The suspect behind recent cyberattacks on South Korea’s financial sector may be a 26-year-old in China’s Guangdong province. In a report published Wednesday, U.S. cybersecurity firm CrowdStrike said it found personal details linked to the suspected attacker while analyzing AI coding-tool sessions and infrastructure tied to a campaign running from late September to early October. […]

Key Takeaways
Suspect Identified: CrowdStrike says the attacker may be a 26-year-old based in China’s Guangdong province.
AI Tools Used: The suspect allegedly used ARTEX, a Chinese-developed AI agent, and Anthropic’s Claude Code.
Nine Banks Targeted: At least nine South Korean banks have disclosed, or been reported as, targets since late September.
The suspect behind recent cyberattacks on South Korea’s financial sector may be a 26-year-old in China’s Guangdong province. In a report published Wednesday, U.S. cybersecurity firm CrowdStrike said it found personal details linked to the suspected attacker while analyzing AI coding-tool sessions and infrastructure tied to a campaign running from late September to early October.
Claude Sessions Point to Maoming, GuangdongCrowdStrike said the individual asked Claude where threat actors typically sell Korean data breach information and sought help finding Korean Telegram data sale groups.
In another session, the person asked Claude to create a security researcher resume. It listed a Telegram account, age, educational background, and a location in Maoming, a city in southern Guangdong, which CrowdStrike said likely belonged to the attacker.
A man who answered a phone number provided in the report said he knew nothing about the matter, and Anthropic, South Korean police, and China’s foreign ministry did not immediately respond to requests for comment, according to Reuters.
What Is ARTEX? The Chinese AI Penetration Testing ToolARTEX is an open-source AI agent for automated penetration testing, published on GitHub this year by a Chinese security engineer using the handle “Autumn.” It is not a standalone large language model (LLM), but connects to external models such as ChatGPT, Claude, and DeepSeek to help organizations test their networks for vulnerabilities.
Its GitHub page says it is meant for personal learning, code research and local technical verification, not real-world testing against online systems or websites.
CrowdStrike has not attributed the activity to a named adversary. It said, with moderate confidence, that the actor is likely a Chinese speaker and financially motivated, based on ARTEX use and Chinese-language prompts.
“Activity at multiple organizations purportedly involved overlapping IP addresses,” CrowdStrike said. “Reporting also suggested the attacker used ARTEX based on references to the string ARTEX in HTML files observed on a reportedly threat actor-controlled server.”
Shinhan Bank and KB Kookmin Bank Customer Data CompromisedShinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, and Hyundai Capital suffered data breaches between September 27 and 30, reports say.
Shinhan Bank said last week that personal information of 25,727 customers was compromised. KB Kookmin Bank said 119 customers’ personal information was leaked, and Hana Bank said 89.
AI Agent Attacks Raise Security ConcernsThe case is likely to intensify concerns over AI agents and whether organizations can defend against them.
Australia said last month that an OpenAI autonomous agent breached a government health statistics portal in June, one of the first known cases of an AI agent hacking a government system.
In other recent news, suspected AI-linked cyberattacks targeting two Seoul megachurches may have exposed data of 850,000 members. In August, feds warned that hackers now use AI to write exploits targeting U.S. water systems’ Siemens PLCs.
Explore More
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | AI Tools and Sloppy Opsec Expose Suspected Chinese Hacker Behind South Korean Bank Breaches | 0 | 8.33 | 09-10-2026 |
| 2 | Chinese AI Agent Pulled From Public View After Breaching South Korean Banks | 0 | 11.64 | 09-10-2026 |
| 3 | South Korea’s Banks Under AI-Assisted Assault: President Lee Demands Answers | 0 | 15.85 | 08-10-2026 |
| 4 | Un agent IA offensif industrialise les compromissions : autopsie des attaques ARTEX | 0 | 8.65 | 08-10-2026 |
| 5 | South Korea warns of possible AI use in banking hacks | 0 | 7.54 | 06-10-2026 |
| 6 | China-linked hackers backdoored executives' laptops via USB, exploiting a fix companies had but weren't using | 0 | 10.4 | 03-09-2026 |
| 7 | В Южной Корее выявили утечки в десятках организаций в результате кибератак | 0 | 8.33 | 06-10-2026 |
| 8 | China-linked hackers posed as former US officials, Anthropic employee to target AI experts | 0 | 10.37 | 01-10-2026 |
| 9 | China-linked hackers posed as former US officials, Anthropic employee to target AI experts | 0 | 10.37 | 01-10-2026 |