Find notable cyber news and cases, enriched with sources, timelines, and signals.

South Korea-based financial firms data exfiltration, late September to early October 2026

Data Leak
First reported
Last updated
Happening score
H score 35
1 unique sources, 1 articles

Summary

Hide ▲

Sensitive data was exfiltrated from multiple South Korea-based financial firms during a late September to early October 2026 intrusion campaign, confirming a leak from a regulated sector. The activity involved ARTEX and Claude AI as part of the offensive workflow. The exposure raises immediate risk of downstream fraud, phishing, and resale of stolen information.

Related Happenings

China-based ARTEX AI-enabled campaign against South Korean financial organizations

Campaign
H score39 First: 08.10.2026 14:00 Last: 08.10.2026 14:00 Sources 1

How related: A suspected China-based threat actor leveraged AI tooling in a campaign that successfully exfiltrated data from South Korean financial organizations, CrowdStrike has revealed.

About this happening: CrowdStrike said a suspected China-based threat actor used ARTEX and Anthropic’s Claude AI in a targeted campaign against South Korean financial organization...

Shinhan Bank hit by cyberattack

Incident
H score41 First: 05.10.2026 17:22 Last: 05.10.2026 17:22 Sources 1

How related: This included Shinhan Bank and Yegaram Savings Bank, who reported breaches affecting 25,000 and 40,000 people, according to Singapore-based newspaper The Straits Times.

About this happening: A suspected China-based threat actor used ARTEX and Anthropic’s Claude AI in a campaign that ran from late September to early October 2026 and exfiltrated data fro...

Timeline

  1. 08.10.2026 03:00 2 articles · 21h ago

    Data exfiltration hits Shinhan Bank and Yegaram Savings Bank

    Victim Impact Update

    Sensitive data was exfiltrated from South Korea-based financial firms, including Shinhan Bank and Yegaram Savings Bank. CrowdStrike said the campaign also involved breaches of a loan progress inquiry service used by financial brokers and an employee mobile work–support system, while the total number of affected organizations remained unconfirmed.

    Show sources
  2. 07.10.2026 03:00 1 articles · 1d ago

    CrowdStrike links a China-based threat actor to ARTEX and Claude AI use

    Technical Analysis Update

    CrowdStrike said a suspected China-based threat actor used ARTEX and Anthropic’s Claude AI during a campaign, linked the intrusions to a single IP address, and found attacker infrastructure containing a Chinese-language pentesting prompt, Claude Code session histories, ARTEX configuration files, and Claude memory files. The same workflow used DeepSeek v4.1-flash as the primary LLM backend and added GLM-5.3 and Grok 4.6 for additional Claude Code sessions.

    Show sources
  3. 06.10.2026 03:00 1 articles · 2d ago

    South Korea’s Financial Services Commission warns customers about hacked financial companies

    Initial Disclosure

    South Korea’s Financial Services Commission issued a consumer alert over attacks on hacked companies and warned customers to stay vigilant for potential phishing attacks and loan scams.

    Show sources