AI NewsKorean Bank Hacker Asked Claude Where to Sell the Stolen Data, CrowdStrike...

Korean Bank Hacker Asked Claude Where to Sell the Stolen Data, CrowdStrike Says

The suspected attacker behind South Korea’s recent bank breaches asked an AI coding tool where breach data sells. CrowdStrike found the request in session logs stored in open directories on attacker-controlled servers.

Several South Korean banks have disclosed customer data leaks over the past week. CrowdStrike’s October 7 report says the campaign used a Chinese-built AI penetration testing tool and several language models.

What Is Known So Far About the Korean Bank Breaches

A string of attacks hit several Korean lenders in succession between late September and early October. Shinhan Bank confirmed its breach on September 30 and said a day later that about 25,000 customers were affected. The intruder slipped past identity checks on a mobile service loan agents use to track applications.

The exposed records covered names, phone numbers, annual income, and calculated loan limits. They also included 66 resident registration numbers, South Korea’s national ID numbers.

KB Kookmin Bank followed on October 2, saying data on 119 customers leaked through a mobile system its employees use. Hana Bank disclosed 89 affected customers, while BNK said records on 11 outsourced workers were taken.

President Lee Jae Myung then raised the AI question at a Cabinet meeting. Police have since opened a full-scale investigation.

“In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety,” he said.

An Open Server Exposed the Attacker’s AI Conversations

CrowdStrike published its findings on October 7. Open directories on attacker-controlled servers held histories from Claude Code, Anthropic’s AI coding assistant, along with configuration files.

“Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files, providing direct insight into the threat actor’s operational methodology and tooling,” the report read.

According to the report, the attacker worked with ARTEX, an open-source agentic penetration testing (pentesting) tool developed in China.

A Hong Kong-based server acted as the attacker’s main infrastructure. An IP address ran the ARTEX instance that CrowdStrike says was likely behind the Korean attacks.

CrowdStrike said the ARTEX instance used DeepSeek v4.1-flash as its main AI model. The attacker also used Zhipu AI’s GLM-5.3 and xAI’s Grok 4.6 in other Claude Code sessions.

DeepSeek also featured in an August TeamT5 report on Chinese hackers. The Taiwanese firm found state-linked groups doubled their attack volume after adopting DeepSeek and open-source AI.

The Attacker Asked About Telegram Markets

Alongside the ARTEX operation, the attacker asked Claude where threat actors typically sell Korean breach data. The same user wanted help finding Korean Telegram groups that sell such data.

CrowdStrike has not named any group behind the campaign. It assessed with moderate confidence that the actor is likely a financially motivated Chinese speaker. That view rests on ARTEX and the Chinese-language prompts.

A Résumé Request May Point to the Hacker

In another session, the user asked Claude to write a security researcher résumé showcasing the ARTEX results. The prompt listed a Telegram handle, an age of 26, and a location in Maoming, Guangdong.

CrowdStrike said the details likely belong to the attacker but cannot be definitively linked to them. The firm also noted the attacker first entered a 2007 birth date.

The same Telegram handle appeared in Claude Code sessions probing a Telegram-based NFT gift marketplace for flaws.

“While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated,” CrowdStrike added.

CrowdStrike said AI tooling can help a financially motivated actor run multiple intrusions in a short span. Previously, Anthropic also said that AI now performs advanced attack tasks for low-skill hackers.

CrowdStrike expects attackers to keep experimenting with AI tools. It was among more than 100 companies that signed an August letter warning that AI-enabled cyberattacks will surge.

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights

- Advertisement -spot_img

More From UrbanEdge

Santiment Sees a Long-Term Bullish Case in Solana’s 124% Network Growth

Solana (SOL) network growth has jumped 124% since early September, according to Santiment. The analytics firm ties a long-term bullish case to that growth, which now adds about 1.71 million new wallets daily. However, institutional demand is moving the other way. US spot Solana exchange-traded funds (ETFs) have shed $17.7 million over three straight sessions,…

Bitget Is Changing How Institutions Hold and Trade Crypto

Nearly half of institutions planning to add crypto exposure in 2026 cite better infrastructure as a reason. Custody, settlement, and risk controls rank among the main reasons, according to a Coinbase and EY-Parthenon survey of 351 firms. The question has moved from what an exchange lists to how it lets capital move in and out.…

Anthropic’s Claude Gets 75% Cheaper. Its $2 Trillion IPO Gets Called “Ridiculous”

Anthropic released Claude Haiku 5.5 on October 7, pricing its newest model about 75% below Haiku 4.5 on average.  The company continues to ship new models ahead of its highly anticipated IPO. However, New Constructs has called Anthropic’s planned listing the “most ridiculous IPO of 2026.” A Cheaper Claude Model Arrives 9 Days After Sonnet…

Global Capital Meets Frontier Technology at Digital Assets & Tokenization Summit in Singapore

Hosted by Luna PR, the closed-door summit will convene institutional investors, founders and policymakers on October 9 to examine how tokenization is reshaping global capital markets.  Global finance, investment,digital asset, and technology leaders will convene at the fourth edition of the Digital Assets & Tokenization Summit on October 9, 2026, at Monti Singapore. The closed-door…

New Generation of Crypto Miners Released by ASICID

ASICID Inc. has released its IDMINER Series, a new lineup of cryptocurrency mining systems designed for Bitcoin, Litecoin, and Dogecoin mining. The series includes the IDMINER HomeRack, IDMINER 2 and IDMINER 1, with configurations ranging from 1,150 TH/s to 9,600 TH/s of Bitcoin hashrate and from 350 GH/s to 3,200 GH/s of Litecoin and Dogecoin…

Samsung Wallet Brings USDC to 82 Million US Phones, No Crypto App Needed

Samsung Wallet adds USDC transfers for US Galaxy users in late October. Here is who runs the service, what it costs, and who can use it. The post Samsung Wallet Brings USDC to 82 Million US Phones, No Crypto App Needed appeared first on BeInCrypto.

Dan Ives Names 5 Tech Stocks for 2027, Including One That Doubled in 2026

Dan Ives named Nvidia, Microsoft, Palantir, Apple, and CrowdStrike as his top 5 tech stock picks. He argued that investors still underestimate a $4 trillion AI spending wave. The 5 stocks have taken very different paths this year. CrowdStrike has more than doubled since the start of 2026, while Microsoft and Palantir have each gained…

Two Crypto CEOs Call the End of Winter, One Says It Happened a While Back

Bitwise CEO Hunter Horsley and MetaMask CEO Joseph Lubin both say the crypto winter is over.  On the sidelines of TOKEN2049, Horsley credited sellers exiting the market and the sector’s growing substance. Lubin, an Ethereum co-founder, believes the thaw arrived quite a while ago. Bitwise Sees a Sweet Spot After Sellers Exit Speaking to CNBC,…

Is Bitcoin Headed to $81,000? What On-Chain Data Shows

Bitcoin (BTC) slipped back below $85,000 this week, days after its first daily close above that level. Glassnode data shows the move came on weak trading volume, with new capital arriving slowly. The firm now flags $81,000, home to the largest buy orders on Binance, as the next level to watch. Why Does Bitcoin Price…
- Advertisement -spot_img