CrowdStrike Links South Korean Bank Hacks to Possible China-Based Suspect Using AI Tools

Technology

CrowdStrike Links South Korean Bank Hacks to Possible China-Based Suspect Using AI Tools

A US cybersecurity firm has identified a possible 26-year-old suspect in China who may be behind a series of cyberattacks targeting South Korean financial institutions, saying the attacker used artificial intelligence tools to help carry out the intrusions.

CrowdStrike said the campaign was active from late September to early October and involved the use of ARTEX, a recently developed open-source AI-powered penetration-testing tool, together with large language models and Anthropic’s Claude Code.

The cybersecurity company stressed that the attacker has not been definitively identified, and the activity has not been attributed to any known hacking group. CrowdStrike assessed with moderate confidence that the person behind the campaign was a Chinese speaker and was likely financially motivated.

The findings add to growing concern among governments and cybersecurity specialists that increasingly capable AI agents could make sophisticated cyberattacks faster and easier to conduct.

Possible Clues Point to Guangdong

CrowdStrike said its investigators found personal information in files and AI coding-tool sessions associated with infrastructure used during the attacks.

In one Claude Code session, the suspected attacker asked the AI system to help create a résumé describing experience as a security researcher. The information reportedly included an age of 26, education details and a location in Maoming, Guangdong province.

Investigators also found a Telegram username associated with the activity.

CrowdStrike said the same username had appeared in other cyber-related activity, including vulnerability research involving a Telegram-based non-fungible token marketplace and a separate suspected attack against a Chinese payment platform.

However, the company cautioned that the personal information could not conclusively establish the identity of the person responsible for the South Korean attacks.

AI Tools Used During the Attacks

One of the most significant aspects of the investigation is the apparent use of several AI systems as part of the attacker’s workflow.

CrowdStrike said the attacker used ARTEX, a Chinese-developed open-source agentic penetration-testing tool designed to identify and test security weaknesses.

The ARTEX instance linked to the campaign primarily used DeepSeek v4.1-flash as its large-language-model backend. The attacker also used other AI models, including GLM-5.3 from Zhipu AI and Grok 4.6, during separate Claude Code sessions.

CrowdStrike said the activity demonstrates how AI-powered tools can be combined with more traditional offensive techniques to automate and accelerate cyber operations.

ARTEX itself is designed as a penetration-testing tool, meaning it can have legitimate cybersecurity uses. Its presence in an attack does not mean the software was created for criminal activity.

The concern comes from how such tools can potentially be repurposed by malicious actors.

South Korean Banks Among the Targets

The suspected campaign comes amid a wave of data breaches affecting South Korean financial institutions.

Companies and banks that have reported incidents include Shinhan Bank, KB Kookmin Bank and Hana Bank, while other financial firms have also reported breaches or data exposure involving contractors and third-party systems.

CrowdStrike said the compromised systems included a loan inquiry service used by financial brokers at one bank and an employee mobile work-support system at another.

South Korean authorities have launched investigations into the incidents, with police and financial regulators examining whether several of the attacks were connected.

The attacks appear to have focused in some cases on systems operated by third parties rather than directly compromising banks’ core payment networks.

That distinction is significant because financial institutions increasingly rely on outside contractors, cloud services and digital platforms to process customer information.

Tens of Thousands of Customers Affected

The recent incidents have exposed personal information belonging to customers of several financial institutions.

Among the cases reported so far, about 25,000 Shinhan Bank customers were affected after an attacker reportedly bypassed identity checks on a portal used by loan brokers.

Around 40,000 customers of Yegaram Savings Bank and approximately 2,200 corporate customers of Welcome Savings Bank also had information exposed.

Other incidents involved KB Kookmin Bank, Hana Bank, BNK Busan Bank and Hyundai Capital.

Despite the scale of the breaches, authorities have not reported that customers’ funds were stolen as a direct result of the attacks.

The full extent of the data taken across all affected institutions remains under investigation.

Evidence Suggests Possible Financial Motive

CrowdStrike said investigators found evidence suggesting the suspected attacker may have been interested in monetising stolen information.

In conversations with Claude, the person reportedly asked about places where stolen South Korean data could be sold and sought information about Korean-language Telegram groups involved in trading such information.

That activity contributed to CrowdStrike’s assessment that the attacker was likely financially motivated.

The company has nevertheless stopped short of naming the individual or assigning the attacks to a particular criminal organisation.

Multiple Servers and IP Addresses Complicated the Investigation

CrowdStrike identified infrastructure that appeared to have been used to conduct the campaign.

One Hong Kong-based server was described as the attacker’s primary infrastructure, while another server hosted the ARTEX installation believed to have been used against South Korean financial organisations.

Investigators also found evidence of additional connection routes that could have helped obscure the attacker’s location.

The use of infrastructure in different jurisdictions makes attribution particularly difficult because the physical location of a server does not necessarily indicate where an attacker is operating from.

CrowdStrike therefore described the evidence pointing toward a Chinese-speaking individual as an assessment rather than a confirmed identification.

President Lee Calls for Stronger Cybersecurity

The developments come just days after South Korean President Lee Jae Myung warned that AI appeared to have been used in some recent bank attacks.

At a Cabinet meeting on Oct. 6, Lee said the apparent use of AI had caused significant concern and called for stronger measures to protect financial institutions.

South Korean financial authorities have also urged banks and other financial companies to strengthen their ability to defend against AI-assisted attacks.

An emergency government response team has been operating around the clock, while authorities have asked cloud providers to block suspicious activity associated with overseas IP addresses.

The latest findings from CrowdStrike now provide additional technical evidence supporting concerns that AI-assisted tools were involved in at least some of the attacks.

A New Challenge for Cybersecurity

The South Korean incidents illustrate a growing challenge for cybersecurity teams: attackers no longer necessarily need to build every tool or manually conduct every stage of an intrusion themselves.

AI systems can potentially assist with vulnerability discovery, coding, reconnaissance and other technical tasks, allowing individuals with fewer resources to carry out more complex operations.

CrowdStrike said the South Korean campaign demonstrated the continuing evolution of adversarial use of agentic AI.

Similar concerns have emerged internationally as security researchers and governments investigate cases in which AI agents have allegedly been used to automate cyber operations.

At the same time, cybersecurity experts caution that the presence of AI in an attack does not necessarily mean the technology independently carried out the entire operation. Human attackers can combine AI assistance with conventional hacking techniques, stolen credentials and existing malicious infrastructure.

Suspect’s Identity Remains Unconfirmed

For now, South Korean investigators have not publicly confirmed that the person identified by CrowdStrike is responsible for the attacks.

CrowdStrike itself has warned that the available information is insufficient to definitively identify the attacker. South Korean police are continuing their investigation, while authorities work to determine the full scope of the breaches and whether multiple incidents were connected.

What is clearer is that the attacks have highlighted a rapidly evolving cybersecurity threat.

With AI-powered tools becoming increasingly accessible, South Korea’s financial sector is now confronting a new type of risk — one in which automated technology can potentially help attackers find weaknesses and pursue sensitive information at a speed and scale that traditional defences may struggle to match.

Get our stories first on Google

More in Asia

See all in Asia