CrowdStrike signage in Sunnyvale, California. Credit: bluestork via Shutterstock The person behind a wave of cyberattacks on South Korean banks may be a 26-year-old living in China’s Guangdong province, US cybersecurity firm CrowdStrike says. The suspect has not been named or charged, and South Korean authorities have not identified anyone. CrowdStrike set out its findings in a report published on October 7, and Reuters reported the age-and-location link.
The company says it cannot firmly link these details to the attacker. According to the report, the attacks hit South Korean financial firms from late September to early October, and data was stolen. The attacker used ARTEX, a free Chinese AI tool that runs mock hacks to find security gaps. It also used Anthropic’s Claude Code and other AI models.
CrowdStrike found the attacker’s AI chat logs in open folders on servers the attacker ran. In one chat, the user asked Claude to write a CV with an age, a university, and a home in Guangdong. However, a date of birth given earlier did not match that age, the report notes. CrowdStrike said it has moderate confidence the attacker speaks Chinese and is likely driven by money.
It did not tie the attacks to any known hacking group. In other chats, the user asked Claude where Korean breach data is sold, the report said. Reuters called a phone number listed in the report, and the man who answered told Reuters he knew nothing about the matter. Anthropic, South Korean police, and China’s foreign ministry did not immediately respond to Reuters’ requests for comment.
Meanwhile, South Korean police opened a formal investigation on October 6, The Asia Business Daily reported. It covers seven financial firms, including Shinhan Bank, KB Kookmin Bank, and Hana Bank. Reuters counts at least nine banks targeted since late September. Shinhan said personal data of about 25,000 customers was exposed, while KB Kookmin put its figure at 119, according to Reuters.
Moreover, President Lee Jae Myung raised the AI angle at a cabinet meeting the same day. “In some hacking cases, details have emerged of the possible use of AI,” Lee said, according to Korea JoongAng Daily. The case follows Australia’s disclosure that an OpenAI agent broke into a government health statistics portal.













Leave a Reply