Skip to content
All systems operational0 AI providers monitored, polled every 2 minutes
Live status
Back to Originals
Security · Agents · Finance

CrowdStrike Linked Korea's Bank Breaches to Exposed Claude Code Logs. The Attack Agent's Main Model Was DeepSeek.

Marcus Chen··7 min read

On Thursday, October 1, 2026, Shinhan Bank disclosed that an unauthorized outsider had pulled the names, phone numbers, annual incomes and borrowing limits of about 25,000 customers. Within a week, KB Kookmin, Hana, BNK Busan and Yegaram Savings Bank had reported breaches too, and South Korea's president was saying some of the incidents showed signs of AI.

Then the attacker's own notes turned up. On Wednesday, October 7, CrowdStrike published a report on the campaign built on open directories the attacker never locked down. They held Claude Code session histories, Claude memory files and the configuration for ARTEX, which CrowdStrike calls "a recently released open-source agentic penetration testing (pentesting) tool developed in China."

Several headlines since have led with Claude. The logs tell a more mixed story, and it matters for anyone deciding where AI security controls should live.

What the Open Directories Showed

CrowdStrike describes a two-server setup. A Hong Kong-based address served as the attacker's main infrastructure. A second server, at 38.244.50[.]120, hosted the ARTEX instance that CrowdStrike says was likely responsible for the Korean attacks, plus a CLAUDE.md file holding a Chinese-language prompt telling the model how to run a pentest.

The model doing the attacking was mostly not Claude. In CrowdStrike's words, "The ARTEX instance used DeepSeek v4.1-flash as the primary LLM backend," reached through what it calls a likely LLM API proxy or reseller, xcai[.]pro. The attacker "supplemented this LLM with GLM-5.3 (Zhipu AI) and Grok 4.6 for additional Claude Code sessions." In other words, Claude Code was at least partly a harness wrapped around other companies' models. DeepSeek's own API documentation publishes an Anthropic-format endpoint and points developers to a Claude Code integration guide, so the swap is documented by the model maker itself.

Claude itself does appear. Beyond the ARTEX work, CrowdStrike says the attacker "asked Claude where threat actors typically sell Korean data breach information and asked Claude for assistance in finding Korean Telegram data sales groups." The report does not say whether Claude answered. In another session, the attacker asked Claude to write a security researcher résumé with bullet points describing the results of the ARTEX work.

That résumé prompt is how a suspect emerged: age 26, South China University of Technology, Maoming in Guangdong province, though the same prompt first gave a 2007 birth date. CrowdStrike says the details likely belong to the attacker but that "currently available information cannot definitively associate these details with the threat actor." Per Korea JoongAng Daily, the man reportedly denied involvement and said his identity had been stolen. CrowdStrike's assessment, with moderate confidence, is narrower: a Chinese speaker, financially motivated, not tied to a named group.

ComponentWhat CrowdStrike foundWhose control applies
Attack agentARTEX, open-source pentesting agent developed in ChinaIts developer, who has since made it closed-source
ARTEX's primary modelDeepSeek v4.1-flash, likely via reseller xcai[.]proDeepSeek and the reseller
Other Claude Code sessionsGLM-5.3 (Zhipu AI) and Grok 4.6The model providers, not the harness
ClaudeAsked where to sell Korean breach data and for a résumé of the ARTEX resultsAnthropic
InfrastructureHong Kong server, ARTEX server, nine listed proxy addressesKorean police, who have identified 28 linked IP addresses

The Damage, Bank by Bank

The counts are still moving. The Korea Times says at least five lenders were hit. Reuters, as cited by Korea JoongAng Daily, says at least nine Korean financial institutions have experienced or been targeted by attacks since late September. CrowdStrike itself says the number of affected organizations "remains unconfirmed."

LenderPeople affectedReported entry point
Shinhan BankAbout 25,000 customersLoan lookup service for outside loan recruiters
KB Kookmin Bank119 (American Banker: 99 customers plus 20 current and former employees)Employee mobile work-support system
Hana Bank89 customersSales-support system (American Banker)
BNK Busan BankData on 11 outsourced developers (American Banker)Web pages with insufficient session validation (American Banker)
Yegaram Savings BankNot disclosedNot disclosed

Two things stand out. First, the 119 and the 99 appear to reconcile: 99 customers plus 20 staff is 119. Second, the entry points are not exotic. American Banker reports the main Shinhan intrusion began on September 28 and ran for about 30 hours against a site built for loan recruiters, who are outside agents rather than bank staff, and that the attacker got past a mobile-phone verification step. The same report says regulators have confirmed no customer has lost money and that no passwords or one-time codes were taken.

