AI Agents Used in Real-World Cyberattacks
AI agents are moving beyond experiments and into real cyberattacks, with a reported campaign targeting South Korean financial organizations using agentic AI tools and Claude Code.

AI Agents Are Now Being Used in Real-World Cyberattacks
Artificial intelligence agents are becoming more capable of performing tasks with less human intervention. A new cybersecurity incident involving South Korean financial organizations shows why this development is becoming an important security issue.
According to Reuters, CrowdStrike said a suspected China-based attacker used a Chinese-developed AI agent together with Anthropic’s Claude Code during cyberattacks targeting at least nine South Korean banks. The activity reportedly took place from late September into early October 2026.
The important point is not simply that an AI model was present during a cyberattack. The bigger development is the use of agentic AI as part of an attack workflow. AI agents can be given objectives, use software tools, analyze information and perform multiple steps with considerably less manual intervention than traditional chatbot interactions.
CrowdStrike reported that its investigation found Claude Code session histories, configuration files and other evidence connected to an AI-driven campaign against South Korean financial organizations. The company said the attacker used ARTEX, an open-source agentic penetration-testing tool developed in China, alongside large language models.
This does not mean that Claude independently hacked the banks. The reported activity involved a human-controlled attacker using multiple AI tools and traditional offensive techniques. That distinction is important because it shows how AI can become a force multiplier for an attacker rather than acting as an entirely autonomous hacker.
CrowdStrike said the activity included attempts to compromise financial systems and exfiltrate data. Its analysis also found evidence that the attacker used AI-assisted workflows to research vulnerabilities and support different stages of the operation. The company assessed that adversaries are likely to continue experimenting with AI tools to increase the speed and scale of their operations.
Why is this different from older AI-assisted hacking stories?
Previously, discussions about AI and cybercrime often focused on what attackers might eventually be able to do. This incident provides a reported example of agentic AI tooling appearing inside a real-world cyber campaign. Instead of using AI only to generate a piece of code or answer a question, attackers can potentially connect AI systems to tools, infrastructure and workflows.
That creates a new security challenge for banks and businesses. An AI agent with excessive permissions could potentially access sensitive information, execute commands or interact with business systems much faster than a human operator. Security teams therefore need to think not only about protecting people and computers, but also about controlling what AI agents are allowed to access and do.
This issue is especially relevant as businesses increasingly deploy AI agents for coding, customer service, research, automation and internal operations. The same capabilities that make agents useful for legitimate businesses can also create additional opportunities for attackers when those systems are poorly protected.
For students and AI creators, the lesson is simple: AI agents are becoming more powerful, but capability also creates responsibility. Understanding permissions, authentication, data protection and safe AI usage will become increasingly important as agentic AI spreads.
The future of AI security may therefore depend on a simple question: not just “What can an AI agent do?” but “What is the AI agent allowed to do?”
This South Korean banking incident is an early warning that cybersecurity and agentic AI are becoming closely connected. Businesses adopting AI agents will need strong access controls, continuous monitoring and clear limits on autonomous actions to reduce the risk of misuse.