Cybersecurity researchers have uncovered a series of attacks targeting South Korean financial institutions in which a suspected financially motivated threat actor allegedly used an AI-powered penetration-testing tool called ARTEX alongside large language models (LLMs) to breach systems and steal sensitive data.
According to a report published by The Hacker News on October 8, 2026, CrowdStrike Intelligence identified suspicious activity that occurred between late September and early October. The campaign affected several South Korean financial organizations, including Shinhan Bank and Yegaram Savings Bank. The full number of affected organizations remains unconfirmed.
How ARTEX Was Used in the Attacks
ARTEX is an AI-driven penetration-testing tool developed in China. It was designed to help security professionals identify vulnerabilities and test systems, but investigators found evidence that it had been repurposed for unauthorized cyber activity.
CrowdStrike reported that the suspected attacker combined ARTEX with multiple AI models to identify vulnerabilities and target services within financial organizations. The investigation also uncovered exposed directories containing AI coding-assistant session histories, configuration files and other information that helped researchers reconstruct the attacker's methods.
Customer Data and Financial Systems at Risk
The attacks reportedly involved systems used by financial brokers to check loan application progress and an employee mobile work-support system. Reports indicate that data belonging to customers and other individuals was exposed in the broader series of breaches.
Investigators believe the attacker may have intended to sell stolen information. CrowdStrike assessed with moderate confidence that the operator was Chinese-speaking and financially motivated, but the campaign has not been attributed to a confirmed individual or known threat group.
ARTEX Developer Responds to Misuse
Following reports linking ARTEX to the attacks, its developer announced that the project would become closed-source and would no longer receive public releases or maintenance support. The developer said the tool was originally intended for authorized security testing and research, not illegal activity.
The incident highlights a wider cybersecurity challenge: tools built to automate legitimate security testing can also be misused by attackers. AI agents can assist with vulnerability discovery, technical analysis and repetitive tasks, potentially allowing individuals to conduct multiple attacks more quickly.
What This Means for the Cybersecurity Industry
Financial institutions may need to strengthen monitoring of AI-assisted attack patterns, improve vulnerability management and secure systems that handle customer and employee information. Organizations should also review access controls, exposed services and incident-response procedures.
The case demonstrates that AI adoption creates both defensive opportunities and new risks. Businesses must ensure that security testing is authorized, systems are regularly assessed and sensitive data is protected against unauthorized access.
