CrowdStrike Holdings Inc. (NASDAQ:CRWD) said a suspected 26-year-old based in China’s Guangdong province may be linked to a cyber campaign targeting South Korean financial institutions that used AI tools to compromise customer data.
CrowdStrike Points to Possible Chinese-Speaking Hacker
In a report published Wednesday, CrowdStrike said it identified personal details potentially connected to the individual while analyzing sessions from AI coding tools and infrastructure tied to cyberattacks against South Korean financial institutions from late September through early October.
The cybersecurity firm said it has not attributed the activity to a named threat actor but assessed with "moderate confidence" that the suspect is Chinese-speaking and financially motivated.
At least nine South Korean banks have reportedly been targeted. Shinhan Bank said information belonging to about 25,000 customers was compromised, while KB Kookmin Bank reported that data from 119 customers was leaked, Reuters reported.
Hacker Used AI Tools Including ARTEX And Claude
CrowdStrike said the attacker used ARTEX alongside multiple AI models, with the observed ARTEX instance using DeepSeek V4.1-Flash as its primary backend. The attacker also used Anthropic’s Claude Code, as well as GLM-5.3 and Grok 4.6 in separate sessions.
Anthropic did not immediately respond to Benzinga’s request for comment.
The attacker reportedly used Claude to ask where stolen Korean data could be sold and sought Korean Telegram groups involved in data transactions.
In another session, the individual asked the AI to create a security researcher résumé containing a Telegram account, age, education and a location in Maoming, Guangdong.
CrowdStrike said the information "likely" belonged to the attacker.
ARTEX is not itself a large language model. Instead, it can connect with external AI models, including Claude, OpenAI’s ChatGPT and China’s DeepSeek, to assist with cybersecurity testing.
Its GitHub page says the tool is intended for learning, code research and local testing, rather than attacks against live websites.
AI Agents Raise New Cybersecurity Concerns
The incident adds to growing concerns about AI-assisted cybercrime and whether organizations are prepared to defend against increasingly autonomous attacks.
Australia said last month that an OpenAI autonomous agent breached a government health statistics portal in June.
Price Action: On Wednesday, CrowdStrike closed at $265.44, down 4.81%. In Thursday’s premarket, the price stood at $264.55, down 0.34%, according to Benzinga Pro.
According to Benzinga Edge Stock Rankings, CrowdStrike ranks in the 98th percentile for Momentum, with its short-, medium- and long-term price trends remaining positive.

Disclaimer: This content was partially produced with the help of AI tools and was reviewed and published by Benzinga editors.
Photo courtesy: Shutterstock
Login to comment