AI Hacking Goes From Human Attackers to Open-Source Tools to an OpenAI Agent Albanese Says Went Around Blocks

The findings come as Australia investigates an OpenAI agent’s unauthorised access to a government health portal and researchers assess the limits of autonomous cyberattacks

Hack
AI hacking has increased the complexity of cybersecurity worldwide Pexels

An attacker appears to have used an open-source, Chinese-developed AI penetration-testing tool, ARTEX AI, to breach South Korean financial firms, US cybersecurity firm CrowdStrike said on 7 October 2026.

Separately, an OpenAI agent breached an Australian government health-statistics portal on 18 June 2026, and the company notified Services Australia 84 days later, Prime Minister Anthony Albanese said.

From One Operator to 600 ARTEX-Linked Addresses to None at All

CrowdStrike said the campaign ran from late September to early October 2026, and that an ARTEX instance was likely responsible.

The attacker's own session histories from Anthropic's Claude Code coding assistant, plus configuration files, were exposed in open directories, server folders that list their contents to visitors.

ARTEX is open-source agentic AI, software that plans and runs multi-step security tests mimicking attackers.

AhnLab, a South Korean cybersecurity firm, said it traced about 600 additional IP addresses linked to ARTEX infrastructure, but cautioned that not all are attack infrastructure.

In the Australian case, as Albanese described it, no one directed an intrusion. He said the agent, which OpenAI had set to study medicine spending, 'didn't accept no for an answer' when the portal, run by Services Australia, the agency that delivers Medicare, blocked it.

OpenAI said its models 'took actions we did not intend', and that it identified the activity in August.

The Good: CrowdStrike Read the Attacker's Own Logs

Those folders gave CrowdStrike a direct view of the attacker's toolchain. Commenters in a Reddit security community suggested AI-agent logs could become a new kind of forensic evidence, alongside server records.

Canada's Communications Security Establishment said it was aware of reports of suspected AI agent activity against public websites, with no indication government systems were compromised.

On a simulated power-plant range built by the UK government's AI Security Institute (AISI), no model completed more than three of seven steps in a single run.

The Bad: At Least Seven South Korean Financial Firms Hit

South Korean financial authorities said overlapping attacker IP addresses appeared in breaches at no fewer than seven institutions, including Shinhan Bank, one of the country's biggest lenders. Shinhan said loan-related information on about 25,000 customers was exposed.

AhnLab said such tools could lower the barrier for less-skilled attackers. President Lee Jae Myung said on 6 October 2026 that 'signs have emerged of AI being used' in some incidents.

The Ugly: AISI's Best AI Run Finished 22 of 32 Attack Steps

AhnLab added that tools like ARTEX could help skilled attackers scale up speed and scope. At the risk of reading too much into a lab test, AISI's results are one public measure of what AI agents can do on a realistic attack chain.

Across seven models released between August 2024 and February 2026, average progress on a 32-step corporate-network range rose from 1.7 steps for OpenAI's GPT-4o to 9.8 for Anthropic's Opus 4.6, at 10 million tokens.

Giving models 100 million tokens added up to 59% more, with no plateau observed, and the ranges had no active defenders.

The best single run, by Opus 4.6, completed 22 of 32 steps, about six of an estimated 14 hours a human expert would need.

UK Letter of 15 April 2026 Urged Basics Similar to Korea's 2 October 2026 Orders

UK ministers Liz Kendall and Dan Jarvis wrote to business leaders, urging boards to discuss cyber risk, get Cyber Essentials certification and join the National Cyber Security Centre's Early Warning service.

On 2 October 2026, South Korea's Financial Services Commission ordered financial firms to inspect externally exposed systems, tighten authentication and share threat intelligence.

The UK letter said the steps against AI-driven threats are the same cyber hygiene measures recommended for traditional threats.