Asia Insurance Post
  • Home
  • Articles
  • Blog
  • Data
  • Facts
  • Editorial
  • Interviews
Select Page

South Korean banks were likely hacked by a China-based actor with an AI agent, CrowdStrike says

by AIP Online Bureau | Oct 8, 2026 | Banking & Bancassurance, Eco/Invest/Demography, International News, Risk Management, Technology | 0 comments

Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told reporters on a call on Thursday that this was an example of a human adversary leveraging AI agents to conduct widespread attacks.

The suspect behind recent cyberattacks at South Korean banks was likely a China-based 26-year-old who used a Chinese-developed AI agent and Anthropic’s Claude Code, US cybersecurity company CrowdStrike said.

In a report published on Wednesday, CrowdStrike said it believed the suspect was likely based in China’s Guangdong province after uncovering personal details linked to the suspected attacker while analyzing AI coding-tool sessions and infrastructure associated with the hacking campaign.

At least nine South Korean banks have disclosed or have been reported by local media as having been targeted by cyberattacks since late September, prompting South Korean police to launch a probe this week and President Lee Jae Myung to call for robust response measures.

Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told reporters on a call on Thursday that this was an example of a human adversary leveraging AI agents to conduct widespread attacks.

“And this is significant because it allows one human to target many customers in a very short period of time using the power of AI,” he said.

The case is likely to intensify security concerns over the rise of AI agents and whether organizations are prepared to defend their systems against them.

Shinhan Bank said last week that personal information of about 25,000 of its customers was compromised, while KB Kookmin Bank said that the personal information of 119 of its customers was leaked.

Australia said last month that an OpenAI autonomous agent breached a government health statistics portal in June, marking one of the first known instances of an AI agent hacking a government system.

Such incidents are forcing cyber insurers to review their policies, as they come to grips with issues including whether autonomous AI systems fit traditional policy definitions of a cyber attacker and who bears liability for AI-generated actions that cause a loss.

Chinese-Speaking Actor

CrowdStrike said the attacker used ARTEX, a recently released Chinese-developed open-source penetration testing tool, alongside large language models such as Anthropic Claude.

“While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated,” its report said.

“This assessment is made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts.”

CrowdStrike said the individual also asked Claude where threat actors typically sell Korean data breach information and sought assistance in finding Korean Telegram data sales groups.

In another session, the person also requested Claude to create a security researcher resume, which included details such as a Telegram account, age, educational background and a location in Maoming, a city in the southern Chinese province of Guangdong, which CrowdStrike said likely belonged to the attacker.

A man who answered a phone number published by CrowdStrike in its report said he had no knowledge of the matter.

Chinese foreign ministry spokesperson Mao Ning told a regular press briefing that the ministry was not familiar with the case and that China as a matter of principle has consistently opposed and combated hacking activities.

Anthropic and South Korean police did not respond to requests for comment.

ARTEX is an open-source AI agent for automated penetration testing that was published on GitHub this year by a Chinese security engineer with the handle Autumn. It is not a standalone large language model but connects to external LLMs such as ChatGPT, Claude and DeepSeek to help organizations test for vulnerabilities in their networks.

The tool’s GitHub page says it is intended for personal learning, code research and local technical verification and should not be used to conduct real-world testing against online systems or websites.

Submit a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • South Korean banks were likely hacked by a China-based actor with an AI agent, CrowdStrike says
  • FSSAI issues notices to Dr Reddy’s, Nestle Health Science, Amazon, Flipkart for misleading claims
  • Govt to cap trade margins at 30 pc of MRP for anti-cancer drugs, say sources
  • NMC bars AI-generated patient testimonials, clinical outcomes in medical advertising
  • GST Council allows employers to get Input Tax Credit on GST paid for employee insurance cover

Categories

  • Articles
  • Banking & Bancassurance
  • Blog
  • Breaking News!
  • Briefs
  • Climate, Environment, Renewable Energy
  • Data
  • Disaster & Management
  • Eco/Invest/Demography
  • Editorial
  • Events
  • Facts
  • Features
  • Health
  • Indian News
  • Intermediaries
  • International News
  • Interviews
  • Life
  • Main Menu
  • Non-Life
  • Pandemic
  • Pension & Social Security
  • Policy
  • Regulation
  • Reinsurance
  • Risk Management
  • Simple
  • Technology
  • Trends, Facts
  • Uncategorized
  • Wealth Management/ Philanthropy
  • Workplace/Employee Benefits
  • Home
  • Articles
  • Blog
  • Data
  • Facts
  • Editorial
  • Interviews
  • Eco/Invest/Demography
  • Indian News
  • International News
  • Health
  • Non-Life
  • Pandemic
  • Technology
  • Risk Management
  • Reinsurance
  • Banking & Bancassurance
  • Wealth Management/ Philanthropy