NewsMacroAI-assisted attacks hit South Korean financial institutions, CrowdStrike investigation finds

AI-assisted attacks hit South Korean financial institutions, CrowdStrike investigation finds

Author: Cryptopolitan·

Key Takeaways

  • •CrowdStrike uncovered AI-assisted hacking traces after the attacker left exposed server directories containing Claude Code session records and configurations for ARTEX, an open-source penetration-testing tool developed in China.
  • •Seven South Korean financial institutions were breached, with Shinhan Bank reporting 25,727 compromised records, Yegaram Savings Bank notifying around 40,000 customers, and Hyundai Capital reporting 146 loan agents affected.
  • •Detection times varied widely among victims, with Shinhan identifying the intrusion within 15 hours, Hana requiring almost 42 hours, and KB Kookmin detecting the breach in 68 hours.
  • •South Korea's government cancelled plans to expand exemptions from network-separation rules, and regulators ordered security inspections of around 500 companies after attackers exploited external services with lower protection levels.
  • •The IMF's June report found AI-enabled adversary activity rose 89% between 2024 and 2025 while average breakout time fell to 29 minutes, narrowing the window banks have to detect and respond to attacks.
AI-assisted attacks hit South Korean financial institutions, CrowdStrike investigation finds

South Korean financial institutions targeted in recent cyberattacks demonstrate how hackers are using AI technology to commit crimes faster than ever. A CrowdStrike investigation published on October 7 uncovered traces of AI-assisted hacking, raising fears that the impacts could spread throughout the financial system rather than remaining limited to the banks under attack.

ARTEX and Claude Code left in the attackers' own files

The attackers made mistakes by leaving behind valuable clues. CrowdStrike researcher Ashley Campion discovered publicly exposed server directories containing Claude Code session records, memory files, and configurations related to ARTEX, an open-source penetration-testing tool developed in China. Claude Code is an AI coding agent that can carry out multi-step programming tasks on a user's behalf; its session files log the instructions a user issues and the outputs the tool produces.

Between late September and early October, the hacker used ARTEX alongside large language models to attack financial institutions.

CrowdStrike was unable to identify the group responsible for the attack or the number of victims. The firm said with moderate confidence that the hacker spoke Chinese and was by financial gain, and it found no indications of state involvement. The findings are detailed in CrowdStrike's official blog post.

Seven firms, tens of thousands of records

As previously reported by Cryptopolitan, seven banks were hacked, spanning commercial banks, savings banks, and a capital company. Shinhan Bank reported 25,727 compromised records, while KB Kookmin reported 119, Hana recorded 89, and BNK Busan reported data on 11 outsourced developers. Yegaram Savings Bank notified around 40,000 affected customers, Welcome Savings Bank reported breaches of 2,200 corporate records, and Hyundai Capital reported 146 loan agents affected.

Detection took considerable time. Reports indicate Shinhan identified the intrusion within 15 hours, Hana required almost 42 hours, and KB Kookmin detected the breach in 68 hours.

The South Korean government cancelled its plans to expand exemptions from its network-separation rules, which require financial firms to keep core internal systems isolated from internet-connected networks. At a meeting on October 4, Financial Services Commission (FSC) Chairman Lee Eog-weon advocated increased vigilance, and regulators ordered security inspections of around 500 companies. Reports from Korea pointed out that the attackers used external services with a lower protection level rather than the banking systems controlled by the banks themselves — a detail that places outside vendors at the center of the regulatory response.

Why faster attacks cost more

The IMF's June report found that AI-enabled adversary activity rose 89% between 2024 and 2025, and average breakout time — the interval between an initial compromise and an attacker moving deeper into a network — fell to 29 minutes. AI can help attackers find and exploit vulnerabilities faster, leaving banks less time to respond.

Bank for International Settlements (BIS) researchers Juan Carlos Crisanto, Adrien Currat, and Jeffery Yong warned in their September paper: "This window to detect, decide on and respond to such attacks has narrowed dramatically."

Meanwhile, PwC's 2027 survey found that 84% of security and finance leaders expect larger cybersecurity budgets, yet only 22% would allow AI to act fully autonomously in defense.

How one bank's breach can reach the rest

The Organisation for Economic Co-operation and Development (OECD) warns that cyberattacks can spread through shared technology providers and financial networks, and breaches have also been linked to deposit withdrawals, weaker lending, falling valuations, and higher borrowing costs. The BIS raises similar concerns about banks relying on the same cloud and AI providers.

Still, the Korean breaches have not caused demonstrated financial contagion or direct theft of bank funds. Regulators are now tasked with making security more stringent, overseeing third-party vendors more closely, and ensuring financial institutions can recover quickly before a cyberattack spreads. The results of the roughly 500 ordered inspections, and any decision on whether the shelved exemption expansion returns, are the next developments to watch.