Late in the night of 8 October, a Chinese program developer named “Autumn-27” issued a statement in GitHub to stop publicly updating ARTEX, to turn the original open-source AI penetration test agent into a closed source and to stop providing public maintenance support. A day ago, CrowdStrike, a United States cyber security company, published an investigation that stated that an assailant who might be located in Guangdong, China, used ARTEX and a commercial large-language model to continuously attack Korean banks and take personal data from some financial institutions.
The most pressing issue for Korean financial clients is not why a software suddenly stops, but why one can look for weaknesses in the periphery of multiple banks using automated tools; For developers, the products are used by the offender to bring open-source security tools into open debate.
原始来源 · crowdstrike.comCrowdStrike10月7日调查:ARTEX与攻击者会话记录crowdstrike.com ↗A publicly exposed catalogue of assailants to expose bank data

CrowdStrike technical report of 7 October states that researchers found an unprotected catalogue of the attacker-controlled server, which exposed Claude Code working session records, ARTEX configurations and other AI tool memory files. These records provide more specific evidence of conduct than guessing the IP territories: how the attackers command the model, how to change targets based on feedback, and which server is used to dispatch the task.
原始来源 · crowdstrike.comCrowdStrike10月7日原始技术报告与会话取证crowdstrike.com ↗CrowdStrike reported that ARTEX assumed the automated security scanning and testing process, and that the operators were using models such as DeepSeek, the think-form GLM and Grok as support tools for different work segments. They do not in themselves constitute fraudsters, nor can they be judged to be involved by “what model is used”. Those who actually perform unauthorized testing, obtain data and attempt to sell them are the perpetrators who use them.
The investigators estimate that the operation took place between the end of September and the beginning of October. The public cases in Korea involved New Korea, nationals, Hanya and some savings banks, with at least nine banks under attack or included in the survey, but the extent of data leaks confirmed by each agency varied. Nine banks cannot be stolen in the same amount of data.
原始来源 · reuters.com路透社:ARTEX开发者宣布闭源reuters.com ↗Bank outsourcing services and loan access points are targeted
The Financial Times disclosed that some of the bank clients ' information was not derived from the Core Funds Trading System, but was used outside applications such as loan progress queries, staff mobile work support, etc. The Bank of New Korea has been affected to varying degrees by about 25,000 customers, the Yegaram Savings Bank about 40,000 clients and the Welcome Savings Bank about 2,200 business clients. The main loss that has been disclosed is the leakage of personal or operational information, and there is no evidence in the report that the attack resulted in the direct theft of funds from the respective client accounts.
This information includes data on identity, loan amounts or income, which is sufficient to inform subsequent accurate fraud. In comparison with one-time theft of funds, obtaining customer information that can be used to impersonate bank customers, induce loans and launch SMS fishing for long periods of time, harm may be delayed.
原始来源 · ft.com金融时报:韩银行客户资料泄露规模ft.com ↗Developer turns off the open code, can you stop the assailant?
原始来源 · en.yna.co.kr韩联社:韩国多家银行遭AI攻击en.yna.co.kr ↗ARTEX developers indicated on 8 October that the project was intended to be used by enterprises to identify security loopholes and to oppose illegal use; In view of the abuse, no public versions and technical support will be published in the future. The Reuters search on 9 October found that the ARTEX GitHub project home page was offline.
原始来源 · reuters.com路透社10月9日:ARTEX开发者关停公开仓库、韩国警方调查reuters.com ↗Closing down projects reduces the access of new users to original versions and to public maintenance, but the code that has been copied does not automatically lapse as a result of the disappearance of the upstream web page. The technical survey also continues to track servers used by the actual operator, exposure information and leaked personal information. Writing the stop-off of the developers as “an attack has ended” is not in keeping with the reality of cybercrime.
CrowdStrike maintains a clear boundary on the attribution of the people behind the scenes: it is probable that the operator is a Chinese user and has a stronger financial incentive; Reuters, based on the investigation leads, stated that it could have involved a 26-year-old man in Guangdong. There is currently no public evidence to attribute the case directly to the national intelligence operation organized by the Chinese Government. The Ministry of Foreign Affairs of China stated that it was not aware of the specific case and expressed its opposition to cyberattacks.
Korea faces new bank protection
President Lee has requested an investigation into the leakage of financial system data, and the Financial Supervisory Authority has notified suspicious IPs and requested industry to strengthen monitoring. The government can trace the attackers, but the bank cannot itself push all the risks to “AI hackers”. The basic issue of customer protection is why the loan query system has too wide access to data, whether third-party services can circumvent the security controls of the core system, and when the customer receives notice of the leak.
The lesson of the attack for the financial industry is not that “prohibiting an open-source tool for a Chinese developer” will solve the risk, but that the automatic attack will magnify the original power gap as a cross-agency leak. The attackers were able to call multiple models and repeatedly test targets, while banks still had the possibility of placing customer identification and loan information in inadequately protected peripheral systems. Criminal responsibility is borne by the perpetrator of the attack; Public data hosting responsibilities cannot be removed from financial institutions.

Article discussion
Verified members can discuss this report publicly and manage their own content.
Checking member sign-in status…