ARTEX, an open-source Chinese software that was first posted on GitHub in July. This program leverages language models to automatically conduct penetration tests and autonomously identify security vulnerabilities. The models used included DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6. Experts discovered session files from Claude Code in accessible directories of the attacker, revealing searches for Telegram groups aimed at selling stolen data.

Targeted institutions, stolen data, and authorities' response

According to Crowdstrike, between late September and early October 2026, a number of South Korean financial institutions were targeted by a presumably lone attacker, believed to be Chinese-speaking, who stole large amounts of data. For Shinhan Bank, more than 25,000 records containing information such as names, contact details, income, and credit limits were stolen, according to the Korean daily Khan. The South Korean financial supervisor convened an emergency meeting, while President Lee Jae Myung demanded a thorough investigation be conducted.

⚡

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.