|

Korean Bank Hacker Asked Claude Where to Sell the Stolen Data, CrowdStrike Says

The suspected attacker behind South Korea’s latest financial institution breaches requested an AI coding instrument the place breach information sells. CrowdStrike discovered the request in session logs saved in open directories on attacker-controlled servers.

Several South Korean banks have disclosed buyer information leaks over the previous week. CrowdStrike’s October 7 report says the marketing campaign used a Chinese-built AI penetration testing instrument and several other language fashions.

What Is Known So Far About the Korean Bank Breaches

A string of assaults hit a number of Korean lenders in succession between late September and early October. Shinhan Bank confirmed its breach on September 30 and stated a day later that about 25,000 prospects have been affected. The intruder slipped previous identification checks on a cell service mortgage brokers use to monitor functions.

The uncovered data coated names, cellphone numbers, annual revenue, and calculated mortgage limits. They additionally included 66 resident registration numbers, South Korea’s nationwide ID numbers.

KB Kookmin Bank adopted on October 2, saying information on 119 prospects leaked by means of a cell system its workers use. Hana Bank disclosed 89 affected prospects, whereas BNK stated data on 11 outsourced staff have been taken.

President Lee Jae Myung then raised the AI query at a Cabinet assembly. Police have since opened a full-scale investigation.

“In some hacking incidents, indicators have emerged of AI getting used, inflicting appreciable public concern and nervousness,” he said.

Follow us on X to get the newest information because it occurs

An Open Server Exposed the Attacker’s AI Conversations

CrowdStrike printed its findings on October 7. Open directories on attacker-controlled servers held histories from Claude Code, Anthropic’s AI coding assistant, together with configuration information.

“Analysis of risk actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration information, and Claude reminiscence information, offering direct perception into the risk actor’s operational methodology and tooling,” the report learn.

According to the report, the attacker labored with ARTEX, an open-source agentic penetration testing (pentesting) instrument developed in China.

A Hong Kong-based server acted as the attacker’s most important infrastructure. An IP tackle ran the ARTEX occasion that CrowdStrike says was seemingly behind the Korean assaults.

CrowdStrike stated the ARTEX occasion used DeepSeek v4.1-flash as its most important AI mannequin. The attacker additionally used Zhipu AI’s GLM-5.3 and xAI’s Grok 4.6 in different Claude Code classes.

DeepSeek additionally featured in an August TeamT5 report on Chinese hackers. The Taiwanese agency discovered state-linked teams doubled their attack volume after adopting DeepSeek and open-source AI.

The Attacker Asked About Telegram Markets

Alongside the ARTEX operation, the attacker requested Claude the place risk actors sometimes promote Korean breach information. The similar person wished assist discovering Korean Telegram teams that promote such information.

CrowdStrike has not named any group behind the marketing campaign. It assessed with average confidence that the actor is probably going a financially motivated Chinese speaker. That view rests on ARTEX and the Chinese-language prompts.

A Résumé Request May Point to the Hacker

In one other session, the person requested Claude to write a safety researcher résumé showcasing the ARTEX outcomes. The immediate listed a Telegram deal with, an age of 26, and a location in Maoming, Guangdong.

CrowdStrike stated the particulars seemingly belong to the attacker however can’t be definitively linked to them. The agency additionally famous the attacker first entered a 2007 delivery date.

The similar Telegram deal with appeared in Claude Code classes probing a Telegram-based NFT present market for flaws.

“While this exercise has not been attributed to a named adversary, the risk actor is probably going a Chinese speaker and financially motivated,” CrowdStrike added.

CrowdStrike stated AI tooling might help a financially motivated actor run a number of intrusions in a brief span. Previously, Anthropic additionally stated that AI now performs advanced attack tasks for low-skill hackers.

CrowdStrike expects attackers to hold experimenting with AI instruments. It was amongst greater than 100 corporations that signed an August letter warning that AI-enabled cyberattacks will surge.

Subscribe to our YouTube channel to watch leaders and journalists present knowledgeable insights

The submit Korean Bank Hacker Asked Claude Where to Sell the Stolen Data, CrowdStrike Says appeared first on BeInCrypto.

Similar Posts