A suspected hacker believed to be based in China used artificial intelligence tools to target South Korean financial institutions and steal data, according to cybersecurity firm CrowdStrike.
In a report published on Wednesday, October 7, CrowdStrike said its investigation identified activity linked to a suspected attacker who used a Chinese-developed AI tool called ARTEX alongside large language models to conduct cyber operations against South Korean financial organisations between late September and early October 2026.
The cybersecurity firm said it discovered records from AI coding-tool sessions and infrastructure associated with the campaign. These findings helped investigators understand how the suspected attacker used AI-assisted tools during the operations.
CrowdStrike assessed that the individual was likely a Chinese speaker and may have been motivated by financial gain. However, the firm stressed that the activity had not been attributed to a formally identified threat group, and the suspect's identity has not been independently confirmed.
ARTEX is an open-source penetration-testing tool developed for cybersecurity work. It can connect to external AI models to help identify and assess weaknesses in computer systems. Its developer's stated purpose is security testing, but investigators believe it was repurposed for unauthorised activity in this case.
CrowdStrike also reported that the suspected attacker used AI tools to seek information about selling stolen South Korean data and locating online groups where such information might be traded. These findings contributed to the firm's assessment that the campaign may have had a financial motive.
The attacks come amid a wider series of reported data breaches affecting South Korean financial institutions. Shinhan Bank disclosed that information relating to about 25,000 customers had been compromised, while KB Kookmin Bank reported a separate incident involving a smaller number of customers. South Korean authorities have launched investigations into the incidents.
South Korean President Lee Jae Myung has called for stronger cybersecurity measures following the breaches. Financial authorities have also urged institutions to improve their defences against attacks that may use AI to identify system weaknesses and automate parts of the intrusion process.
The case highlights growing concern that AI tools designed for legitimate software development and security testing could also be misused by cybercriminals. Experts warn that such tools may allow attackers to work faster, making it increasingly important for organisations to strengthen monitoring, access controls and incident-response systems.
Investigations are continuing, and the full extent of the affected organisations and compromised information remains unclear. Authorities have not publicly confirmed the suspect's identity or attributed the attacks to a specific organisation or government.
