
CrowdStrike researchers investigating attacks on South Korean financial institutions found exposed AI session logs containing operational details and a resume-writing request that may identify the attacker.
In a report published Wednesday, analyst Ashley Campion said the prompt named "YY," listed a Chinese university and a location in Guangdong, and gave conflicting age information: 26, but initially a birth date in September 2007.
CrowdStrike considers the details likely to belong to the attacker but says it cannot definitively establish that connection.
The attacks affected at least five lenders, including Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank, and BNK Busan Bank, according to The Korea Times.
In one case, the attackers allegedly breached a loan progress inquiry service and in another, they gained access to a mobile work-support system.
The researchers found references to YY in AI sessions associated with activity involving ARTEX, a recently released open source penetration-testing tool developed in China and used in the attacks alongside Claude Code.
Researchers examined an exposed directory on a server associated with the attacks. A Chinese-language instruction file led them to another server in Hong Kong, where they found session histories, configuration files, and AI memory files documenting the targeting.
The resume prompt included a Telegram username that also appeared in activity targeting a possible Chinese payment platform and in Claude Code sessions seeking vulnerabilities in a Telegram-based NFT gift marketplace, CrowdStrike said.
"The use of agentic AI tooling alongside traditional offensive capabilities highlights the continued evolution observed by CrowdStrike in adversarial tradecraft," Campion said.
"This activity demonstrates how AI tooling can enable a financially motivated threat actor to conduct multiple intrusions within a short time span. CrowdStrike Intelligence assesses that adversaries will likely continue to experiment with implementing AI tooling in their operations to enhance their operational tempo and capabilities."
Police are investigating whether an individual or an organized group carried out the attacks.
Shinhan Bank reported that about 25,000 customers were affected, while KB Kookmin and Hana reported 119 and 89 respectively. Lawmakers have approved plans to summon the heads of five major commercial banks to an October 19 parliamentary audit to answer questions about cybersecurity lapses. ®