On Oct. 8, a person linked to personal details in exposed records reportedly denied involvement in attacks on South Korean financial institutions, while China’s Foreign Ministry spokesperson Mao Ning said she did not know the case’s specific circumstances. The developments followed CrowdStrike’s Oct. 7 report on a campaign involving infrastructure associated with the attacks and records linked to Claude Code and ARTEX.

The denial and China’s response

CrowdStrike said it could not definitively link personal details found in the records to the operator. The person connected to those details reportedly denied involvement and said someone else had framed him. His identity and responsibility for the attacks remain unconfirmed.

At an Oct. 8 Foreign Ministry briefing, Mao Ning said she did not know the specific circumstances of the case. She reiterated China’s opposition to hacking and to spreading false information for political purposes.

What CrowdStrike reported about the campaign

CrowdStrike’s Oct. 7 report described infrastructure associated with a campaign targeting South Korean financial institutions and said the activity resulted in data exfiltration. The attacks were reported to have taken place from late September into early October 2026, with at least nine institutions targeted.

CrowdStrike assessed with moderate confidence that the operator was likely a Chinese speaker and financially motivated. The assessment did not name an adversary.

The reported roles of ARTEX and Claude Code

ARTEX is an open-source agent for automated penetration testing that connects to external language models. Claude Code is a coding assistant. Claude Code session histories and ARTEX configuration files were reportedly found in open directories associated with the operation.

Those records place both tools in the investigation’s picture, but the reported session histories do not identify specific intrusion steps carried out with Claude Code. ARTEX and a coding assistant are different tools, and the presence of their records does not by itself identify who operated them.

Reported disclosures at Shinhan Bank and KB Kookmin Bank

Among the institution-specific disclosures, Shinhan Bank reported personal-information exposure affecting about 25,000 customers. KB Kookmin Bank reported a leak affecting 119 customers.