A suspected cyberattacker may have used artificial intelligence to launch a broad campaign against South Korean financial institutions, raising fresh concerns about how quickly a single individual can exploit AI to target multiple organisations.

At least nine South Korean banks have disclosed or have been reported by local media as targets of cyberattacks since late September. The incidents have prompted South Korean police to open an investigation and President Lee Jae Myung to call for stronger measures to protect the country's financial and digital infrastructure.

US cybersecurity firm CrowdStrike said the suspected attacker was likely a 26-year-old based in China's Guangdong province. The company said investigators uncovered personal information associated with the individual while examining sessions involving AI coding tools and digital infrastructure connected to the hacking campaign.

Adam Meyers, CrowdStrike's senior vice president of counter adversary operations, said the case demonstrated how artificial intelligence could amplify the capabilities of a human attacker.

"And this is significant because it allows one human to target many customers in a very short period of time using the power of AI," Meyers told reporters on a Thursday call.

CrowdStrike said the individual used ARTEX, a recently released Chinese-developed open-source penetration-testing tool, together with large language models including Anthropic's Claude.

The company said its assessment was that the attacker was probably Chinese-speaking and financially motivated, although it stopped short of attributing the campaign to a known hacking group.

"While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated," CrowdStrike said in its report.

"This assessment is made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts."

The suspected attacker also appeared to use Claude to seek information about underground markets for stolen Korean data. According to CrowdStrike, the person asked where threat actors typically sell information obtained in Korean data breaches and sought help locating Korean Telegram groups involved in the sale of stolen information.

In another AI session examined by CrowdStrike, the individual reportedly asked Claude to prepare a security researcher résumé. The document contained details including a Telegram account, age, educational background and a location in Maoming, a city in Guangdong province.

CrowdStrike said the information appeared likely to belong to the suspected attacker, although the company did not publicly identify the individual.

A man who answered a telephone number included in CrowdStrike's report said he had no knowledge of the matter.

The allegations come as South Korean authorities confront a series of attacks affecting the country's banking sector. Shinhan Bank said last week that personal information belonging to about 25,000 customers had been compromised, while KB Kookmin Bank said information relating to 119 customers had been leaked.

The incidents have added to growing concern over the use of autonomous and semi-autonomous AI systems in cyber operations. Unlike conventional software tools, AI agents can perform multiple tasks, interpret information and generate code or other actions with considerably less direct human intervention.

Australia reported last month that an autonomous OpenAI agent had breached a government health statistics portal in June, in what was described as one of the first known cases of an AI agent hacking a government system.

The emergence of such incidents is also creating challenges for the cyber-insurance industry. Insurers are examining whether autonomous AI systems fit existing definitions of a cyber attacker and how responsibility should be assigned when AI-generated actions result in financial or other losses.

A Chinese-speaking actor

CrowdStrike said the suspected South Korean bank attacker relied on ARTEX, an open-source AI agent designed to automate penetration testing. The tool was published on GitHub this year by a Chinese security engineer using the online handle Autumn.

ARTEX is not itself a large language model. Instead, it connects to external AI systems, including ChatGPT, Claude and DeepSeek, to assist with security testing and vulnerability research.

Its GitHub page says the software was created for personal learning, code research and local technical verification. It also warns that the tool should not be used for real-world testing against online systems or websites.

CrowdStrike's findings do not establish that the developer of ARTEX was involved in the South Korean attacks. Open-source cybersecurity tools can be used for legitimate defensive research as well as malicious activity.

Chinese Foreign Ministry spokesperson Mao Ning said she was not familiar with the specific case when asked about the allegations at a regular press briefing.

China, she said, has consistently opposed and fought hacking activities as a matter of principle.

Anthropic and South Korean police did not respond to requests for comment.

For cybersecurity specialists, the investigation illustrates a potentially important shift: sophisticated attacks may no longer require large teams of highly skilled hackers working manually. With AI agents handling parts of reconnaissance, coding and research, a single operator could potentially pursue multiple targets at a scale that would previously have required substantially more time and manpower.

The South Korean incidents are therefore being closely watched not only because of the data reportedly exposed, but also because they offer another indication of how artificial intelligence could reshape the economics and speed of cybercrime.