CrowdStrike reported on October 7, 2026, that a string of intrusions against South Korean financial institutions from late September into early October was likely the work of a single attacker who leaned heavily on AI tools. Reporting by Reuters on October 8 confirmed the main points: at least nine South Korean banks have disclosed or been reported as targeted, police have opened an investigation, and President Lee Jae Myung has called for a robust response.
One person, one AI toolkit, a row of banks
The report's profile describes a suspected 26-year-old based in Maoming, Guangdong, China — likely a Chinese speaker acting for financial gain — but CrowdStrike rates that assessment as only moderate confidence and cautions that the available information cannot definitively identify the attacker. The toolkit included ARTEX, an open-source AI penetration-testing tool first posted on GitHub in July, alongside Anthropic's Claude Code. Researchers traced the case through Claude Code session logs found in the attacker's open directories: the logs contained attack activity, a request to draft a "security researcher" résumé, and searches for where Korean breach data is typically sold. Confirmed losses include personal data of about 25,000 Shinhan Bank customers — names, contact details, income, and credit limits — and 119 KB Kookmin Bank customers.
The warning is about capacity, not just identity
Breaching multiple banks used to take a team working for weeks. The report instead describes one person sweeping across institutions in about ten days with agent tooling. That is the point CrowdStrike executives made to reporters: AI lets a single human target many victims in a very short window. Bank defenses were designed assuming attackers have limited manpower; when scanning, vulnerability discovery, and exploit writing are delegated to tools, the defender's response window shrinks to hours.
How to read this report
Two cautions apply. First, the attribution is still "likely": the profile comes from logs the attacker left behind, which cannot be independently verified and could be staged. Second, the tools involved are publicly available; Claude Code appearing in the logs does not mean one vendor's guardrails uniquely failed. It is an industry-wide reality that coding agents serve defenders and attackers alike. For financial institutions, the practical step is to rehearse against agent-speed attacks rather than wait for the next emergency meeting.