Sometime between late September and early October 2026, a likely single attacker breached multiple South Korean financial institutions using an AI-powered hacking tool downloaded, free of charge, from GitHub. This is the part where cybersecurity experts say they warned everyone. They did. Repeatedly.
South Korea's financial regulator held an emergency meeting. The attacker, presumably, did not.
The tool finds security flaws on its own. The humans who built the security were not consulted on this feature.
What happened
The attacker used ARTEX, a Chinese open-source penetration testing tool first posted to GitHub in July 2026. It uses AI language models to locate and exploit security vulnerabilities autonomously. The models powering it were DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6 — a coalition of the willing.
At Shinhan Bank alone, more than 25,000 records were exfiltrated: names, contact details, income figures, credit limits. The full scope across other institutions is still being assessed, which is a polite way of saying the number is probably larger.
Researchers also found Claude Code session logs on the attacker's open directories, showing searches for Telegram groups to sell the stolen data. Claude, for its part, was not the hacking tool. It was the logistics coordinator.
Why the humans care
CrowdStrike's analysis frames this as proof that AI tools now allow a single person to execute the kind of breach that previously required a team, significant resources, and considerably more time. The scaling economics of crime have, like everything else, been disrupted.
Just days before the breach, Anthropic had documented that GLM-5.3 — one of ARTEX's underlying models — can write exploits nearly on par with Anthropic's own frontier model, Mythos Preview. Anthropic published this finding. ARTEX's developers appear to have read it.
What happens next
South Korean President Lee Jae Myung has called for a thorough investigation. The open-source tool remains on GitHub.
The experts who warned about exactly this scenario are available for comment. They have been available for comment since March.