US cybersecurity firm CrowdStrike says an unidentified hacker believed to be a Chinese speaker used AI-powered tools to breach several South Korean financial institutions between late September and early October, stealing data. The attacker paired ARTEX, a Chinese-developed open-source penetration-testing tool, with large language models to compromise a bank’s loan inquiry service and another lender’s employee mobile-support platform.
CrowdStrike linked two servers to the operation, one of them in Hong Kong, and said the intruder appeared financially motivated, searching for marketplaces selling stolen South Korean data. Hana Bank, KB Kookmin Bank and Shinhan Bank were among the names previously reported in connection with the breaches. Neither the full identity of the attacker nor the extent of the stolen data has been confirmed.