Banking · 9 October 2026
AI-powered hacking tools enabled a likely single attacker to breach multiple South Korean banks
According to CrowdStrike, a suspected Chinese-speaking attacker hacked multiple South Korean financial institutions. At Shinhan Bank alone, more than 25,000 customer records were stolen. The attacker used ARTEX, an open-source tool that uses AI models like DeepSeek and GLM-5.3 for automated penetration testing. CrowdStrike says the case shows how AI tools can let a single person pull off massive breaches. The article AI-powered hacking tools enabled a likely single attacker to breach multiple South Korean banks appeared first on The Decoder .
What happened
Security vendor CrowdStrike has identified a suspected Chinese-speaking attacker believed to have breached multiple South Korean financial institutions using AI-assisted hacking tools. At Shinhan Bank alone, more than 25,000 customer records were reportedly stolen.
According to CrowdStrike, the attacker used ARTEX, an open-source penetration-testing tool that harnesses AI models — including DeepSeek and GLM-5.3 — to automate parts of the intrusion process. CrowdStrike's analysis suggests the scale and reach of the campaign across several banks were achievable by what appears to have been a single operator.
Why it matters
The case is a concrete illustration of how generative and agentic AI tools are lowering the barrier to conducting complex, multi-target cyberattacks. Tasks that once required a coordinated team — reconnaissance, exploitation, lateral movement across networks — can now be substantially automated, letting a lone attacker operate at a scale and speed previously associated with organised groups.
For banks and other institutions handling sensitive customer data, this shifts the threat calculus. Defensive postures built around the assumption that large-scale breaches require well-resourced teams may need rethinking, as AI-augmented tooling compresses the cost and skill required to mount sophisticated, multi-institution campaigns.
By the numbers
- 25,000+ customer records reportedly stolen from Shinhan Bank in the breach.
- Multiple South Korean financial institutions were affected, according to CrowdStrike.
- Two named AI models — DeepSeek and GLM-5.3 — were reportedly leveraged by the ARTEX tool to automate penetration testing.
The Renascence take
Much of the commentary around AI-enabled hacking focuses on the technical novelty of the tools. The more important story for leaders is organisational: defensive capacity has historically scaled with headcount and budget, while offensive capacity is now scaling with access to AI models anyone can download.
This incident is less about one attacker and more about a structural shift in asymmetry: AI tools let a single actor replicate what used to take a team, which means the "it would take too much effort to target us" assumption no longer holds for mid-sized institutions. Customer-facing organisations — especially in banking, where trust is the product — should treat AI-augmented threat modelling as a board-level service-design issue, not just an IT one, because the next breach notification is itself a customer experience moment that will test how well they've prepared to communicate, contain and rebuild trust at speed.
Sources
This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.
More in Banking
Stay ahead of CX
Get the signal, not the noise.
The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.
