A Security Firm Says It Found the Attackers' Own AI Chat Logs on an Open Server

Security company CrowdStrike Intelligence reported on Oct. 7, 2026, that it had traced the servers behind a run of intrusions at South Korean financial organizations in which data was taken, and that the operator had left its own working files on one of those servers, in folders anyone could browse.
CrowdStrike's published account of the intrusions says those files gave it direct insight into how the operator worked. They included session logs from Claude Code, an AI coding agent, setup files for ARTEX, a freely available tool that automates security testing, and the agent's stored memory. The campaign was active from late September to early October 2026, and how many organizations were affected remains unconfirmed.
CrowdStrike says the activity has not been attributed to a named adversary. With moderate confidence, it assesses that the actor is likely a Chinese speaker and financially motivated, and it gives two reasons: the use of ARTEX, which the report describes as developed in China, and Chinese-language prompts it found in the files. The assessment is the vendor's own.
According to the report, the ARTEX instance used DeepSeek v4.1-flash as its main model backend, and the operator added GLM-5.3, from Zhipu AI, and Grok 4.6 for further agent sessions. The operator also asked the AI agent where stolen Korean data is usually sold, and for help finding Telegram groups that trade it.
As for what was breached, the report cites industry reporting rather than its own observation: several South Korean financial firms had data breaches over that period, and at two of them the systems involved were a loan progress inquiry service used by brokers and an employee mobile work-support system.
CrowdStrike Intelligence says it expects attackers to keep trying AI tools to work faster. The report lists the network indicators the company tied to the activity and maps them to ATT&CK, MITRE's public catalog of attacker techniques, so defenders can search their own records.
