AI-Assisted Bank Attacks Put Agentic Cybersecurity on the Global Agenda

by Ben Voss
AI-Assisted Bank Attacks Put Agentic Cybersecurity on the Global Agenda

AI-Assisted Bank Attacks Put Agentic Cybersecurity on the Global Agenda

A suspected China-based attacker used an AI agent and automated penetration-testing software in a campaign against South Korean financial institutions, according to CrowdStrike and Reuters. The incidents show how one operator can use AI to expand the scale and speed of attacks, while forcing banks, insurers, and technology companies to rethink responsibility for AI-assisted actions.

At least nine South Korean banks have disclosed or were reported to have been targeted since late September. Shinhan Bank said personal information belonging to about 25,000 customers was compromised, while KB Kookmin Bank reported that information on 119 customers was leaked. South Korean police have opened an investigation, and President Lee Jae Myung has called for a strong response.

How AI was used

CrowdStrike said the suspected attacker combined ARTEX, an open-source agentic penetration-testing tool developed in China, with large language models and Anthropic's Claude Code. ARTEX is designed to automate parts of security testing and connect to external AI models. Its GitHub page says it is intended for learning, code research, and local technical verification—not unauthorized testing of real-world systems.

Researchers found exposed server directories containing Claude Code session histories, ARTEX configuration files, and memory files. CrowdStrike said the attacker used DeepSeek v4.1-flash as the primary model for ARTEX and also used GLM-5.3 from Zhipu AI and Grok 4.6 during separate Claude Code sessions. The company assessed with moderate confidence that the operator was a Chinese speaker and financially motivated, but it has not attributed the activity to a named group.

The important development is not that AI independently decided to attack banks. The evidence instead points to a human operator using AI agents to automate reconnaissance, vulnerability research, coding, and other repetitive tasks. CrowdStrike said this allowed one person to target many customers in a short period.

Why the incident matters

Traditional security programs often assume that an attacker must manually perform each step of an intrusion. Agentic tools can compress those steps, allowing attackers to test more systems, adapt to failures, and continue working with less direct supervision. That increases pressure on organizations to monitor API access, limit automated activity, and identify machine-generated behavior across application and network logs.

The campaign also creates difficult questions for cyber-insurance policies and incident response. Reuters reported that insurers are reviewing whether autonomous or semi-autonomous AI systems fit existing definitions of a cyber attacker and who should bear responsibility when a model-assisted action causes a loss.

South Korean regulators have warned financial companies about phishing and fraud risks following recent breaches. The Financial Services Commission and Financial Supervisory Service instructed firms to strengthen fraud monitoring, provide assistance to affected customers, and share suspicious information through the country's AI-based anti-phishing Sharing & Analysis Platform, known as ASAP.

What organizations should do now

  1. Inventory every AI agent, coding assistant, and automated security tool connected to corporate systems.
  2. Restrict agents to the minimum files, networks, credentials, and APIs required for their task.
  3. Log and review agent activity separately from human activity so unusual automation is visible.
  4. Test internet-facing services for abuse by automated tools, not only for conventional malware.
  5. Update incident-response and insurance plans to address actions performed with AI assistance.

The South Korean attacks remain under investigation, and the full scope of the affected organizations is not yet confirmed. But the case already offers a clear warning: defensive systems designed for human-speed attacks may not be sufficient when AI helps adversaries operate continuously and at scale.

References

Campion, A. (2026, October 7). Unknown threat actor uses AI-driven ARTEX to target South Korean finance. CrowdStrike. https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/

Shim, K.-S., & Goh, B. (2026, October 8). South Korean banks were likely hacked by a China-based actor with an AI agent, CrowdStrike says. Reuters. https://live.euronext.com/en/financial-news/south-korean-banks-were-likely-hacked-china-based-actor-ai-agent-crowdstrike-says

Financial Services Commission. (2026, October 6). FSC-FSS issue consumer alert over potential phishing scams following data breaches in financial sector. https://fsc.go.kr/eng/pr010101/87887?curPage=1&srchBeginDt=&srchCtgry=&srchEndDt=&srchKey=&srchText=