News

South Korea Bank Hacks: 26-Year-Old in China Suspected

A 26-year-old China-based individual may be behind cyberattacks targeting South Korean banks, with CrowdStrike linking the suspect to AI tools, Chinese-language prompts and attempts to access Korean data-selling groups.

Written By : Somatirtha
Reviewed By : Manisha Sharma

A 26-year-old individual based in China’s Guangdong province may be behind a series of cyberattacks targeting South Korea’s financial sector, according to US cybersecurity firm CrowdStrike.

The suspected attacker allegedly used the Chinese-developed AI agent ARTEX and Anthropic’s Claude Code to target South Korean financial institutions from late September to early October.

CrowdStrike Identifies Suspected Attacker

In a report published on Wednesday, CrowdStrike uncovered personal details linked to the suspected attacker while analyzing AI coding-tool sessions and infrastructure connected to the campaign.

The cybersecurity firm noted the activity has not been attributed to a named adversary but assessed with moderate confidence that the threat actor is likely a Chinese speaker and financially motivated. The assessment was based on the use of the Chinese-developed ARTEX tool and observed Chinese-language prompts.

CrowdStrike informed that the individual also asked Claude where threat actors typically sell Korean data breach information and sought help finding Korean Telegram data sales groups.

In another session, the person asked Claude to create a security researcher resume containing details including a Telegram account, age, educational background, and a location in Maoming, a city in Guangdong province. CrowdStrike said the information likely belonged to the attacker.

Also Read: ‘ASOS HACKED’: Shoppers Receive Threatening App Message Over Snowflake Data

AI Agent Used in Bank Attacks

ARTEX is an open-source AI agent for automated penetration testing. It was published on GitHub this year by a Chinese security engineer using the handle Autumn.

The tool is not a standalone large language model. It connects to external models such as ChatGPT, Claude, and DeepSeek to help organizations test network vulnerabilities. Its GitHub page says it is intended for personal learning, code research and local technical verification and should not be used for real-world testing against online systems or websites.

At least nine South Korean banks have disclosed, or have been reported by local media about being subjected to cyberattacks since late September. The attacks prompted South Korean police to launch a probe this week, while President Lee Jae Myung called for a robust response.

Shinhan Bank said about 25,000 customers' personal information was compromised, while KB Kookmin Bank said the personal information of 119 customers was leaked.

Anthropic, the South Korean police, and China’s foreign ministry did not immediately respond to requests for comment.

Join our WhatsApp Channel to get the latest news, exclusives and videos on WhatsApp

Crypto Prices Today: Bitcoin Slips to USD 82,900 as Treasury Yields, Liquidations Test Support

Banks that have Integrated Crypto Trading into Their Platforms

Crypto PACs Rethink Midterm Strategy After Clarity Act Collapse

The Technology Behind Institutional Crypto Settlement

Ethereum Supply: Is ETH Becoming Inflationary Again?