Seoul Blames the Plumbing, Too

Korea's Financial Services Commission has been blunt about where the failure sits. American Banker reports it ordered firms to inspect every internet-facing system, then told them to stop storing or exposing personal credit data to employees, loan recruiters and contractors who do not need it, calling that setup the cause of the intrusions, with fixes due by October 8.

At a parliamentary audit on Thursday, October 8, FSC Chairman Lee Eog-won told lawmakers, per The Korea Times: "Even in some very basic areas, our response has been inadequate." He also said: "To prevent attacks using AI, we ultimately have no choice but to use AI in defending them." The government is considering easing network separation rules so banks can use AI and outside security services to find holes faster.

A National Assembly committee has approved summoning the heads of KB Kookmin, Shinhan, Hana, Woori and NH NongHyup as witnesses at the Financial Supervisory Service audit on Monday, October 19, according to The Korea Times and The Register.

The tool itself is gone from public view. On Thursday, October 8, ARTEX's developer, who goes by Autumn-27 on GitHub, said the project would become closed-source with no further public releases or maintenance, citing misuse, without directly addressing the Korean attacks. Reuters reports the GitHub page has been taken down. Code that has already been cloned does not disappear with it.

The Same Week, Anthropic Signed CrowdStrike for Defense

One day after the report, on October 8, Anthropic launched the Anthropic Cyber Mission, whose Critical Infrastructure Defense Program names 11 founding partners, CrowdStrike among them, alongside a free OSS Scanner for open-source projects that Anthropic says it expects to have "a true-positive rate above 90%." The Mission's launch post does not mention Korea, and we found no public Anthropic statement on the bank incidents as of Sunday.

And on Saturday, October 10, Microsoft CEO Satya Nadella posted on X that "We must assume a model is compromised and contain it from the start," as quoted by TechCrunch, arguing for separating the model from the harness and moving safeguards outside the model. The ARTEX logs are a working example of the problem from the other side: the harness, the model and the reseller each sat with a different party, and the attacker owned the one piece that tied them together.

Our Take

The headline version, Claude agents hacked Korean banks, is about a third right. By CrowdStrike's account the agent that did the attacking was ARTEX, its main model was DeepSeek bought through a reseller, and Claude Code also ran sessions on GLM-5.3 and Grok 4.6. Claude's role in the report is the fence-shopping questions and a résumé. That is not nothing, and Anthropic owes a public answer on whether Claude helped and whether those accounts were cut off.

But the bigger lesson is that model-level refusals are the wrong place to hang your defense. An open-source agent pointed at a cheap, compatible endpoint never touches the safeguards of the lab whose harness it borrowed. If you run a bank, the controls you own are the ones on your side of the wire: who can query a loan lookup service, whether a session token is actually checked, and whether a recruiter needs to see an applicant's income at all.

That is why we think the FSC chairman's line is the most honest thing anyone has said about this. The failures were basic. AI changed the tempo, which is exactly what CrowdStrike's assessment says: AI tooling let one financially motivated actor "conduct multiple intrusions within a short time span." It did not invent a new class of hole. Expect more of this pattern: commodity agents, rented models, old bugs, faster.

The other lesson is cheaper. We know this much only because the attacker left their agent logs in public directories. The next one will not be so generous, and banks should plan for that.

Three signposts for the next 60 days:

  • What the bank CEOs commit to at the October 19 audit, and whether any figure for new security spending is put on the record.
  • Whether Anthropic, DeepSeek or Zhipu publish anything on the accounts CrowdStrike describes, including whether Claude answered the questions about selling the data.
  • Whether Korea actually eases its network separation rules for AI defense tools, and whether ARTEX forks show up in another country's incident reports.

Sources: CrowdStrike, American Banker, The Korea Times, Korea JoongAng Daily, The Register, Reuters via Investing.com, Bloomberg via Insurance Journal, BleepingComputer, Anthropic, DeepSeek API docs and TechCrunch.