U.S. cybersecurity firm CrowdStrike reports that an unidentified hacker, believed to be a Chinese speaker, is likely behind cyberattacks targeting multiple South Korean financial institutions. The firm says the attacker used AI-enabled hacking tools to breach systems and steal data, with activity occurring between late September and early October.

CrowdStrike’s report cites ARTEX, a Chinese-developed open-source penetration-testing tool, and the use of large language models (LLMs) during the intrusion process. The outlets describe compromised services including parts of a bank loan inquiry system used by financial brokers and an internal mobile work-support system used by employees. The reporting adds that financial authorities and investigators are looking into the incidents, which have followed broader breach activity at banks.

While the sources agree on the technical indicators—ARTEX and LLM-assisted tactics—they differ mainly on the level of specificity about the suspect. One outlet notes CrowdStrike’s suggestion that the suspected attacker may be 26 years old and located in China, while other coverage focuses more broadly on the alleged connection to Chinese-speaking and financially motivated behavior.