1 min read
Add as a preferred source on Google

AI-Assisted Attacks Hit South Korean Banks, Exposing Hacker Records

Shinhan Bank, KB Kookmin Bank and Hana Bank were targeted from late September through early October, with exposed Claude Code records revealing campaign details.

Empty bank corridor with a smartphone beside an access reader / TokenPost.ai
Empty bank corridor with a smartphone beside an access reader / TokenPost.ai

Multiple South Korean banks were targeted in AI-assisted cyberattacks from late September through early October, with exposed Claude Code records revealing how the campaign was organized and potentially identifying its operator.

The affected institutions included Shinhan Bank, KB Kookmin Bank and Hana Bank. The attacks reportedly targeted loan-status services used by financial intermediaries and mobile office systems used by bank employees, exposing personal information belonging to tens of thousands of customers.

Investigators identified ARTEX, an open-source agentic penetration-testing tool, at the center of the activity. The tool used DeepSeek v4.1-Flash as its main language-model backend, while Claude Code sessions also connected to GLM-5.3 from Zhipu AI and Grok 4.6 from xAI.

The operator left a server directory open, exposing ARTEX configuration files, Claude Code instruction documents, memory files and previous session records. The conversations included requests to find Telegram groups that trade South Korean data and to draft a cybersecurity researcher résumé.

The attacks have not been formally attributed to a specific individual or group.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…