A 26-year-old in China’s Guangdong province may be the suspect in a series of hacks on South Korean banks highlighted by authorities in recent days, computer security firm CrowdStrike said in an advisory.
The firm said in the Wednesday report that it had uncovered details potentially linked to the attacker while analysing sessions from an AI programming tool and infrastructure linked to the hacking campaign, which began in late September.
The attacker used Chinese open-source penetration testing tool ARTEX along with AI models, the company said.
It noted a Claude Code session in which the user requested the creation of a security researcher CV describing results from the South Korean hacking activity, and listing a Telegram account, age, education background and a location in Maoming, Guangdong.
The same Telegram username appeared in other hacking activity, including research involving a Telegram-based NFT marketplace and an attack on a Chinese payment platform, CrowdStrike said.
Such indicators led it to assess with “moderate confidence” that the details may belong to the South Korea bank hacker and that the attacks may be financially motivated.
South Korea’s president Lee Jae Myung on Tuesday called on the country’s financial sector to use AI to fend off emerging threats.
Bank hacks
“In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety,” Lee said during a cabinet meeting.
Shinhan Bank and KB Kookmin Bank reported cyber-attacks in which customer data was stolen, Korea’s Financial Services Commission said on Friday, while Yonhap reported that Hana Bank and Woori Bank had also experienced breaches.
Authorities have not yet indicated what role AI tools may have played in the attacks or the scale of the data theft.