Solo Hacker Used AI Agent to Breach South Korean Banks

In late September to early October 2026, a single attacker harnessed AI tools to breach multiple financial institutions in South Korea and exfiltrate both customer and employee data. Targeting savings banks, online lending firms, capital firms, and larger banks, the breach underscores how open-source AI augments solo cyber threat actors.

Targeted Services, Not Core Banking Systems

The attack avoided core banking infrastructure. Instead, it focused on peripheral services with weaker defenses, including APIs and broker tools. For example, at one bank a service used by brokers to check loan progress was compromised. At another major bank, the intruder accessed an internal system designed to support mobile work for employees. Affected institutions include Shinhan Bank, Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Hyundai Capital, Welcome Savings Bank, and two online lenders.

AI Stack and Infrastructure Exposed

Investigators from CrowdStrike uncovered that the actor used an open-source Chinese tool named ARTEX for the penetration, which was publicly released just weeks prior. ARTEX powered “autonomous testing” workflows found in exposed HTML content linked to the breach. Alongside ARTEX, several AI models were leveraged—including DeepSeek v4.1-flash, GLM-5.3 from Zhipu AI, and Grok 4.6—via Claude Code sessions.

The infrastructure supporting the intrusion consisted of at least a two-server framework. One server in Hong Kong served as the main control point, while another, identified by IP 38.244.50[.]120, housed the ARTEX instance. A Chinese-language prompt was found directing a large language model to carry out penetration—the artifacts let analysts peek into the attacker’s workflow, model choices, and steps.

Motivation, Risk, and Broader Implications

Signs point toward financial gain as the motive rather than political or state-sponsored espionage. The attacker was observed experimenting with how and where stolen data is traded, including in Telegram groups.

A key takeaway is how AI tools are lowering technical entry barriers for cybercriminals. The automation sped up tasks like reconnaissance, script generation, and detection of vulnerable systems. As tools like ARTEX spread, solo operators can strike far more organizations before being noticed.

What Organizations Can Do

Financial institutions need to expand their security scope beyond just core systems. Third-party portals, employee support tools, internal applications, and APIs require robust protection. Measures include enforcing strict authentication, limiting automated queries, segregating systems by role, monitoring abnormal access patterns, especially customer record lookups, and being quick to investigate traffic from infrastructure known to be malicious.

Indicators of compromise include the IP 38.244.50[.]120, which hosted ARTEX, and a set of proxy IPs used during suspicious activity. Also noted was the domain xcai[.]pro used as a probable API proxy or reseller for DeepSeek. Logs showed exposed Claude Code session records, configuration files, and model memory that laid bare the operation’s framework.

Why this matters: this incident shows how AI-powered tools are shifting the cyber-risk landscape. What once required large teams can now be handled by one actor with sufficient knowledge and open-source code. For financial organizations, vigilance over non-core but connected systems is no longer optional. As AI agents continue to evolve, defenders must anticipate attacks using models and workflows not yet widely understood. Expect increased detection of AI-assisted breach activity—and a need for policies centered on transparent AI use, infrastructure hygiene, and proactive system monitoring.