Benzinga reported that information belonging to about 25,000 Shinhan Bank customers was compromised and data from 119 KB Kookmin Bank customers was leaked. The same report put the number of South Korean banks targeted at at least nine. The customer figures concern two named banks; the larger figure counts targets.
CrowdStrike described a campaign against South Korean financial institutions that involved data exfiltration. In an October 10 report, Bill Toulas of BleepingComputer detailed the reported tools and named Shinhan Bank, KB Kookmin Bank and Hana Bank. Benzinga, citing Reuters, reported the customer figures and the wider target count.
Two banks have reported customer figures
Benzinga reported that Shinhan Bank had information compromised for about 25,000 customers. For KB Kookmin Bank, it reported leaked data from 119 customers. The accounts describe different impacts, so the figures are best read alongside their respective banks and disclosures.
| Bank | Reported customer figure | Reported impact |
| Shinhan Bank | About 25,000 | Customer information compromised |
| KB Kookmin Bank | 119 | Customer data leaked |
The wider target count is not the customer count
Benzinga reported at least nine South Korean banks as targets. BleepingComputer named three: Shinhan Bank, KB Kookmin Bank and Hana Bank. Those figures describe different scopes: one is a broader target count, while the other identifies banks named in BleepingComputer’s account. The customer-level figures above apply to Shinhan Bank and KB Kookmin Bank.
The reported campaign took place in late September and early October 2026, according to Benzinga. CrowdStrike attributed the activity to an unidentified actor; BleepingComputer described the actor as Chinese-speaking.
ARTEX and Claude Code had distinct reported roles
ARTEX is a penetration-testing suite, not a language model. BleepingComputer reported that the observed ARTEX instance used DeepSeek v4.1-flash as its primary backend. GLM-5.3, attributed to Zhipu AI, and Grok 4.6 were named in additional Claude Code sessions—not as ARTEX’s primary backend.
The distinction matters: the account describes an actor using several tools and models, not a single AI system carrying out every part of the activity. The reporting associates Claude Code session histories with the actor; it does not attribute the operation to Anthropic.
Exposed records included session histories and configuration files
Bill Toulas reported that CrowdStrike researchers found exposed directories containing Claude Code session histories, ARTEX configuration files and Claude memory files. The records also included requests to Claude about Korean Telegram groups where stolen data might be sold.
BleepingComputer also reported that the South Korean government held an emergency meeting and called for immediate security measures for critical IT systems. The outlet reported that ARTEX’s developer closed the project’s source and discontinued updates; when BleepingComputer published its account on October 10, English- and Korean-language derivatives based on existing code were available. Reddit commenters discussing the project raised concerns about existing copies and who users would trust for future updates.