CrowdStrike says AI-assisted hacker hit Korean banks, then exposed identity clues through Claude logs

CrowdStrike says AI-assisted hacker hit Korean banks, then exposed identity clues through Claude logs

N
News Editor
2026-10-09 02:03:38
CrowdStrike said a wave of cyberattacks targeting South Korean financial institutions since late September 2026 involved ARTEX, an open-source AI penetration tool developed in China, paired with large language models including DeepSeek v4.1-flash and Anthropic’s Claude Code. The attacks affected multiple banking systems, including a loan progress inquiry service and an employee mobile work support platform. Shinhan Bank said about 25,000 customers had personal data accessed illegally, while Kookmin Bank reported leaks involving 119 customers. The case drew wider attention because the attacker appears to have exposed their own operational trail. According to CrowdStrike, an open directory on infrastructure controlled by the threat actor contained full Claude Code session logs, configuration files, and memory files. Those records allegedly included prompts asking where South Korean personal data could be sold, requests to search Telegram groups trading Korean data, and an instruction for Claude to draft a cybersecurity researcher résumé that listed the ARTEX-based attack on Korean banks as work experience. The leaked résumé prompt contained identity clues including the alias Y.Y, an age listed as 26, an initially provided birth date of 2007-09-22, South China University of Technology, Maoming in Guangdong province, a phone number, and a Telegram handle. South Korean authorities have opened a formal investigation, while CrowdStrike said it assesses with medium confidence that the actor was a Chinese-language user motivated by financial gain.

CrowdStrike said a large-scale cyber campaign that began in late September 2026 and targeted South Korean financial institutions used ARTEX, an open-source AI agent tool developed in China, together with large language models including DeepSeek v4.1-flash and Anthropic’s Claude Code. During the investigation, the security firm said it also found that the attacker had exposed conversations with Claude through a misconfigured public directory, revealing personal details that could point to the operator’s identity.

Campaign began in late September and hit multiple Korean banks

In a report released on Oct. 7, 2026, CrowdStrike said the attacks on South Korea’s financial sector started in late September. Statements from affected banks showed that Shinhan Bank confirmed illegal access to personal data belonging to about 25,000 customers, while Kookmin Bank said 119 customers had personal information exposed.

The targets included a loan progress inquiry system and an employee mobile work support platform. South Korea’s banking sector had already faced a string of intrusions, and the government had previously said traces of a Chinese-language AI hacking tool had been found.

ARTEX was used with several AI models

According to CrowdStrike, the attacker primarily relied on ARTEX, described as an agent-based AI penetration testing tool developed in China. Its setup used DeepSeek v4.1-flash as the main backend and also called Zhipu AI’s GLM-5.3, xAI’s Grok 4.6, and Anthropic’s Claude Code.

CrowdStrike said that combination increased the speed and efficiency of automated vulnerability discovery and attack execution, adding another layer to the role generative AI now plays in both offense and defense.

Open directory exposed Claude session records

For all the sophistication in the attack chain, the operator appears to have made a basic infrastructure mistake. CrowdStrike said it found full Claude Code session logs, configuration files, and memory files in an open directory on a server controlled by the attacker, allowing researchers to reconstruct the workflow in detail.

The records showed prompts asking Claude where South Korean personal data could be sold and requests to search Telegram groups involved in trading Korean data.

Attacker asked Claude to write a cybersecurity résumé

One exchange stood out. The attacker asked Claude to help draft a personal résumé for a cybersecurity researcher and told the model to include the results of the ARTEX-based attack on Korean banks as part of that work history.

That prompt exposed a set of personal details, including:

  • Alias: Y.Y
  • Age and birth date: listed as 26 years old, with an initially provided birth date of 2007-09-22
  • Education: South China University of Technology
  • Location: Maoming, Guangdong, China
  • Contact details: phone number 17820191556 and Telegram account @YY520CN

In effect, the same AI tooling used to support the intrusion also became a source of identifying clues.

Identity remains unverified as South Korea opens a task force probe

South Korean media reported that a journalist called the phone number listed in the report. A man in Henan who identified himself as a convenience store clerk denied any connection to the case. It remains unclear whether the résumé used the attacker’s real information, someone else’s identity, or fabricated details.

South Korean President Lee Jae-myung raised the case during a State Council meeting, saying AI-enabled cybercrime had caused significant public unease. Police in South Korea have since formed a dedicated task force to investigate.

CrowdStrike points to a Chinese-language user with financial motives

CrowdStrike said it could not determine the attacker’s ultimate attribution with complete certainty. Even so, the firm assessed with medium confidence that the operator was a Chinese-language user motivated by financial gain.

The company also warned that AI agent tools are lowering the barrier to advanced attacks and that threat actors are likely to use AI more often to accelerate operations, putting pressure on companies and financial institutions to strengthen cyber defenses.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.