Chinese-Speaking Hacker Breaches South Korean Banks Using AI Tools
Article Content
- •A suspected Chinese-speaking hacker targeted South Korean banks using AI tools.
- •CrowdStrike linked the attacks to a 26-year-old individual in Guangdong, China.
- •The hacker utilized ARTEX and large language models to compromise banking systems.
A suspected Chinese-speaking hacker has targeted South Korean financial institutions, including Shinhan Bank and KB Kookmin Bank, using AI-powered tools. The attacks occurred between late September and early October 2026, with CrowdStrike reporting the use of ARTEX, a Chinese-developed open-source penetration testing tool, alongside large language models. The attacker appeared financially motivated, conducting searches for marketplaces selling stolen South Korean data. While CrowdStrike identified a 26-year-old suspect in Guangdong, China, the exact identity and extent of the breaches remain unconfirmed. Investigations are ongoing by South Korean authorities following these breaches, which have raised concerns about the security of financial systems against AI-assisted attacks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Hana Bank in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What banks were affected?
What tools were used in the attacks?
Is the attack still ongoing?
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…