South Korean financial institutions hit by suspected AI-assisted attacks as investigators trace clues in Claude Code logs

South Korean financial institutions hit by suspected AI-assisted attacks as investigators trace clues in Claude Code logs

N
News Editor
2026-10-08 10:26:15
At least seven financial institutions in South Korea were hit by data breaches from late September to early October, with Shinhan Bank, KB Kookmin Bank and Hana Bank among the affected names. Publicly disclosed figures show about 25,000 Shinhan Bank customers and roughly 40,000 customers at Yegaram Savings Bank were impacted. Exposed data included names, phone numbers, annual income and loan limits, though no stolen funds have been identified so far. South Korean regulators suspect the incidents may be tied to a single attacker because several of the intrusions shared overlapping IP addresses. On Oct. 6, President Lee Jae-myung said the attacks may have involved AI. A day later, CrowdStrike released more detailed findings, saying investigators found evidence tied to two servers, one in Hong Kong used to control the operation and another running the open-source AI penetration testing system ARTEX. According to CrowdStrike, exposed server directories allowed investigators to obtain ARTEX configuration files, Claude Code chat logs and AI memory files. The configuration showed the attacker mainly used DeepSeek v4.1-flash with ARTEX, while other sessions also referenced Claude Code, GLM-5.3 and Grok 4.6. Chat records also contained apparent personal details, but CrowdStrike said the attacker’s real identity remains unconfirmed.

At least seven financial institutions in South Korea suffered data breaches from late September to early October, including Shinhan Bank, KB Kookmin Bank and Hana Bank. Among the disclosed cases, about 25,000 customers at Shinhan Bank and roughly 40,000 customers at Yegaram Savings Bank were affected. The leaked information included names, phone numbers, annual income and loan limits. No theft of funds has been identified so far.

Attacks targeted peripheral banking systems

The intrusions mainly hit peripheral business systems used by banks, including loan inquiry services for loan brokers and mobile work systems used by employees. Because several of the attacks involved overlapping IP addresses, South Korean regulators suspect the incidents were carried out by the same attacker.

Lee Jae-myung and CrowdStrike pointed to AI use

On Oct. 6, South Korean President Lee Jae-myung said the attacks may have used AI. On Oct. 7, cybersecurity company CrowdStrike published more detailed evidence.

Investigators said the attacker used two servers. One was located in Hong Kong and was used to control the operation. The other ran ARTEX, an open-source AI penetration testing system. Because some server directories were left exposed, investigators were able to obtain ARTEX configuration files, Claude Code chat logs and AI memory files.

Configuration files showed use of several large models

According to the findings, ARTEX can connect to different large language models, automatically look for vulnerabilities, plan testing steps and call security tools. The configuration files showed the attacker mainly used DeepSeek v4.1-flash to run ARTEX. In addition, the attacker used Claude Code and, in other sessions, called GLM-5.3 and Grok 4.6.

Chat logs exposed other activity and apparent identity clues

The Claude Code chat logs also revealed other activity. The attacker asked where leaked data from South Korea is usually sold and how to find related Telegram trading groups. The attacker also asked AI to draft a resume for a security researcher and requested that it include penetration testing results achieved with ARTEX.

In the prompts used for that resume, the attacker left details including an age of 26, Maoming in Guangdong, South China University of Technology, a phone number and a Telegram account. The listed date of birth did not match the stated age. CrowdStrike said the attacker may use Chinese and may be financially motivated, but the person’s real identity has not been confirmed.

Telegram account holder denied involvement

On Oct. 8, South Korea’s Kyunghyang Shinmun contacted the user of the Telegram account mentioned above. The person said he worked at a convenience store in Henan and claimed someone had deliberately used his information to frame him. Reporters, however, found that the same account also appeared on administrator lists for two Telegram communities linked to DDoS attacks.

That claim has not been verified, and South Korean police are still investigating.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.