Invest2 publishersAlso reported elsewhere2 min readPublished
One operator used a free pentest agent and Claude Code to breach as many as nine Korean banks
ARTEX's developer made the open-source agent closed-source on October 8 after CrowdStrike linked it to a China-based 26-year-old who breached South Korean banks. The campaign exposed roughly 68,000 customer records, Cryptobriefing reported.
The Investor · Invest desk

What happened
- Shinhan Bank was the worst hit, with around 25,000 customer records compromised.
- The exposed personal data included names, phone numbers, annual incomes and loan limits.
- ARTEX is not a standalone model but connects to external LLMs such as ChatGPT, Claude and DeepSeek to run its probing.
- Attack traffic was routed through IP addresses spanning more than ten countries to obscure its origin.
- ARTEX's GitHub page was taken down the same day the project went closed-source.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- cost The leaked data, including annual incomes and loan limits, enables highly targeted financial fraud, and the people whose records were taken carry that risk.
- constraint The developer's step is prospective: no further versions and no maintenance support. It does nothing about the open-source versions already published this year.
- exposure Claude Code sat in the attack chain, so whether model providers should keep their assistants out of such chains is now Anthropic's question to answer; the company has not commented.
- capability A single operator with a downloadable tool and a commercial AI assistant breached multiple banks, which lowers the resources needed to attack a financial institution to within one person's reach.
The tool cost nothing: ARTEX was released on GitHub this year as an open-source agent to automate penetration testing [17]. CrowdStrike said the operator was a single 26-year-old based in China who ran it alongside Anthropic's Claude Code, an account carried by both Cryptobriefing and Mint [9][10][21]. The campaign took roughly two weeks [3].
The breaches reached internal banking systems, not the customer-facing portals that carry the heaviest defenses, because internal systems often assume that anyone already inside belongs there [11].
The two reports do not line up on scale. Cryptobriefing put the number of firms at between seven and nine [3]; Mint, citing disclosures and local media, said at least nine banks have been named as targets since late September, and police opened a probe this week [19]. Shinhan alone accounts for about 37 percent of the 68,000 records exposed [23].
The developer, who uses the GitHub handle Autumn-27 and is named by Cryptobriefing as the Chinese cybersecurity engineer Li Puhua [8], announced the change on the code-hosting platform on Thursday. "Given the misuse of the tool, the ARTEX project will no longer be updated and will be converted to closed source. No further versions will be released to the public nor will maintenance support be provided," the developer said [16]. He said he opposed any illegal use of the software and bore no responsibility for conduct that breaks the law [22], and that ARTEX was built for authorized security testing [7].
President Lee Jae Myung called for stronger cybersecurity measures after the incidents [13]. China's foreign ministry spokesperson Mao Ning said on Thursday that the ministry was not familiar with the case and that China consistently opposes and combats hacking [20].
What to watch
- Whether Anthropic comments on the ARTEX chain or changes Claude Code's safeguards against being wired into attacks.
- What Korean police conclude, given routing through more than ten countries complicates cross-border attribution.
- Whether forks or copies of the already-public ARTEX code resurface despite the switch to closed-source.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [2]
ARTEX's GitHub page was taken down the same day the project went closed-source.
ReportedView cited source - [3]
The attacks struck between late September and early October 2026, roughly a two-week span, and breached internal systems at between seven and nine South Korean financial firms.
ReportedView cited source - [4]
Approximately 68,000 individuals had personal data exposed in the attacks.
ReportedView cited source - [5]
The exposed personal data included names, phone numbers, annual incomes and loan limits.
ReportedView cited source - [6]
Shinhan Bank bore the worst of the breach, with around 25,000 customer records compromised.
ReportedView cited source - [7]
ARTEX was built as an autonomous AI agent for authorized security testing.
ReportedView cited source - [8]
The developer uses the GitHub handle Autumn-27 and is named by Cryptobriefing as the Chinese cybersecurity engineer Li Puhua.
ReportedView cited source - [9]
CrowdStrike tied the operations to a financially motivated individual in China, estimated to be a 26-year-old based in the country.
ReportedView cited source - [10]
According to CrowdStrike, the attacker used ARTEX in conjunction with Anthropic's Claude Code.
ReportedView cited source - [11]
The combination was effective against internal banking systems rather than public-facing applications; internal systems often rely on the assumption that anyone with access already belongs there.
ReportedView cited source - [12]
To cover tracks, traffic generated during the attacks was routed through a network of IP addresses spanning more than ten countries.
ReportedView cited source - [13]
President Lee Jae Myung publicly addressed the incidents and called for enhanced cybersecurity measures.
ReportedView cited source - [14]
Annual income figures and loan limits are the kind of information that enables highly targeted financial fraud.
ReportedView cited source - [16]
The developer, using the GitHub handle Autumn-27, said on the code-hosting platform on Thursday: "Given the misuse of the tool, the ARTEX project will no longer be updated and will be converted to closed source. No further versions will be released to the public nor will maintenance support be provided."
ReportedView cited source - [17]
Released on GitHub this year, ARTEX is an open-source AI agent designed to automate penetration testing.
ReportedView cited source - [18]
ARTEX is not a standalone large language model but connects to external LLMs such as ChatGPT, Claude and DeepSeek to help organisations test for vulnerabilities.
ReportedView cited source - [19]
At least nine South Korean banks have disclosed or been reported by local media as targets of cyberattacks since late September, prompting police to launch a probe this week.
ReportedView cited source - [20]
Chinese foreign ministry spokesperson Mao Ning said on Thursday that the ministry was not familiar with the case and that China consistently opposes and combats hacking activities.
ReportedView cited source - [21]
CrowdStrike said on Wednesday the suspect behind the South Korean bank attacks was likely a China-based 26-year-old who used the ARTEX AI agent and Anthropic's Claude Code.
ReportedView cited source - [22]
The developer said they opposed any illegal use of the software and bore no responsibility for conduct that violates laws and regulations.
ReportedView cited source - [23]
Shinhan's roughly 25,000 records are about 37 percent of the roughly 68,000 records exposed.
Derived
Sources
2 independent publishers whose own reporting we read for this story.
- cryptobriefing.comARTEX AI agent goes closed-source after being linked to South Korean bank hacks
1 article · October 9, 2026
- economictimes.indiatimes.comARTEX AI agent: Chinese developer makes ARTEX AI agent closed-source after Korean bank hack - The Economic Times
1 article · October 8, 2026
- livemint.comChinese developer makes ARTEX AI agent closed-source after Korean bank hack | Mint
1 article · October 8, 2026