The Lab Notes

Anthropic

CrowdStrike says hacker used Claude Code on South Korean banks

CrowdStrike Intelligence found Claude Code session logs on servers tied to a campaign against South Korean financial firms.

A laptop with lines of code on its screen, cut out against a solid bright color.

An attacker used Anthropic’s Claude Code, alongside Chinese and rival models, in a run of intrusions at South Korean financial firms, according to a CrowdStrike Intelligence report. Session logs left on exposed servers let investigators see how the work was done.

CrowdStrike published the report Oct. 7, 2026, under the title “Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance.” It said the campaign ran from late September to early October and resulted in exfiltrated data.

Exposed directories held the session histories

CrowdStrike said open directories controlled by the threat actor held Claude Code session histories, ARTEX configuration files and Claude memory files. One server also held an exposed Claude Code instruction file with a Chinese-language penetration-testing prompt.

ARTEX is an open-source agentic penetration-testing tool developed in China. Reuters, via CNA, reported Oct. 8 that a Chinese security engineer who goes by “Autumn” published it on GitHub this year. Reuters said it connects to outside models such as ChatGPT, Claude and DeepSeek, and that its GitHub page says it should not be used against real online systems.

The attacker ran several models

CrowdStrike said the ARTEX instance used DeepSeek v4.1-flash as its primary backend. The actor added GLM-5.3, from Zhipu AI, and Grok 4.6 for additional Claude Code sessions. In the sessions, the actor asked Claude where threat actors typically sell Korean data-breach information.

CrowdStrike assessed with moderate confidence that the actor is likely a Chinese speaker and financially motivated. It has not attributed the activity to a named adversary. The activity “demonstrates how AI tooling can enable a financially motivated threat actor to conduct multiple intrusions within a short time span,” CrowdStrike said.

Banks have reported leaks of customer data

At least nine South Korean banks have disclosed, or been reported by local media as, targets since late September, Reuters said. Police opened a probe this week. President Lee Jae Myung called for strong response measures.

Shinhan Bank said about 25,000 customers’ personal information was compromised, Reuters reported. KB Kookmin Bank said 119 customers’ data leaked. CrowdStrike said the number of affected organizations remains unconfirmed.

The Register reported Oct. 8 that lawmakers approved summoning the heads of five major commercial banks to an Oct. 19 parliamentary audit over cybersecurity lapses. Anthropic, South Korean police and China’s foreign ministry did not immediately respond to Reuters’ requests for comment.

What it means for the labs

We think the case raises the question of how labs police agent products used through a general-purpose tool. By CrowdStrike’s account, the attacker ran a lab’s commercial coding agent next to DeepSeek, Zhipu AI and xAI models. The session logs sat on exposed servers. That is what let investigators see the work.

Reuters said the case is likely to intensify concerns over AI agents and whether organizations can defend against them.