Korean Bank Hacker Asked Claude Where to Sell the Stolen Data, CrowdStrike Says
The suspected attacker behind South Korea's recent bank breaches asked an AI coding tool where breach data sells. CrowdStrike found the request in session logs stored in open directories on attacker-controlled servers.
Several South Korean banks have disclosed customer data leaks over the past week. CrowdStrike's October 7 report says the campaign used a Chinese-built AI penetration testing tool and several language models.
What Is Known So Far About the Korean Bank Breaches
A string of attacks hit several Korean lenders in succession between late September and early October. Shinhan Bank confirmed its breach on September 30 and said a day later that about 25,000 customers were affected. The intruder slipped past identity checks on a mobile service loan agents use to track applications.
The exposed records covered names, phone numbers, annual income, and calculated loan limits. They also included 66 resident registration numbers, South Korea's national ID numbers.
KB Kookmin Bank followed on October 2, saying data on 119 customers leaked through a mobile system its employees use. Hana Bank disclosed 89 affected customers, while BNK said records on 11 outsourced workers were taken.
President Lee Jae Myung then raised the AI question at a Cabinet meeting. Police have since opened a full-scale investigation.
"In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety," he said.
An Open Server Exposed the Attacker's AI Conversations
CrowdStrike published its findings on October 7. Open directories on attacker-controlled servers held histories from Claude Code, Anthropic's AI coding assistant, along with configuration files.
"Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files, providing direct insight into the threat actor's operational methodology and tooling," the report read.
According to the report, the attacker worked with ARTEX, an open-source agentic penetration testing (pentesting) tool developed in China.
A Hong Kong-based server acted as the attacker's main infrastructure. An IP address ran the ARTEX instance that CrowdStrike says was likely behind the Korean attacks.
CrowdStrike said the ARTEX instance used DeepSeek v4.1-flash as its main AI model. The attacker also used Zhipu AI's GLM-5.3 and xAI's Grok 4.6 in other Claude Code sessions.
DeepSeek also featured in an August TeamT5 report on Chinese hackers. The Taiwanese firm found state-linked groups doubled their attack volume after adopting DeepSeek and open-source AI.
The Attacker Asked About Telegram Markets
Alongside the ARTEX operation, the attacker asked Claude where threat actors typically sell Korean breach data. The same user wanted help finding Korean Telegram groups that sell such data.
CrowdStrike has not named any group behind the campaign. It assessed with moderate confidence that the actor is likely a financially motivated Chinese speaker. That view rests on ARTEX and the Chinese-language prompts.
-- Price
A Résumé Request May Point to the Hacker
In another session, the user asked Claude to write a security researcher résumé showcasing the ARTEX results. The prompt listed a Telegram handle, an age of 26, and a location in Maoming, Guangdong.
CrowdStrike said the details likely belong to the attacker but cannot be definitively linked to them. The firm also noted the attacker first entered a 2007 birth date.
The same Telegram handle appeared in Claude Code sessions probing a Telegram-based NFT gift marketplace for flaws.
"While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated," CrowdStrike added.
CrowdStrike said AI tooling can help a financially motivated actor run multiple intrusions in a short span. Previously, Anthropic also said that AI now performs advanced attack tasks for low-skill hackers.
CrowdStrike expects attackers to keep experimenting with AI tools. It was among more than 100 companies that signed an August letter warning that AI-enabled cyberattacks will surge.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Sui and Alibaba Cloud Announce AI Payments in Stablecoins
What Is the WEEX AI Trading Demo at TOKEN2049 Singapore?
Learn what the WEEX AI Trading Demo at TOKEN2049 Singapore is, what visitors can test with a simulated account, and the questions worth asking on site.

Integrating Bitcoin into Your Business: A New Solution for Managing Operations While Keeping Control of Your Wallets

Lucent Block Fails After Four Years of Distribution Verification; Lee Eok-yeon Says 'Issuance Exceptions Are Different from Distribution Approval'

OpenAI Says a Secret AI Model Cracked Hundreds of Open Math Problems in One Prompt—Mathematicians Want Receipts

Sui and Alibaba Cloud Collaborate for Automated Payments by AI Agents

Coinbase opens regulated route to Deribit markets for US institutions

Mistral Large 4, aka 'Le Chonk': The French Heavyweight Against GPT-6 Astra and Claude

Whale Withdraws 110 Million Lobsters, USDT Identified as Key Channel for Iran's Shadow Banking

U.S. Department of Justice Cites Bitcoin Fog Case to Oppose Roman Storm's Not Guilty Request

SEC drops to 2 members, and 1 hidden rule shifts crypto power

Zcash Activates Lobbying Organization and Requests $750,000

Flash Loan Attacks Drained $1.2B From DeFi Between 2020 and 2024: Study

Gathering of Users of OAM-Pay Phoenix Due to Delayed Withdrawals

Samsung Electronics Files Patent for Smart Contract Cryptocurrency Wallet

Criminal Case Initiated in Voronezh for Legalizing Drug Trafficking Profits via Cryptocurrency

Meta, TikTok, X Initiate Legal Action Against UK Ofcom

Coinbase says it cut a 90-case AI support test from 1–2 weeks to 30–45 minutes

What happened to Kelsier’s $300M crypto stash?

Authorities Scrutinize Binance's Services for EU Customers, Focus on Scope of 'Reverse Solicitation'

Greenfield Complains to Swiss Regulator About Governance Issues at Safe Ecosystem Foundation

Vitalik Buterin tries AI that keeps personal data private

Vitalik Builds Three-Layer Privacy Architecture for Personalized Health Recommendations

ESMA proposes ending EU custody and transfer services for non-compliant stablecoins

World ID Empowers Verification for AI Agent Support

Three Methods for On-Chain Central Bank Money

Ethereum Launches zkAPI for Paying AI Consultations Without Revealing Identity

Fideuram AI scam: How did €39.5M vanish into crypto?

LIBRA lawsuit dismissed as court rejects claims against Meteora and Chow

Financial Services Agency Requests Budget of Approximately 1.33 Billion Yen for Digital Finance Initiatives, 15 Times More Than Last Year, Supporting On-Chain Finance and Digital Payment Integration
Sui and Alibaba Cloud Announce AI Payments in Stablecoins
What Is the WEEX AI Trading Demo at TOKEN2049 Singapore?
Learn what the WEEX AI Trading Demo at TOKEN2049 Singapore is, what visitors can test with a simulated account, and the questions worth asking on site.








