A China-based threat actor breached nine South Korean financial institutions — including Shinhan Bank — using a combination of an open-source AI pentesting tool and large language models to automate every stage of the attack. The incident, documented by CrowdStrike investigators and reported by The Hacker News today, exposed the personal data of more than 25,000 banking customers and stands as one of the clearest examples yet of AI being weaponized against financial infrastructure at scale.
What Is ARTEX — and Why It Matters
ARTEX is an open-source AI-assisted pentesting tool — meaning it was originally designed to help security teams find their own vulnerabilities. In the wrong hands, it automates the work a human attacker would otherwise do manually: probing systems for weaknesses, mapping network architecture, and identifying exploitable entry points.
In this campaign, the attackers paired ARTEX with Anthropic's Claude Code and multiple additional LLMs (large language models, the AI systems behind tools like ChatGPT and Gemini). According to CrowdStrike, the AI stack handled reconnaissance (gathering intelligence on targets), exploitation (leveraging discovered vulnerabilities), and data exfiltration (copying and transmitting stolen records) — tasks that would typically require a team of skilled operators and days of manual work.
The Breach in Numbers
- Nine institutions targeted, all South Korean financial firms
- Shinhan Bank confirmed as one of the named victims
- 25,000+ customers had personal data compromised
- Attribution: China-based threat actor (CrowdStrike has not publicly named the group)
The attack did not appear to exploit a single zero-day vulnerability. Instead, the AI toolchain allowed the actor to move across multiple institutions quickly, adapting to each target's defenses in ways that suggest the models were being used for real-time decision-making during the intrusion.