Skip to content
Chinese-Speaking Hacker Breaches South Korean Banks Using AI Tools

Chinese-Speaking Hacker Breaches South Korean Banks Using AI Tools

First seen 8 Oct 2026, 06:31 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 08:32 UTC
  • •A suspected Chinese-speaking hacker targeted South Korean banks using AI tools.
  • •CrowdStrike linked the attacks to a 26-year-old individual in Guangdong, China.
  • •The hacker utilized ARTEX and large language models to compromise banking systems.

A suspected Chinese-speaking hacker has targeted South Korean financial institutions, including Shinhan Bank and KB Kookmin Bank, using AI-powered tools. The attacks occurred between late September and early October 2026, with CrowdStrike reporting the use of ARTEX, a Chinese-developed open-source penetration testing tool, alongside large language models. The attacker appeared financially motivated, conducting searches for marketplaces selling stolen South Korean data. While CrowdStrike identified a 26-year-old suspect in Guangdong, China, the exact identity and extent of the breaches remain unconfirmed. Investigations are ongoing by South Korean authorities following these breaches, which have raised concerns about the security of financial systems against AI-assisted attacks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-30
Cyberattacks on South Korean banks reported
CrowdStrike reported multiple breaches at financial institutions including Shinhan Bank and KB Kookmin Bank.
Straitstimes
2026-10-07
CrowdStrike report published
CrowdStrike detailed the use of AI tools in the cyberattacks and identified a suspect linked to the breaches.
Straitstimes
2026-10-08
Ongoing investigations announced
South Korean authorities confirmed investigations into the breaches following the CrowdStrike report.
Aa.Tr

More articles in this cluster (3)

Following this threat?

Track Hana Bank in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What banks were affected?
The cyberattacks targeted several South Korean banks, including Shinhan Bank and KB Kookmin Bank.
What tools were used in the attacks?
The attacker used ARTEX, an open-source penetration testing tool, along with large language models.
Is the attack still ongoing?
The current status of the attack is unclear, but investigations are ongoing by South Korean authorities.