One person, one open-source tool and three AI language models. CrowdStrike said that was likely enough to break into multiple South Korean financial institutions between late September and early October 2026 and steal large amounts of data.
Shinhan Bank shows how much was lost. More than 25,000 records were stolen there alone, including names, contact details, income and credit limits, according to Korean newspaper Khan.
The response was quick. South Korea’s financial regulator held an emergency meeting, and President Lee Jae Myung called for a thorough investigation.
The toolkit was already public on GitHub
The attacker is suspected to be Chinese-speaking. They didn’t build custom malware from scratch. Instead, they used ARTEX, a Chinese open-source tool first posted on GitHub in July.
ARTEX uses AI language models for automated penetration testing. That means it finds security flaws on its own, without a human probing each system by hand.
Three models powered it in this attack: DeepSeek v4.1-flash, GLM-5.3 and Grok 4.6. They come from three different developers, and all three were wired into one publicly posted tool.
The attacker’s own logs were left in the open
Researchers found Claude Code session logs in the attacker’s open directories. The logs show searches for Telegram groups where the stolen data could be sold.
So the operation used AI for more than the break-in. It also showed up in the planning for selling what was taken.
The warning security researchers kept repeating
CrowdStrike said the case shows how AI tools can let a single person carry out breaches on this scale in a short window. Security experts have been warning about exactly this kind of risk for months.
The timing makes that warning hard to brush off. Just days earlier, Anthropic documented that GLM-5.3 can write exploits nearly on par with Mythos Preview, Anthropic’s frontier model and the one that sparked the entire debate in late March 2026.
That’s the detail worth sitting with if you run security at a bank. One of the models Anthropic flagged for near-frontier exploit writing was already plugged into an open-source tool on GitHub, and it took what was likely a single attacker to point it at Shinhan.
Free crypto, NFTs & new crypto games, before everyone else
Airdrops, free games and launches the day they drop. One email, no spam, unsubscribe anytime.














