Find notable cyber news and cases, enriched with sources, timelines, and signals.

China-based ARTEX AI-enabled campaign against South Korean financial organizations

Campaign
First reported
Last updated
Happening score
H score 39
2 unique sources, 2 articles

Summary

Hide ▲

CrowdStrike said a suspected China-based threat actor used ARTEX and Anthropic’s Claude AI in a targeted campaign against South Korean financial organizations from late September to early October 2026. The activity led to data exfiltration, and the actor used ARTEX to discover vulnerabilities and compromise specific services. CrowdStrike also linked the operator to efforts to find Korean Telegram data sales groups, while assessing the attacker as a Chinese speaker with financial motivation. South Korea’s Financial Services Commission warned customers of the hacked companies about possible phishing attacks and loan scams.

Related Happenings

South Korea-based financial firms data exfiltration, late September to early October 2026

Data Leak
H score35 First: 08.10.2026 14:00 Last: 08.10.2026 14:00 Sources 1

How related: The campaign reportedly resulted in data being exfiltrated from a number of South Korea-based financial firms.

About this happening: Sensitive data was exfiltrated from multiple South Korea-based financial firms during a late September to early October 2026 intrusion campaign, confirming a leak from a r...

Shinhan Bank hit by cyberattack

Incident
H score41 First: 05.10.2026 17:22 Last: 05.10.2026 17:22 Sources 1

How related: This included Shinhan Bank and Yegaram Savings Bank, who reported breaches affecting 25,000 and 40,000 people, according to Singapore-based newspaper The Straits Times.

About this happening: A suspected China-based threat actor used ARTEX and Anthropic’s Claude AI in a campaign that ran from late September to early October 2026 and exfiltrated data fro...

Anthropic Claude misuse analysis of multi-agent reconnaissance, exploitation, and exfiltration

Technical Analysis
H score59 First: 11.09.2026 17:29 Last: 11.09.2026 17:29 Sources 1

About this happening: Anthropic says Claude AI was abused by multiple threat groups, including ShinyHunters, Midnight Blizzard, and GTG-10007, for credential harvesting, recon...

Midnight Blizzard Claude-assisted cyberespionage campaign

Campaign
H score19 First: 11.09.2026 11:47 Last: 11.09.2026 11:47 Sources 1

About this happening: Midnight Blizzard ran a Claude-assisted cyberespionage campaign that automated malware evasion and kept the operation active across more than 20 organizations. The act...

CISA, NSA, and FBI joint advisory on AI model distillation

Public Sector Action
H score25 First: 08.09.2026 15:00 Last: 08.09.2026 15:00 Sources 1

About this happening: CISA, NSA, and FBI released a joint cybersecurity advisory warning U.S. AI companies about knowledge distillation campaigns targeting frontier models. The advi...

Timeline

  1. 08.10.2026 14:00 3 articles · 10h ago

    CrowdStrike details AI-enabled intrusions against South Korean financial organizations

    Initial Disclosure

    CrowdStrike said a suspected China-based threat actor used ARTEX alongside Anthropic’s Claude AI in a campaign that ran from late September to early October 2026 and exfiltrated data from South Korean financial organizations. The actor used ARTEX to discover vulnerabilities and compromise specific services, asked Claude for help finding Korean Telegram data sales groups, and CrowdStrike assessed with moderate confidence that the attacker was a Chinese speaker and financially motivated. Reporting tied the activity to breaches at Shinhan Bank and Yegaram Savings Bank affecting 25,000 and 40,000 people.

    Show sources
  2. 06.10.2026 03:00 1 articles · 2d ago

    South Korea warns customers of hacked companies about phishing and loan scams

    Legal Policy Action Update

    South Korea’s Financial Services Commission issued a consumer alert on October 6 warning customers of the hacked companies to stay vigilant for potential phishing attacks and loan scams after the attacks.

    Show sources