Multiple financial institutions in South Korea have recently been targeted by cyber attacks. According to a report released by the US cybersecurity company CrowdStrike on Wednesday, researchers found clues from the operation records of hackers using artificial intelligence (AI) tools that are suspected to be related to a 26-year-old individual from Guangdong, China. However, it is currently not confirmed whether this data belongs to the attackers.
Since the end of September, there have been several data breaches in the South Korean financial industry. South Korean news agency Yonhap reported that at least 7 financial institutions have experienced security breaches by Monday, including Shinhan Bank, KB Kookmin Bank, Hana Bank, among others. The Korea Times estimated that personal information of over 67,000 individuals has been leaked.
South Korean President Jae-myung Lee stated on Tuesday that some of the attacks showed signs of using AI, and has called for enhanced cybersecurity measures.
According to the investigation report released by CrowdStrike on Wednesday, the related attack activities occurred from the end of September 2026 until early October. Researchers analyzed servers controlled by the attackers and obtained Claude Code session history, ARTEX configuration files, and Claude memory files, where they found clues that resembled those of a suspected hacker.
One Claude Code session revealed that the user had requested Claude’s help in drafting a resume for a cybersecurity researcher and listed the achievements obtained using the ARTEX tool.
The provided clues included name, phone number, Telegram account, educational background from South China University of Technology at the age of 26, and being located in Maoming, Guangdong, China, among other information.
Researchers also found that the same Telegram username had appeared in other online activities, including vulnerability research on an NFT gift trading market based on Telegram and a suspected attack on a Chinese payment platform.
CrowdStrike stated, “While this activity has not been attributed to any named attackers, the attackers are likely Chinese-speaking and motivated by economic gain.”
The credibility of this assessment is termed as “medium,” based on the fact that the attackers used tools developed in China and the Chinese-language cues observed by researchers.
However, there are still doubts about the related identity information. For instance, although the clues mention a 26-year-old, the initially provided birthdate is September 22, 2007, which is inconsistent. CrowdStrike emphasized that the information currently available is insufficient to confirm if this personal data truly belongs to the attackers.
CrowdStrike’s investigation discovered that the attackers utilized the recently introduced ARTEX, an open-source proxy-style penetration testing tool developed in China, and integrated multiple large language models to launch attacks on South Korean financial institutions.
In particular, ARTEX primarily used the DeepSeek v4.1-flash model, and the attackers also employed the GLM-5.3 and Grok 4.6 from the smart AI in Claude Code sessions.
Researchers also found a dual-server architecture, with one located in Hong Kong being the main infrastructure controlled by the attackers, and the other responsible for running ARTEX, likely used in attacks on South Korean financial institutions.
The compromised systems include a loan progress inquiry service for financial brokers in a bank and an employee mobile work support system in another bank.
CrowdStrike pointed out that this attack demonstrates the combination of AI tools with traditional network attack methods, potentially allowing attackers to carry out multiple intrusions in a short period.
CrowdStrike also discovered that the attackers had asked Claude about where hackers usually sell the information obtained from recent South Korean data breach incidents and sought assistance in finding South Korean data trading groups on Telegram.
These records provide clues that the attackers might be motivated by economic gain, but CrowdStrike has not confirmed if the stolen data has been sold.
The South Korean police have set up a 28-member special task force to investigate recent cyber attacks on financial institutions. The Financial Supervisory Service of South Korea has provided around 30 IP addresses associated with the attack activities to financial institutions, requesting enhanced security checks.
Both the Financial Services Commission and the Financial Supervisory Service of South Korea stated that no cases of financial losses have been confirmed yet. The two institutions have issued warnings and initiated a month-long special response plan to prevent further damage.
CrowdStrike evaluates that the attackers may continue to attempt to utilize AI tools to enhance the speed and capability of cyber attacks in the future.
