News

AI-powered hacker who hit Korean banks may have exposed themselves by asking Claude to write a CV

CrowdStrike says an attacker used the open-source AI pentest tool ARTEX against South Korean banks, and left Claude Code logs online, including a request to write a CV with personal details.

djcroman news card: AI-powered hacker who hit Korean banks may have exposed themselves by asking Claude to write a CV

A hacker who broke into several South Korean banks with the help of AI tools may have given themselves away in the most ordinary way possible: by asking an AI to write a CV. That is one of the more surprising details in a report that the US security company CrowdStrike published on 7 October 2026. The report looks at the tooling behind a wave of data breaches that hit Korean banks and lenders at the end of September, and it shows how far AI agents have already moved into real criminal operations.

The story has two sides. One is worrying: an open-source AI hacking tool that was published only in July was apparently used to break into banks within days of its latest update. The other side is almost comic: the attacker left their own working folders open on the internet, including the logs of their conversations with Claude Code, and one of those conversations was a request for a security researcher résumé built around the results of the attack.

Timeline: ARTEX appears on GitHub on 26 July 2026, wins a Baidu hosted contest on 3 September, gets its latest version on 24 September; the attack on KB Kookmin Bank begins on 27 September, data leaks follow until 30 September, regulators meet on 4 October and CrowdStrike publishes its report on 7 October

What happened at the banks

Between 27 and 30 September 2026, several Korean financial institutions reported data leaks after outside intrusions. According to the Korean newspaper Kyunghyang Shinmun, which cited financial authorities and industry sources, the list includes Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank and Hyundai Capital. Two online lending platforms were also hit, and Welcome Savings Bank reported a separate leak of more than 2,200 corporate customer records on the same day. Analysts quoted by the paper believe the number of companies that saw attempted attacks is much larger.

Shinhan Bank took most of the damage. The paper reports that 25,727 items of personal information were taken there, and not just names and phone numbers: the stolen data also included annual income and loan limits. At KB Kookmin Bank the data of 119 customers leaked, at Hana Bank the data of 89 customers.

Bar chart of stolen records per institution: Shinhan Bank 25,727, Welcome Savings Bank more than 2,200 corporate records, KB Kookmin Bank 119, Hana Bank 89

The attacks did not go through the front door. The main online and mobile banking apps were not breached. Instead, the attacker went after smaller systems at the edge of each bank. At Shinhan it was a loan progress inquiry service used by loan brokers. At Kookmin it was an internal mobile app that employees use for their daily work. CrowdStrike describes exactly these two systems in its own report.

Korean security experts told the paper that the method looked like an automated brute force approach. The attacker fed random values into the broker service until valid customer numbers came back, then pulled the matching contact and loan data. The authorities see it less as a targeted strike on one company and more as an AI tool probing many companies at once, with the weakest ones falling first.

The reaction was serious. On 4 October, a public holiday in Korea, the Financial Services Commission called an emergency meeting for the whole financial sector, and the heads of Shinhan, KB Kookmin and Hana Bank were summoned. President Lee Jae Myung called for a thorough investigation. The Financial Supervisory Service and the Financial Security Institute started on site inspections at Shinhan.

ARTEX: a pentest tool turned weapon

The tool at the center of the story is called ARTEX. It is an autonomous penetration testing system built on large language models, and it is open source on GitHub. Penetration testing, or pentesting, means attacking your own systems on purpose to find holes before real attackers do. ARTEX automates that work: it lets an AI agent plan and run the steps of an attack on its own.

According to the Kyunghyang report, ARTEX was published on 26 July 2026 by a developer known only by a GitHub handle. On 3 September it took first place among about 150 teams at an attack and defense competition hosted by Baidu in China. Its latest version came out on 24 September. Three days later, on 27 September, the attack on Kookmin Bank began.

Korean researchers first spotted the link. The head of the Genians Security Center wrote on 2 October that the web servers used in the attacks carried the string "ARTEX" in their page titles, together with a Chinese phrase that translates as "autonomous penetration test console". CrowdStrike then went further and analyzed the servers themselves.

Inside the attacker's servers

CrowdStrike found that one server tied to the attacks hosted an ARTEX instance and an open directory, a folder that anyone on the internet could browse. In it sat a CLAUDE.md file. That is the instruction file that Claude Code, Anthropic's coding agent, reads at the start of a session. In this case it held a Chinese language prompt telling the AI how to carry out penetration tests. It also mentioned a second server in Hong Kong.

That Hong Kong server turned out to be the attacker's main base. It also had open directories, and they contained Claude Code session histories, ARTEX configuration files and Claude memory files. In other words, CrowdStrike could read along with what the attacker had asked the AI tools to do from late September to early October.

