🌏 中文版
What happened
Between late September and early October 2026, at least seven South Korean financial institutions — including KB Kookmin Bank, Shinhan Bank, and Hana Bank — reported customer data breaches. CrowdStrike Intelligence traced unauthenticated open directories the attacker had left on servers in Hong Kong and elsewhere, finding Claude Code session histories, Claude memory files, and ARTEX configuration files. From these, CrowdStrike reconstructed how the attacker used ARTEX, an open-source agentic penetration-testing tool, together with multiple LLMs, to automate the intrusions. The actor hasn't been attributed to a known group, but the evidence points to a financially motivated, Chinese-speaking operator.
Key facts
| Item | Detail |
|---|---|
| Incident type | Weaponized agentic AI tooling (data exfiltration) |
| Scope | At least 7 South Korean financial institutions, 68,000+ people's data exposed |
| Severity | High |
| CVE | None — this is tool misuse combined with pre-existing access-control gaps, not a single software flaw |
| Sources | The Hacker News, CrowdStrike's official writeup, WSJ, qz.com |
Attack surface
ARTEX is an LLM multi-agent autonomous pentesting system released in July by Chinese developer Li Puhua (alias Autumn, GitHub handle Autumn-27), pitched for research and authorized security testing — it even won a "Agent+" red-vs-blue challenge hosted by Baidu in September. The infrastructure CrowdStrike recovered shows a two-server setup: a Hong Kong IP served as the operator's main hub, while a second IP (38.244.50[.]120) ran the ARTEX instance, backed primarily by DeepSeek v4.1-flash with Zhipu AI's GLM-5.3 and Grok 4.6 as supplementary models, likely reached through the LLM API reseller xcai[.]pro. The entry points at the two banks were a loan-progress inquiry service used by brokers, and an employee mobile work-support platform — both pre-existing systems open to a specific user base with weaker authentication, not an AI flaw in the bank's own products.
What made the attack work wasn't a novel AI vulnerability — it was agentic automation collapsing what used to require constant human operation into "press a button once, let the AI keep adapting its strategy around the clock." ARTEX autonomously gathered recon, hunted for weaknesses, planned attack paths, and executed them, cutting the attacker's time and labor cost dramatically. This incident doesn't map neatly onto a single OWASP LLM Top 10 category — the target's LLM wasn't prompt-injected or hijacked; the attacker simply turned agentic AI into attack infrastructure. CrowdStrike's own MITRE ATT&CK mapping classifies acquiring ARTEX under T1588.007 Obtain Capabilities: Artificial Intelligence, which sits closer to an emerging tactic category — "AI tooling lowering the bar for automated intrusion" — than to an application-layer bug. Ironically, what exposed the attacker was the same kind of OPSEC failure common in agentic workflows generally: leaving Claude Code session logs, config files, and memory files sitting in an unauthenticated open directory, along with what appears to be the operator's own name, phone number, and Telegram handle.
Defense
Immediate actions
- Audit broker-facing and employee-facing systems like loan-inquiry portals and mobile work platforms to confirm authentication and rate limiting can withstand bursts of automated probing, not just human-paced attacks
- Check any agentic or pentesting tooling you run for exposed config files, API keys, or session logs sitting in unauthenticated directories — that's exactly the slip that let defenders here reconstruct the whole attack, a reminder that agent workflow logs are both an asset and a liability
Long-term architecture
- Shift from signature-based detection toward behavior-baseline anomaly detection; agentic attacks adapt their path in real time, so rule-based detection tuned to known patterns has limited reach
- Apply Zero Trust and least privilege to high-value financial and internal systems to limit blast radius when any single access point is compromised
- Evaluate watchlist tools like Lakera or Invariant Labs for agent-runtime behavioral monitoring to flag "structurally similar probing against multiple sensitive endpoints from one external source in a short window," and use supply-chain/tooling scanners like Protect AI to regularly check whether your own exposed services are unintentionally leaking indexable configs or logs
Impact
At least seven South Korean financial institutions are confirmed affected, with over 68,000 people's personal data exposed (per WSJ and qz.com); per-institution breakdowns vary across outlets, and CrowdStrike's own analysis notes the total number of affected organizations remains unconfirmed as of writing — treat per-bank figures as provisional pending official findings. There's no "patch" in the usual sense here: ARTEX isn't a vulnerability but a tool, and its author, Autumn-27, took the project closed-source and halted all updates and maintenance after the misuse came to light, stressing that it violated the tool's intended, authorized-testing purpose. What actually needs fixing is the access-control gaps in each victim institution's own systems, and that timeline hasn't been disclosed. South Korea's police cyber unit has opened a formal investigation.
If your organization runs agentic tooling internally or externally — whether for defense or testing — this incident is a reminder of two things: first, the config files, session logs, and memory files agentic workflows generate become an incident starting point if access to them isn't managed, regardless of which side you're on; second, routing model access through an LLM API reseller layer makes traffic harder to attribute to its true source, which is worth factoring into anomaly-detection design on the defending side.
Today's takeaway
What's interesting here is that defenders didn't piece this together by patching a hole or blocking malicious traffic — they reconstructed the entire attack chain from the attacker's own agentic-workflow mistake: an unauthenticated open directory leaking full Claude Code session logs and tool configs. Most "AI security incident" coverage is about the defender's AI system getting breached. This one flips that: the attacker's own AI workflow logs became the evidence that cracked the case, which says access control on agent operation logs matters just as much no matter which side you're on.
References
- ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms — The Hacker News
- Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance — CrowdStrike Intelligence
- Hackers Use Chinese AI Tool to Hit South Korean Banks, Exposing New Risk — The Wall Street Journal
- Hackers used Chinese AI tool Artex used to hack South Korean banks — Quartz
- South Korea Suspects AI Tool Helped Steal Bank Customer Data — GovInfoSecurity
Loading...