South Korean Bank Hacks: AI Evidence Grows, Identity Remains Unclear

New AI-tool records strengthen evidence in South Korean bank hacks, while attacker identity, the full breach count and AI’s exact role remain unresolved.

By

·

3 min read
Woori Bank headquarters, photographed in 2020; file photo, not the hacking incident.

Image: Woori Bank headquarters, June 20, 2020. File photo, not the hacking incident. Magneta6006 / Wikimedia Commons / CC BY-SA 4.0. Original unaltered; display may crop. No endorsement implied.

E.K.K | Updated October 11, 2026

New technical evidence strengthens the case for AI-assisted hacking, while the attacker’s identity remains unresolved.

CrowdStrike’s October 7 investigation reports AI-tool records on infrastructure linked to attacks against South Korean financial institutions. For banks and customers already facing data leaks, this adds evidence beyond the early reports of tool traces. It does not establish who carried out every recent breach.

What the technical investigation found

CrowdStrike says attacker-controlled directories exposed Claude Code session histories and ARTEX configuration files. ARTEX is a tool for testing system weaknesses that can use AI to perform tasks. The findings concern a campaign spanning late September and early October, not a confirmed explanation for all bank attacks. CrowdStrike investigation.

Attribution remains an assessment

The company assesses a likely Chinese-speaking, financially motivated attacker with moderate confidence. It cautions that personal details in the records cannot definitively identify the perpetrator. Chinese-language prompts or a tool’s country of development do not establish nationality or state sponsorship. CrowdStrike investigation.

Reuters reported on October 8 that a person answering a published phone number denied knowledge of the matter. China’s foreign ministry said it was unfamiliar with the case and opposed hacking. These responses do not resolve the attribution question. Reuters, October 8.

Leaks and the official response

According to Reuters on October 8, Shinhan Bank said about 25,000 customers’ information was compromised, while KB Kookmin reported 119 customers affected. Reuters counted at least nine banks that had disclosed attacks or were reported as targets. That is not a verified total of successful breaches, and the two customer figures are not a sector-wide total. Reuters, October 8.

Reuters reported on October 6 that President Lee Jae Myung flagged signs of AI use in some incidents and called for rapid fact-finding and damage containment. The report described a police investigation, an emergency regulatory meeting and the sharing of 28 IP addresses associated with hacking attempts. A presidential warning and indicators shared by regulators are distinct from a final technical finding. Reuters, October 6.

ARTEX’s developer withdraws public releases

Reuters’ October 9 report says ARTEX’s developer announced on October 8 that the project would become closed-source, with no further public releases or maintenance. The developer opposed illegal use; Reuters found the GitHub page had been removed. This does not show that already downloaded copies have stopped working. Reuters, October 9.

What banks still need to demonstrate

AHR analysis: Evidence of AI assistance changes the questions investigators can ask. They can examine which tasks were automated, where people intervened and whether the tools accelerated an attack. It still does not measure how much expertise the attacker needed or establish that AI acted independently.

For customers, the practical tests remain the scope of exposed data, verified repairs, timely notification and protection against follow-up fraud. For banks, authentication and access controls need to withstand repeated probing regardless of the tool used. Common infrastructure can help connect incidents, but each connection requires evidence.

Sources and verification

CrowdStrike provides the original technical assessment; Reuters supplies reporting and responses. AHR has not independently examined the seized records. The corresponding Presidential Office transcript and police release were not obtained. The original FSC release could not be reopened in this update; detailed claims drawn only from that release have been removed. No final official attribution, complete breach count or sector-wide financial loss is established here.

Continue Reading

Share this article


Discover more from Asia Horizon Review

A concise weekly briefing on Asian security, defense technology and international strategy. No daily clutter.


Discover more from Asia Horizon Review

Subscribe now to keep reading and get access to the full archive.

Continue reading