Benzinga reported that information belonging to about 25,000 Shinhan Bank customers was compromised and data from 119 KB Kookmin Bank customers was leaked. The same report put the number of South Korean banks targeted at at least nine. The customer figures concern two named banks; the larger figure counts targets.

CrowdStrike described a campaign against South Korean financial institutions that involved data exfiltration. In an October 10 report, Bill Toulas of BleepingComputer detailed the reported tools and named Shinhan Bank, KB Kookmin Bank and Hana Bank. Benzinga, citing Reuters, reported the customer figures and the wider target count.

Two banks have reported customer figures

Benzinga reported that Shinhan Bank had information compromised for about 25,000 customers. For KB Kookmin Bank, it reported leaked data from 119 customers. The accounts describe different impacts, so the figures are best read alongside their respective banks and disclosures.

BankReported customer figureReported impact
Shinhan BankAbout 25,000Customer information compromised
KB Kookmin Bank119Customer data leaked

The wider target count is not the customer count

Benzinga reported at least nine South Korean banks as targets. BleepingComputer named three: Shinhan Bank, KB Kookmin Bank and Hana Bank. Those figures describe different scopes: one is a broader target count, while the other identifies banks named in BleepingComputer’s account. The customer-level figures above apply to Shinhan Bank and KB Kookmin Bank.

The reported campaign took place in late September and early October 2026, according to Benzinga. CrowdStrike attributed the activity to an unidentified actor; BleepingComputer described the actor as Chinese-speaking.

ARTEX and Claude Code had distinct reported roles

ARTEX is a penetration-testing suite, not a language model. BleepingComputer reported that the observed ARTEX instance used DeepSeek v4.1-flash as its primary backend. GLM-5.3, attributed to Zhipu AI, and Grok 4.6 were named in additional Claude Code sessions—not as ARTEX’s primary backend.

The distinction matters: the account describes an actor using several tools and models, not a single AI system carrying out every part of the activity. The reporting associates Claude Code session histories with the actor; it does not attribute the operation to Anthropic.

Exposed records included session histories and configuration files

Cloud Codes’ technical explainer uses diagrams of ARTEX’s agent loop and code snippets to walk through the reported tool architecture.

Bill Toulas reported that CrowdStrike researchers found exposed directories containing Claude Code session histories, ARTEX configuration files and Claude memory files. The records also included requests to Claude about Korean Telegram groups where stolen data might be sold.

BleepingComputer also reported that the South Korean government held an emergency meeting and called for immediate security measures for critical IT systems. The outlet reported that ARTEX’s developer closed the project’s source and discontinued updates; when BleepingComputer published its account on October 10, English- and Korean-language derivatives based on existing code were available. Reddit commenters discussing the project raised concerns about existing copies and who users would trust for future updates.