Diagram of the setup: a Hong Kong server as main attacker infrastructure that ran the Claude Code sessions, an ARTEX server with a Chinese language attack prompt, the AI models DeepSeek v4.1 Flash, GLM-5.3 and Grok 4.6 run through Claude Code, and side door targets such as a broker loan service and a staff mobile app

The details are interesting for anyone who follows the AI model market. The ARTEX instance used DeepSeek v4.1 Flash as its main language model. For additional Claude Code sessions, the attacker added GLM-5.3 from Zhipu AI and Grok 4.6. So although Claude Code was the agent framework, most of the thinking was done by other models plugged into it. CrowdStrike believes the attacker reached DeepSeek through a reseller service that passes API requests along.

The logs also show what the attacker cared about after the break in. The attacker asked Claude where criminals usually sell stolen Korean data, and also asked for help finding Korean Telegram groups that trade such data. That is one reason CrowdStrike calls the actor financially motivated.

The CV that gave it away

Then comes the detail that made this report go viral. In one Claude Code session, the user asked Claude to write a résumé for a security researcher. The CV was supposed to include bullet points describing the results of the ARTEX operation, in effect turning the bank attacks into career highlights. To do that, the user typed in personal details: a name, a phone number, a Telegram account, an age of 26, a degree from a university in Guangdong and a home city in southern China.

CrowdStrike published those details in its report. We are not repeating the name, phone number or account here, because the identity has not been confirmed. CrowdStrike itself is careful: it says the details "likely belong" to the threat actor, but that the available information cannot definitively connect them. The same Telegram handle also shows up in other Claude Code sessions that looked for weaknesses in a Telegram based NFT gift marketplace and in what may be a Chinese payment platform.

There is an obvious lesson here, and it is not new: the weakest point of many attackers is their own operational security. What is new is the place where the mistake happened. AI agents keep logs, memory files and instruction files. They make work faster, but they also leave a detailed written record of everything the user asked for. When that record sits in an open folder, it becomes evidence.

Who is behind it

CrowdStrike has not tied the activity to any known hacking group. Its assessment, made with moderate confidence, is that the attacker is a Chinese speaker and financially motivated. The reasons are the Chinese developed tool and the Chinese language prompts.

Korean officials warn against jumping to conclusions. The president of the Financial Security Institute told reporters that ARTEX is open source and available worldwide, and that attack IP addresses can be routed through many countries, so they alone cannot identify an attacker. The attacks used IP addresses from eight countries, including Korea, the United States, Japan and Hong Kong. CrowdStrike lists nine proxy addresses in its report. Yonhap, Korea's national news agency, also stresses that the identity, the full extent of the breaches and the total amount of stolen data are still unconfirmed.

Why this matters

Security researchers have warned for two years that AI agents would lower the bar for hacking. This case is one of the clearest real world examples so far. A single actor, probably working alone or in a small group, used a free tool and a handful of commercial language models to hit many financial institutions within a few days. CrowdStrike writes that AI tooling can enable a financially motivated threat actor to conduct multiple intrusions in a short time, and that it expects attackers to keep experimenting with it.

Three points stand out.

  • Speed. Only three days passed between the latest ARTEX release and the first attack. Defenders no longer have weeks to react after a new offensive tool appears.
  • Breadth over depth. The attacker did not need a clever exploit against core banking systems. An agent that tries random inputs against many peripheral services, without getting tired, is enough to find the one that is poorly protected.
  • Mixed model stacks. The attacker combined several models from different companies inside one agent framework. Blocking abuse at a single AI provider does not stop that kind of setup, because the attacker can swap in another model behind the same tool.

For banks, the lesson is simple and uncomfortable: every small service with a login form or an open API is now part of the attack surface, because AI agents can test all of them at once. Rate limits, proper authentication on internal apps and monitoring for unusual query patterns matter as much as the security of the main banking app.

The secondary risk is phishing. Korean authorities worry that names and phone numbers combined with income and loan limits can be used for very convincing scam calls that look like real loan offers. Customers of the affected banks should treat unexpected loan calls and messages with extra suspicion.

For AI companies, the case raises the question of how much they can see and stop. Claude Code was the shell, but the attacker mostly ran other models through it. Anthropic and other providers have published reports about blocking misuse of their own models. Here, the most useful signal for investigators did not come from any provider at all, but from logs the attacker forgot to hide.

What comes next

The investigations in Korea are still running. Shinhan Bank has formed a task force and says it will announce compensation plans after talking to regulators. CrowdStrike has published the IP addresses and server details so that other companies can check their own logs. Whether the person behind the CV is really the attacker is still an open question, and so is whether more banks were hit than are known so far.

What is already clear is that this will not be the last case. Open-source AI attack tools are getting better every month, and they are easy to download. The difference between a red team tool and a criminal tool is only who runs it.

Sources

Source: crowdstrike.com

Newsletter

The AI news that matters, in your inbox.