CrowdStrike says China-based suspect used AI tools in South Korean bank hacks
CRWD•CrowdStrike said a suspect likely based in China used an AI agent and Claude Code in cyberattacks targeting at least nine South Korean banks since late September. Shinhan Bank said about 25,000 customers’ personal information was compromised, while KB Kookmin Bank said 119 customers’ information was leaked.
1. AI tools in attacks
CrowdStrike said it found personal details linked to a suspected attacker while analysing AI coding-tool sessions and infrastructure connected to attacks on South Korean financial institutions from late September to early October. The suspect may be a 26-year-old in China’s Guangdong province and used ARTEX, a Chinese-developed open-source penetration-testing tool, alongside AI models such as Claude.
2. Suspect’s possible details
CrowdStrike said the person asked Claude where threat actors sell Korean data breaches and for help finding Korean Telegram data sales groups. In another session, the person requested a security researcher resume containing a Telegram account, age, education and a location in Maoming, which CrowdStrike said likely belonged to the attacker. The firm assessed with moderate confidence that the actor was likely a Chinese speaker and financially motivated.
3. Banks disclose breaches
At least nine South Korean banks have disclosed or been reported by local media as targets since late September. South Korean police launched a probe this week, and President Lee Jae Myung called for robust response measures.




