Korean Bank Hacker Asked Claude Where to Sell the Stolen Data, CrowdStrike Says

Source Beincrypto

The suspected attacker behind South Korea’s recent bank breaches asked an AI coding tool where breach data sells. CrowdStrike found the request in session logs stored in open directories on attacker-controlled servers.

Several South Korean banks have disclosed customer data leaks over the past week. CrowdStrike’s October 7 report says the campaign used a Chinese-built AI penetration testing tool and several language models.

What Is Known So Far About the Korean Bank Breaches

A string of attacks hit several Korean lenders in succession between late September and early October. Shinhan Bank confirmed its breach on September 30 and said a day later that about 25,000 customers were affected. The intruder slipped past identity checks on a mobile service loan agents use to track applications.

The exposed records covered names, phone numbers, annual income, and calculated loan limits. They also included 66 resident registration numbers, South Korea’s national ID numbers.

KB Kookmin Bank followed on October 2, saying data on 119 customers leaked through a mobile system its employees use. Hana Bank disclosed 89 affected customers, while BNK said records on 11 outsourced workers were taken.

President Lee Jae Myung then raised the AI question at a Cabinet meeting. Police have since opened a full-scale investigation.

“In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety,” he said.

Follow us on X to get the latest news as it happens

An Open Server Exposed the Attacker’s AI Conversations

CrowdStrike published its findings on October 7. Open directories on attacker-controlled servers held histories from Claude Code, Anthropic’s AI coding assistant, along with configuration files.

“Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files, providing direct insight into the threat actor’s operational methodology and tooling,” the report read.

According to the report, the attacker worked with ARTEX, an open-source agentic penetration testing (pentesting) tool developed in China.

A Hong Kong-based server acted as the attacker’s main infrastructure. An IP address ran the ARTEX instance that CrowdStrike says was likely behind the Korean attacks.

CrowdStrike said the ARTEX instance used DeepSeek v4.1-flash as its main AI model. The attacker also used Zhipu AI’s GLM-5.3 and xAI’s Grok 4.6 in other Claude Code sessions.

DeepSeek also featured in an August TeamT5 report on Chinese hackers. The Taiwanese firm found state-linked groups doubled their attack volume after adopting DeepSeek and open-source AI.

The Attacker Asked About Telegram Markets

Alongside the ARTEX operation, the attacker asked Claude where threat actors typically sell Korean breach data. The same user wanted help finding Korean Telegram groups that sell such data.

CrowdStrike has not named any group behind the campaign. It assessed with moderate confidence that the actor is likely a financially motivated Chinese speaker. That view rests on ARTEX and the Chinese-language prompts.

A Résumé Request May Point to the Hacker

In another session, the user asked Claude to write a security researcher résumé showcasing the ARTEX results. The prompt listed a Telegram handle, an age of 26, and a location in Maoming, Guangdong.

CrowdStrike said the details likely belong to the attacker but cannot be definitively linked to them. The firm also noted the attacker first entered a 2007 birth date.

The same Telegram handle appeared in Claude Code sessions probing a Telegram-based NFT gift marketplace for flaws.

“While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated,” CrowdStrike added.

CrowdStrike said AI tooling can help a financially motivated actor run multiple intrusions in a short span. Previously, Anthropic also said that AI now performs advanced attack tasks for low-skill hackers.

CrowdStrike expects attackers to keep experimenting with AI tools. It was among more than 100 companies that signed an August letter warning that AI-enabled cyberattacks will surge.

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Gold Price Forecast: Gold Rebounds Above $4,200, Can Falling Oil Prices Drive Another Rally?As of Friday (October 9), gold prices (XAUUSD) rebounded noticeably after consecutive declines. During today's Asian session, gold prices briefly rebounded above $4,200, reaching an intra
Author  TradingKey
7 hours ago
As of Friday (October 9), gold prices (XAUUSD) rebounded noticeably after consecutive declines. During today's Asian session, gold prices briefly rebounded above $4,200, reaching an intra
placeholder
Hurricane Isaias has shut in a quarter of Gulf oil output — can WTI clear $92 before Thursday's EIA report?WTI trades at $90.80 after rebounding roughly 3% from Wednesday's $87.96 low as Hurricane Isaias — the Atlantic season's first — forces producers to shut in about 25% of US Gulf of Mexico output. Brent holds at $103.41. The first official read on the disruption arrives with the EIA weekly petroleum report on Thursday 15 October — here are the key levels and both scenarios.
Author  Irene Q.
10 hours ago
WTI trades at $90.80 after rebounding roughly 3% from Wednesday's $87.96 low as Hurricane Isaias — the Atlantic season's first — forces producers to shut in about 25% of US Gulf of Mexico output. Brent holds at $103.41. The first official read on the disruption arrives with the EIA weekly petroleum report on Thursday 15 October — here are the key levels and both scenarios.
placeholder
【Daily Brief】Gold rebounds 1% off a two-month low, Nasdaq drops 1.25% and yields ease — the storm premium keeps WTI near $91Gold trades at $4,174 after rebounding from Wednesday's $4,090 two-month low, the Nasdaq fell 1.25% while the Dow edged higher, and the 10-year Treasury eased to 5.23% from the week's highs. Hurricane Isaias keeps about 25% of Gulf output shut in with WTI near $91, and bitcoin holds below $82,000. The next scheduled tests are the EIA report on 15 October and the FOMC on 27-28 October.
Author  Irene Q.
10 hours ago
Gold trades at $4,174 after rebounding from Wednesday's $4,090 two-month low, the Nasdaq fell 1.25% while the Dow edged higher, and the 10-year Treasury eased to 5.23% from the week's highs. Hurricane Isaias keeps about 25% of Gulf output shut in with WTI near $91, and bitcoin holds below $82,000. The next scheduled tests are the EIA report on 15 October and the FOMC on 27-28 October.
placeholder
WTI slips below $90.50 as Trump signals no pre-election strike on IranWest Texas Intermediate (WTI) oil price declines after posting nearly 2.5% gains in the previous day, trading around $90.30 per barrel during Asian hours on Friday.
Author  FXStreet
15 hours ago
West Texas Intermediate (WTI) oil price declines after posting nearly 2.5% gains in the previous day, trading around $90.30 per barrel during Asian hours on Friday.
placeholder
Bitcoin Drops Below $83,000 as US Government Transfers Over 10,000 BTC, Sparking Panic Over Potential Selling PressureUS government transfers over 10,000 BTC as Bitcoin extends losses to breach $83,000, but a further sharp decline remains unlikely.On October 8, Bitcoin (BTC) extended its recent losses, f
Author  TradingKey
Yesterday 07: 32
US government transfers over 10,000 BTC as Bitcoin extends losses to breach $83,000, but a further sharp decline remains unlikely.On October 8, Bitcoin (BTC) extended its recent losses, f
goTop
quote