About

The consultancy born at the intersection of behavioral economics and human experience.

RENÉ STUDIO

The CX design platform we built from a decade of client work.

Open rene.cx ↗
NOW HIRING

Join a team reshaping how the world experiences brands.

View open roles →

COMPANY

GROW WITH US

CONNECT

Services

Comprehensive CX and management consulting for enterprise brands.

RENÉ STUDIO

Every engagement, mapped and scored in one AI workspace.

Open rene.cx ↗
ALL SERVICES

Explore the full range of CX & management consulting services.

Browse all services →

CORE

SPECIALIST

Solutions

Structured solutions that turn CX ambition into measurable outcomes.

RENÉ STUDIO

Map, score and fix the journeys we redesign, with AI.

Open rene.cx ↗
ALL SOLUTIONS

Explore every CX solution we offer.

Browse solutions →

STRATEGY & GOVERNANCE

DESIGN & DELIVERY

CULTURE & EXPERIENCE

Industries

A decade of CX transformation across the region's defining sectors.

RENÉ STUDIO

Sector-ready journeys, scored by AI in minutes.

Open rene.cx ↗
ALL INDUSTRIES

See how we work across every sector.

Browse industries →

BUILT ENVIRONMENT

FINANCE & TECH

PEOPLE & MOBILITY

Products

Proprietary tools, platforms, and AI that power CX transformation.

RENÉ STUDIO

Design, score and fix customer journeys with AI.

Open rene.cx ↗
REBELDECK A · 36 FORCES

The forces that shape how humans experience the world.

Explore REBEL Reveal →
ALL PRODUCTS

Explore the full Renascence product ecosystem.

Browse products →

AI & TECHNOLOGY

LEARNING & GAMES

PLATFORMS & TOOLS

CX TOOLKIT

Opinion

Insights, research, and conversations at the frontier of CX.

RENÉ STUDIO

Turn what you read into a journey you can score.

Open rene.cx ↗
ReadExperience JournalArticles & research on CX, behavior, and transformation.Watch & listenExperience LoomOur video podcast on CX & behavior.CuratedCX NewsIndustry news that matters in CX, minus the noise.

Latest articles

Latest episodes

Latest news

Hub

Free tools, templates, and resources to advance your CX practice.

RENÉ STUDIO

Design, score and fix customer journeys with AI.

Open rene.cx ↗
THE MANIFESTOBurn the Deck.
Ten Virtues. Zero Excuses.Start reading →
THE HUB

Every free tool, template and resource in one place.

Visit the Hub →

AI TOOLS

FREE TOOLS

LEARNING

CULTURE

Banking · 9 October 2026

CrowdStrike Finds Bank Hacker's CV in Exposed AI Logs

CrowdStrike uncovered exposed AI tooling logs — including a likely CV — tied to a suspected Chinese-speaking attacker who used Claude Code and ARTEX to target South Korean banks.

Newsdesk
Curated briefing · 2 min read

What happened

Cybersecurity firm CrowdStrike says it has identified detailed logs — including what appears to be a CV belonging to a suspected Chinese-speaking threat actor — after exposed artificial intelligence tooling surfaced during an investigation into attacks on South Korean banks. According to reporting by The Register, the attacker is believed to have used Anthropic's Claude Code alongside an agentic penetration-testing tool called ARTEX to probe and attack financial institutions in South Korea.

The exposed logs reportedly gave CrowdStrike researchers an unusually granular view into how the attacker operated, including personal details that may help attribute the campaign. The firm's findings point to AI coding and agentic security tools being actively deployed in real-world intrusion attempts against banking targets, rather than purely in defensive or research contexts.

Why it matters

This case is a concrete illustration of how agentic AI tools — systems capable of planning and executing multi-step tasks with limited human oversight — are already being repurposed for offensive cyber operations. Tools built or marketed for legitimate penetration testing and software development, such as Claude Code, can lower the skill threshold for mounting technically sophisticated attacks on sensitive infrastructure like banking systems.

For technology and security leaders, the episode underscores that AI governance can no longer be treated as solely an internal adoption question. Organisations building or deploying agentic AI products need to consider how those same capabilities could be misused by third parties, and financial institutions in particular should assume that AI-assisted reconnaissance and intrusion attempts are a live operational risk rather than a theoretical one.

By the numbers

  • South Korea — the country whose banking sector was targeted in the attacks under investigation.
  • Two AI-related tools — Claude Code and the agentic pentesting tool ARTEX were both reportedly used by the suspected attacker.

The Renascence take

Coverage of this incident will likely focus on attribution and attacker tradecraft. The more durable lesson for experience and technology leaders is about exposure design — how AI tooling logs, credentials and operational traces are generated, stored and secured, because those same artefacts that exposed this attacker's identity are a liability whenever an organisation's own AI workflows are not built with forensic discipline from day one.

Every agentic AI deployment creates a new trail of logs, prompts and tool calls — and most teams are treating that trail as exhaust rather than as sensitive operational data. The behavioural fix is simple but under-practised: design AI tooling with the same log-hygiene and least-privilege discipline you'd apply to a production database, not as an afterthought bolted on once something goes wrong. Banks and other high-trust institutions should be auditing not just whether staff use AI tools, but how those tools' own logs could become an attack surface or, as in this case, an attacker's own undoing.

Sources

This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.

FAQ

Questions we get on this topic

CrowdStrike identified detailed logs, including what appears to be a CV belonging to a suspected Chinese-speaking threat actor, which surfaced from exposed AI tooling during an investigation into attacks on South Korean banks.

According to The Register, the attacker is believed to have used Anthropic's Claude Code alongside an agentic penetration-testing tool called ARTEX to probe and attack South Korean financial institutions.

The logs reportedly gave CrowdStrike researchers an unusually detailed view of the attacker's methods and included personal information that may help identify who was behind the campaign.

It shows agentic AI tools built for legitimate uses like coding and penetration testing can be repurposed for real intrusion attempts, meaning financial institutions should treat AI-assisted attacks as a live operational risk and apply strict log-hygiene and least-privilege practices to their own AI workflows.

Stay ahead of CX

Get the signal, not the noise.

The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.