Last week, South Korea’s biggest banks were getting hammered. Shinhan, Kookmin, Hana, seven financial institutions total, breached in a coordinated campaign that exposed the data of over 65,000 consumers. The Financial Services Commission convened emergency sessions. President Lee Jae Myung ordered an investigation. KISA raised the national cyber alert level from “Caution” to “Watch.”
And according to CrowdStrike’s threat intelligence report, the entire operation might have been executed by one person.
Not a nation-state. Not a sophisticated criminal syndicate. One individual, allegedly armed with a stack of open-source AI tools, ARTEX, DeepSeek v4.1-Flash, GLM-5.3, Grok 4.6, and Claude Code, who managed what would have previously required a coordinated team of skilled operators.

This isn’t just another data breach story. This is the first confirmed case where agentic AI tooling, not a single LLM, but an orchestrated stack of them, was deployed in a real-world, multi-target financial crime spree. And the implications for defenders are genuinely terrifying.
The ARTEX Stack: A Kitset for Cybercrime
Let’s break down what this attacker actually used, because the specifics matter.
ARTEX is an open-source, autonomous penetration-testing system built on large language models with a multi-agent architecture. It was released on GitHub in July 2026 by the account Autumn-27 under an AGPL-3.0 license, and it won the “Agent+” challenge run by the Baidu Security Response Center, finishing first among roughly 150 teams. As of early October, the repository had 1,655 stars and 376 forks.
Even the developer behind ARTEX, a Chinese cybersecurity engineer known by the alias Autumn, designed it for legitimate vulnerability discovery. But here’s the uncomfortable truth about open-source security tools: they don’t stay in the hands of the good guys.
The toolkit went beyond ARTEX alone. CrowdStrike’s analysis of attacker-controlled infrastructure uncovered Claude Code session histories and config files showing the operator cycled through multiple LLMs for different tasks. The ARTEX instance used DeepSeek v4.1-Flash as its primary backend, supplemented by GLM-5.3 (Zhipu AI) and Grok 4.6 for additional Claude Code sessions. DeepSeek was likely accessed through an API proxy or reseller.
The operational architecture was a two-server setup: a Hong Kong-based IP serving as the primary command infrastructure, with the ARTEX instance at 38.244.50[.]120 handling the Korean attacks. The attacker burned through at least nine proxy IPs to obscure the trail.
What the Attack Actually Looked Like
The technical timeline reveals a methodical campaign starting September 28. The attacker didn’t go after consumer-facing banking apps, those have the heaviest security investment and most aggressive monitoring. Instead, ARTEX targeted the soft underbelly: peripheral business-support systems.
The attack pattern was credential stuffing on steroids. AI agents fed large volumes of username/password combinations from prior data breaches into login portals, but adaptively, varying timing, rotating infrastructure, and adjusting parameters in response to defenses without a human in the loop. What made this different from traditional credential-stuffing campaigns wasn’t the technique, it was the elimination of the skill floor. An agent that tries, verifies, and tries again never gets tired.
The breach results were staggeringly asymmetrical:
| Institution | Data Compromised | Hours to Detect |
|---|---|---|
| Shinhan Bank | 25,727 customers | 15 |
| Yegaram Savings Bank | ~40,000 customers | Not disclosed |
| Welcome Savings Bank | ~2,200 corporate records | Not disclosed |
| KB Kookmin Bank | 119 customers | 67 |
| Hana Bank | 89 customers | 41 |
| BNK Busan Bank | 11 external developers | Not disclosed |
| Hyundai Capital | Mortgage broker data | Not disclosed |
The three major banks combined had spent 124 billion won (about $92 million) on security the previous year. The paradox is almost tragic: they deployed enterprise-grade defenses on the castle walls while leaving the supply gate wide open.
“Opsec Level: CLAUDE.md”
Here’s where the story takes a turn from scary to almost darkly comedic.
