Published: October 9, 2026 · Last updated: October 9, 2026
TL;DR: CrowdStrike says it found a document that reads like the suspected South Korea bank hacker’s own resume, sitting inside exposed AI session logs from the attack, and the Chinese developer behind ARTEX, the open-source AI agent used to automate the break-in, has pulled the project from GitHub and made it closed-source for good.

CrowdStrike has turned up a strange, oddly personal clue in its ongoing investigation into who broke into South Korean banks this year: a document that reads like the suspect’s own resume, sitting inside AI session logs the hacker apparently forgot to scrub before moving on to the next target.
The firm’s researchers found the file while digging through logs tied to an AI agent called ARTEX, an open-source tool originally built for automated penetration testing. According to CrowdStrike’s write-up, first reported by The Register and picked up since by Reuters, The Hacker News and Security Affairs, the exposed logs did not just show attack commands. They showed a working session that looked a lot like someone multitasking, running reconnaissance against bank systems in one window while drafting an unrelated personal document in another, and leaving both behind on infrastructure that was never meant to be seen.
CrowdStrike had already linked the campaign to a financially motivated, Chinese-speaking individual it believes is around 26 years old, a detail we covered when the firm first tied the breaches to Anthropic’s Claude Code. That earlier reporting included the detail that the suspect allegedly asked Claude where to sell the stolen banking data once it was out the door, treating a mainstream AI assistant like a logistics consultant for the back half of the crime. The resume find adds a face, or at least a paper trail, to an attacker who otherwise existed only as a pattern of queries and exploit attempts.
The fallout has already hit ARTEX itself. Its developer pulled the project from GitHub this week and converted it to a closed-source tool, according to reporting from The Standard and OODAloop, effectively killing public access to the code once CrowdStrike’s findings tied it directly to a real-world bank intrusion. ARTEX was built to help security teams simulate attacks on their own systems, the same category of tool that red-teamers and penetration testers rely on legitimately every day. That is also exactly what makes it attractive to someone trying to automate a break-in against a target that is not theirs to test.
This is becoming a familiar shape for AI-era cybercrime stories. The attacker does not need to write custom malware from scratch anymore. They stitch together a commercial coding assistant for the technical heavy lifting, an open-source agent framework for repetitive reconnaissance, and whatever chat tool is handy for the parts of the job that used to require a human fence or a forum contact. Each piece looks mundane on its own. Put together, they ran a campaign that reportedly exposed data on tens of thousands of South Korean bank customers.
For banks and other financial institutions, the practical lesson is less about any single tool and more about logging discipline on the attacker’s side becoming a real source of evidence on the defender’s side. CrowdStrike did not catch this hacker because of a clever new detection algorithm. It caught him because AI tools leave session logs, and sloppy operational security around those logs can expose an attacker as thoroughly as it exposes the victims. Expect more threat intelligence teams to start treating AI session artifacts as a standard part of incident response rather than an afterthought.
There is also a harder question sitting underneath this for companies building widely available AI coding and agent tools. Claude Code was used here as a tool, not a co-conspirator, and Anthropic has no obvious way to have stopped a user from asking where to sell stolen data any more than a search engine can stop someone from asking the same question. But as more of these cases surface with named tools attached, the pressure on AI vendors to build stronger misuse-detection into widely available assistants is only going to grow, even when the tool itself was never the vulnerability.
Related: This builds directly on CrowdStrike’s original attribution of the breach to a hacker using Claude Code and ARTEX, and on the earlier disclosure that South Korea’s president confirmed AI tools helped an attacker breach Shinhan Bank, exposing data on roughly 25,000 customers.
Bottom Line: The most advanced part of this attack was never the AI. It was assuming the logs from the tools doing the work would stay invisible forever. They didn’t, and now the open-source project at the center of it all barely exists in public anymore.
Follow Teck Hustlers: Facebook · X · Instagram · LinkedIn · TikTok · Pinterest



