AI-Assisted Attacks Hit South Korean Banks, Exposing Hacker Records
Shinhan Bank, KB Kookmin Bank and Hana Bank were targeted from late September through early October, with exposed Claude Code records revealing campaign details.

Multiple South Korean banks were targeted in AI-assisted cyberattacks from late September through early October, with exposed Claude Code records revealing how the campaign was organized and potentially identifying its operator.
The affected institutions included Shinhan Bank, KB Kookmin Bank and Hana Bank. The attacks reportedly targeted loan-status services used by financial intermediaries and mobile office systems used by bank employees, exposing personal information belonging to tens of thousands of customers.
Investigators identified ARTEX, an open-source agentic penetration-testing tool, at the center of the activity. The tool used DeepSeek v4.1-Flash as its main language-model backend, while Claude Code sessions also connected to GLM-5.3 from Zhipu AI and Grok 4.6 from xAI.
The operator left a server directory open, exposing ARTEX configuration files, Claude Code instruction documents, memory files and previous session records. The conversations included requests to find Telegram groups that trade South Korean data and to draft a cybersecurity researcher résumé.
The attacks have not been formally attributed to a specific individual or group.