An open-source AI agent designed for penetration testing was removed from public access after cybersecurity researchers linked it to a series of cyberattacks targeting South Korean banks. Between late September and early October 2026, between seven and nine South Korean financial institutions were breached, exposing the personal data of approximately 68,000 individuals, including names, phone numbers, annual incomes, and loan limits. Shinhan Bank was the hardest hit with roughly 25,000 customer records compromised. The attacker, identified as a 26-year-old based in China and financially motivated, allegedly used ARTEX in conjunction with Anthropic’s Claude Code to carry out the operations. The Chinese developer of the tool, Li Puhua, closed access to the project on October 8, 2026, citing misuse of his creation.
Source: Read the original article

