ARTEX is an open-source agentic penetration-testing tool. On October 7, 2026, US cybersecurity firm CrowdStrike published an investigation reporting that from late September to early October 2026, an attacker used ARTEX together with several large language models to carry out targeted intrusions against multiple South Korean financial institutions and exfiltrate data. Reuters reported on October 8 that at least nine South Korean banks had disclosed or been reported as targets, and that South Korean police had opened a probe this week.
The attacker's own session logs became the breakthrough
CrowdStrike's intelligence team found its leads in open directories controlled by the attacker, which contained Claude Code session histories, ARTEX configuration files and memory files — effectively laying the operator's methods in front of researchers. According to the report, the attacker ran a two-server setup; the primary model backend was DeepSeek v4.1-flash, supplemented in some Claude Code sessions by Zhipu's GLM-5.3 and Grok 4.6. The sessions even included questions about where stolen Korean data is typically sold and requests for help finding data-trading groups.
The scope is still being confirmed
Based on South Korean media reports and bank disclosures, personal information of about 25,000 Shinhan Bank customers was compromised, while KB Kookmin Bank reported 119 customers affected. One breached system was a loan-progress inquiry service used by financial brokers; another was an employee mobile work-support system. CrowdStrike stated plainly that the exact number of affected organizations remains unconfirmed. South Korean President Lee Jae Myung has called for stronger cybersecurity measures.
Why the financial sector should pay attention
CrowdStrike's profile of the attacker is a moderate-confidence assessment: likely a Chinese speaker, financially motivated, but not attributed to any named group. Reuters reported that personal clues in the session material led researchers to believe the operator may be a 26-year-old located in Guangdong, while CrowdStrike stressed that available information cannot definitively identify the individual. The real warning is not the strength of one tool but the shift in thresholds: intrusions that once required a team working in shifts can now be advanced by one person directing agentic tools that find vulnerabilities and write exploit code on their own, hitting multiple institutions within roughly ten days. A CrowdStrike executive said on October 8 that this is a textbook example of a single adversary using AI agents to target many victims in a very short period.
For banks and financial institutions, defenses must adapt: assume a much faster attack tempo, and prioritize auditing internet-facing edge services, vendor systems and employee mobile entry points. For ordinary customers, extra caution with calls and messages impersonating banks is warranted in the coming weeks — verify through official channels first.