CrowdStrike found open directories on the attacker’s own infrastructure. Directory listing was enabled. The attacker left files like CLAUDE.md, a Chinese-language penetration testing prompt designed to instruct the LLM, exposed to anyone who looked. Then there were the Claude Code session histories, the ARTEX config files, and the Claude memory files.
Let’s break down what was left lying around:
- Questions like “Where can I sell this data?” and requests to find Korean Telegram data sales groups
- An attempt to have Claude produce a security researcher résumé that included the results of the ARTEX activity
- Personal details in the prompts: Name (“YY”), phone number, Telegram username (
@YY520CN), age (26), education (South China University of Technology), and location (Maoming, Guangdong, China)
Adding insult to injury, the attacker also asked Claude to include the hack results in the résumé. The “resume achievement” of hacking Korean banks is… not the way to impress a future employer.
The online security community reacted with a mix of schadenfreude and mockery. A popular observation was that the level of operational security was “CLAUDE.md”, referencing the config file that exposed the entire operation. Perhaps one of the more pointed quips summarized the situation succinctly: this was less “mission impossible” and more “vibe hacking”, an amateur with access to professional-grade tools, inadvertently documenting their own crime spree.

Why This Matters Beyond Mood Lighting
Beyond the schadenfreude, this incident signals something deeper. The threat isn’t that an AI was “smart”, it’s that the barrier to entry for sophisticated cyberattacks has essentially collapsed.
The Oasis Security AGATHA platform identified 359 unique IP addresses globally associated with ARTEX-related activity. More than 91 percent of that infrastructure was on overseas servers, with over half routed through a single hosting network. A second framework, CyberStrikeAI, was observed operating approximately 1,000 servers during the same period.
The infrastructure isn’t the story. The accessibility is. ARTEX is free, open-source, and available on GitHub with 1,655 stars. To point it at a target, you no longer need exploit development skills, botnet management, or deep knowledge of authentication bypass techniques. You need an API key to an LLM backend and the motivation.
Let’s put this in historical context. Traditional credential-stuffing campaigns required attackers to manage bot infrastructure, rotate proxies, handle authentication challenges, and analyze results. Each step was a potential failure point that demanded human expertise. ARTEX automates the entire loop: reconnaissance, vulnerability identification, exploit execution, and result verification.
This is precisely what the National Intelligence Service’s National Information Security White Paper warned about: hacking groups are progressing toward “agentic AI”, systems capable of executing attacks autonomously without continuous human direction.
One security engineer I know summarized the financial reality: in a similar case with frameworks like Strix, Cairn, and Hermes, the attacker spent an average of $25.46 per target. Minimum spend: $3.13. For that price, you get an AI agent that does reconnaissance, plans attack paths, launches tools, and verifies results on its own.
A Chinese Tool Doesn’t Mean Chinese Hackers
It’s tempting to treat the ARTEX origin story as the whole story. The tool is Chinese-developed. The prompts were in Chinese. The suspected actor studied in Guangdong. But as Lee Eog-weon, chairman of the Financial Services Commission, reportedly noted, we’re overcomplicating attribution.
The Financial Supervisory Service mapped 33 IP addresses across 12 countries, including the United States (the largest group at 5 addresses), Japan, Hong Kong, Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, and Sweden. The ARTEX repository remains online with 1,655 stars, freely available to anyone.
Park Sang-won, head of the Financial Security Institute, put it bluntly: the tool’s language says more about the software’s origin than the attacker’s geography. This pattern is familiar, a few years ago, state-sponsored hackers using jailbroken AI models were already demonstrating how open-source AI could be weaponized. The difference is now it’s available to lone actors with minimal resources.
The Regulatory Reckoning
South Korea’s response has been appropriately aggressive, though the measures feel remedial rather than novel.
The FSC’s post-incident directive ordered checks of externally accessible systems, stronger authentication, and tighter access controls, security basics that institutions should have already maintained on any system holding national ID numbers and income data. Phase II EFTA reforms are planned to operationalize administrative fines and strengthen CEO and board accountability for cybersecurity failures.
