Skip to content

Leadership4 publishersAlso reported elsewhere2 min readPublished

CrowdStrike traces AI-assisted attacks on South Korean banks to one possible suspect in Guangdong

CrowdStrike tied AI-assisted South Korean bank attacks, run on an open-source pentest tool and DeepSeek, to a possible 26-year-old suspect in Guangdong. The reported breaches involved systems banks run for brokers and staff, so the exposure to manage sits at the bank's edge, whoever the attacker proves to be.

The Board Room · Leadership desk

How we use AISend a correction

Illustration accompanying CrowdStrike traces AI-assisted attacks on South Korean banks to one possible suspect in Guangdong
Generated illustration

What happened

  • At least nine South Korean banks have been targeted since late September, though not all nine necessarily suffered a successful breach.
  • Three banks have published customer counts that add up to roughly 25,200 people whose personal information was exposed.
  • CrowdStrike found Claude Code sessions in which the individual asked about markets for stolen South Korean data and Telegram groups that trade it.
  • CrowdStrike assessed with moderate confidence that the attacker is a Chinese speaker driven by financial gain.
  • South Korean President Lee Jae Myung said it looked as if AI had played a part in some of the attacks, and he urged tougher cyber defences.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • constraint Planning on one person breaching nine banks overstates the record, because the account does not tie each incident among the nine to this suspect.
  • capability An attacker's own AI coding sessions handed CrowdStrike a motive and a candidate profile, so AI usage records become evidence investigators can work from after an intrusion.
  • precedent The president's call for defences sized to AI-enabled threats makes it likely Korean supervisors will ask banks to show controls against agent-driven intrusion before attribution is settled.

CEO Today, reporting CrowdStrike's findings, wrote that the case shows how commercially available AI can be adapted to let individuals run more sophisticated attacks with fewer technical resources [20]. So far the confirmed customer losses sit mostly at one lender. Shinhan Bank confirmed about 25,000 affected customers, KB Kookmin 119 and Hana 89 [12][13][14]. Shinhan alone is about 99% of that confirmed total [19].

The tooling came from the defensive side of the industry. ARTEX is an open-source platform developed in China that uses AI agents to automate security assessments, and it was designed for legitimate testing [5]. CrowdStrike said the attacker ran it with DeepSeek as the primary language model [4]. Claude Code appears in the account as evidence, in sessions found alongside configuration files and other records tied to the attack infrastructure. The account does not say Claude Code was used to break in [6].

A skeptic would call this a contained fraud case with no state behind it. The findings establish no connection to the Chinese government, and China's foreign ministry said it was unfamiliar with the case and restated its opposition to hacking [11]. The answer to the skeptic is the route in. According to CrowdStrike, the reported breaches involved a loan application enquiry service used by financial brokers and an employee mobile support platform, both systems connected to banking operations [17]. CEO Today noted that in large financial organisations, external service providers, employee platforms and customer-facing applications can create vulnerabilities [21].

The suspect profile rests on the attacker's own prompts. In one session the individual asked Claude to draft a cybersecurity researcher CV listing an age of 26, educational details and a location in Maoming, Guangdong [8]. CrowdStrike said those details may belong to the person responsible, and that the evidence does not establish a definitive identity [9].

I'd separate the horizons. Whether one operator can work through a whole country's banks is a question for this decade, and this case does not settle it. This quarter's question is narrower: whether broker-facing services and staff apps sit inside the same testing and monitoring scope as core banking systems. Korean banks will answer it with police investigations open and financial regulators already running an emergency response [15].

What to watch

  • Whether CrowdStrike or South Korean police tie the remaining incidents among the nine targeted banks to the same individual.
  • Whether investigators confirm or rule out the Maoming identity drawn from the CV the individual asked Claude to write.
  • Whether South Korea's financial regulators turn their emergency response into rules covering broker-facing and employee systems.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence45
Adoption
Insufficient
Hype gap+20
Incentives40
Confidence50
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    CrowdStrike linked a series of AI-assisted cyberattacks against South Korean financial institutions to a possible suspect in China.

    ReportedSupportedSource: CrowdStrike, via CEO TodayView cited source
  2. [2]

    CrowdStrike said digital records associated with the attacks suggest the individual responsible may be a 26-year-old based in Guangdong province, though it has not established the suspect's identity.

    ReportedSupportedSource: CrowdStrikeView cited source
  3. [3]

    At least nine South Korean banks have reportedly been targeted since late September, though that does not mean all nine suffered successful data breaches.

    ReportedSupportedSource: CEO TodayView cited source

Sources

4 independent publishers whose own reporting we read for this story.

  1. ceotodaymagazine.com

    1 article · October 8, 2026

    CrowdStrike Links AI Bank Hacks to Suspect in China
  2. Analysis: the hacker who targeted South Korean banks is likely Chinese-speaking, financially motivated, and used LLMs and open-source Chinese agentic tool ARTEX
  3. itnews.com.au

    1 article

    CrowdStrike says China-based suspect used AI tools in South Korean bank hacks - iTnews
  4. thenextweb.com

    1 article · October 8, 2026

    CrowdStrike links South Korean bank breaches to AI tools and a China suspect

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories