CrowdStrike Suspects A 26-Year-Old In China Hacked Korean Banks With Claude Code

CrowdStrike suspects a 26-year-old in China over South Korean bank hacks after finding personal details in Claude Code sessions (Image: Shutterstock)
CrowdStrike suspects a 26-year-old in China over South Korean bank hacks after finding personal details in Claude Code sessions (Image: Shutterstock)

CrowdStrike said a suspected attacker behind recent South Korean bank hacks may be a 26-year-old in China who used Anthropic's Claude Code and a Chinese penetration-testing tool.

Key Points:

  • CrowdStrike has not tied the campaign to a named group and rates its findings on the operator at moderate confidence.
  • A resume request in a Claude Code session listed an age of 26 and a location in Maoming, Guangdong.
  • At least nine South Korean banks have been targeted since late September, and the suspect's identity remains unconfirmed.

CrowdStrike Report Findings

The U.S. cybersecurity firm said in a report published Wednesday that it found personal details tied to the attacker while analyzing AI coding sessions and servers used in the campaign. The attacks ran from late September to early October.

Its analysts examined open directories on attacker-controlled servers that held Claude Code session histories, memory files and configuration files for ARTEX, an open-source penetration-testing agent developed in China. In one session, the user asked Claude to draft a security researcher resume. The prompt listed a Telegram account, an age of 26, an education entry for South China University of Technology and a location in Maoming, a city in Guangdong province.

CrowdStrike said the details likely belonged to the attacker but acknowledged they were difficult to link definitively. A man who answered a phone number listed in the report told reporters he had no knowledge of the matter.

Also Read: How Much Does Anthropic's CEO Make? IPO Filing Has The Answer

Claude Code, ARTEX Use

No named hacking group has been blamed. CrowdStrike described the operator as "likely a Chinese speaker and financially motivated," an assessment it rated at moderate confidence based on the Chinese-developed tool and Chinese-language prompts. ARTEX appeared on GitHub this year as a tool that connects to outside language models, and its page says it is meant for personal learning and should not be used against live systems.

The logs also hint at a profit motive.

The user asked Claude where stolen Korean data is typically sold and how to find Telegram groups that trade it. ARTEX ran mainly on DeepSeek v4.1-flash, while other Claude Code sessions drew on GLM-5.3 from Zhipu AI and Grok 4.6, and CrowdStrike expects attackers to keep adopting such tools to move faster.

South Korean Bank Breaches

At least nine South Korean banks have disclosed attacks or been named in local media reports since late September, prompting a police investigation this week and a call from President Lee Jae Myung for a robust response.

Shinhan Bank said personal information of about 25,000 customers was compromised through a loan broker inquiry service, while KB Kookmin Bank reported 119 customer records leaked from an employee work-support system. On Oct. 3, a Korea Financial Security Institute official confirmed that investigators traced Shinhan attack logs to ARTEX, adding that a hacker used the AI as a tool and it did not act alone.

Read Next: OpenAI's 722 AI Math Papers Are Public, Now Mathematicians Must Judge Them

Alexey Bondarev profile photo

Alexey Bondarev

Alexey Bondarev is Head of Content at Yellow.com. He specializes in in-depth Research and Learn pieces, with a focus on analytical reporting, industry context, and the bigger forces shaping crypto, from the AI era and security technologies to fintech innovation. He believes that everything digital will imminently overcome everything analogue and is working hard to make that come true.

Disclaimer and Risk Warning: The information provided in this article is for educational and informational purposes only and is based on the author's opinion. It does not constitute financial, investment, legal, or tax advice. Cryptocurrency assets are highly volatile and subject to high risk, including the risk of losing all or a substantial amount of your investment. Trading or holding crypto assets may not be suitable for all investors. The views expressed in this article are solely those of the author(s) and do not represent the official policy or position of Yellow, its founders, or its executives. Always conduct your own thorough research (D.Y.O.R.) and consult a licensed financial professional before making any investment decision.
Latest News
Show All News