President Lee’s directive, via AFP, acknowledged the threat shift: “AI can make hacking easy even for people with no particular skills.” That statement, perhaps more than any technical detail, captures the essence of what happened.
But there’s a troubling gap between what banks thought they were defending against and what they were actually facing. The three banks that spent $92 million on security last year still experienced dwell times of 15 to 67 hours. The attackers went unnoticed long enough to exfiltrate meaningful data.
What Defenders Should Actually Do
The uncomfortable implication is that traditional signature-based detection and perimeter defenses are insufficient. Here’s what security teams should be prioritizing:
1. Treat peripheral systems like core systems. The attacker didn’t touch core banking infrastructure, they went after loan broker portals, employee mobile support systems, and sales support databases. Organizations need to inventory every internet-accessible system and apply consistent authentication rigor, monitoring, and response capabilities. A lazy 2FA implementation on a partner portal is an imminent breach.
2. Recognize the dwell-time asymmetry. When attackers are automated, they operate 24/7 and iterate attacks faster than humans can respond. Manual SOC processes designed around human behavior will struggle. Automated detection and response, the AI-powered vulnerability scanning approaches many are prototyping, need to be production-ready, not research projects.
3. Adopt AI for defense. The Korean government recognized this explicitly: “systems capable of using AI to defend against AI will be needed.” But let’s be careful about what this means. AI-powered defense isn’t just about deploying a chatbot that answers security questions. It’s about using machine learning to detect behavioral anomalies, automating containment actions, and integrating AI into the detection loop. CrowdStrike and other vendors have been pushing this, but the adoption gap between what’s possible and what’s deployed remains massive.
4. Prepare for the “second wave.” Authorities fear secondary attacks, vishing and smishing campaigns leveraging the stolen data (names, phone numbers, resident registration numbers, annual income, loan limits) to target individuals. This is a reminder that data breaches have a long-tail impact: the data doesn’t have an expiration date, and AI tools make it easier to use that data in convincing social engineering attacks.
The Attacker of the Future Isn’t Coming. He Already Arrived.
Nathan Lambert, an AI researcher, tweeted something that stuck with me: “so long as Claude Code can be the orchestrator of a hack we desperately need open models to diffuse defense as well.”
The South Korean attack is not about one amateur’s spectacular failure of operational security. It’s about what happens when an entire class of destructive capability becomes accessible to anyone who can follow a README. The “skill floor” for cybercrime has been eliminated. The attackers aren’t necessarily smarter, they’re just better-equipped.
The tools will keep improving. ARTEX already has competitors, CyberStrikeAI was observed running about 1,000 servers simultaneously. Attackers are learning from each other’s failures. The next operator will have better OPSEC, better infrastructure, and perhaps a cleaner résumé.
For defenders, the message is clear: your security posture needs to be measured in hours patch-to-deploy, not years organization-wide. You need automated defenses because attackers are already automated. The “technological lag” the Korea Times identified in the financial sector isn’t unique to South Korea.
The next attack may not come from a recognizable group or a sophisticated nation-state. It might come from a student in Guangdong, a researcher in Lagos, a developer in São Paulo, someone who cloned a GitHub repo, configured an API key, and pointed a tool at your organization. The security implications of LLM-powered code analysis extend beyond your pull requests, they’ve become the foundation of offensive operations.
The question isn’t whether AI-powered attacks will happen against your organization. It’s whether your defenses are already automated enough to respond when they do.
The CISO’s checklist for the agentic AI era:
- Can you detect AI-generated credential stuffing patterns in real-time?
- Is your incident response automated enough to contain intrusions within minutes, not 43 hours?
- Are your peripheral systems defended like your core systems?
- Have you tested your defenses against an ARTEX-class attack, not just a human adversary?
The “one guy, five models, zero standups” joke from the security community is funny because it’s true. The next incarnation may not be a joke at all, it’ll be the norm. And the defenders who haven’t already adapted will be the ones explaining to regulators why a $25 AI tool was enough to bring down their banks.




