Leadership4 publishersAlso reported elsewhere2 min readPublished
CrowdStrike traces AI-assisted attacks on South Korean banks to one possible suspect in Guangdong
CrowdStrike tied AI-assisted South Korean bank attacks, run on an open-source pentest tool and DeepSeek, to a possible 26-year-old suspect in Guangdong. The reported breaches involved systems banks run for brokers and staff, so the exposure to manage sits at the bank's edge, whoever the attacker proves to be.
The Board Room · Leadership desk

What happened
- At least nine South Korean banks have been targeted since late September, though not all nine necessarily suffered a successful breach.
- Three banks have published customer counts that add up to roughly 25,200 people whose personal information was exposed.
- CrowdStrike found Claude Code sessions in which the individual asked about markets for stolen South Korean data and Telegram groups that trade it.
- CrowdStrike assessed with moderate confidence that the attacker is a Chinese speaker driven by financial gain.
- South Korean President Lee Jae Myung said it looked as if AI had played a part in some of the attacks, and he urged tougher cyber defences.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- constraint Planning on one person breaching nine banks overstates the record, because the account does not tie each incident among the nine to this suspect.
- capability An attacker's own AI coding sessions handed CrowdStrike a motive and a candidate profile, so AI usage records become evidence investigators can work from after an intrusion.
- precedent The president's call for defences sized to AI-enabled threats makes it likely Korean supervisors will ask banks to show controls against agent-driven intrusion before attribution is settled.
CEO Today, reporting CrowdStrike's findings, wrote that the case shows how commercially available AI can be adapted to let individuals run more sophisticated attacks with fewer technical resources [20]. So far the confirmed customer losses sit mostly at one lender. Shinhan Bank confirmed about 25,000 affected customers, KB Kookmin 119 and Hana 89 [12][13][14]. Shinhan alone is about 99% of that confirmed total [19].
The tooling came from the defensive side of the industry. ARTEX is an open-source platform developed in China that uses AI agents to automate security assessments, and it was designed for legitimate testing [5]. CrowdStrike said the attacker ran it with DeepSeek as the primary language model [4]. Claude Code appears in the account as evidence, in sessions found alongside configuration files and other records tied to the attack infrastructure. The account does not say Claude Code was used to break in [6].
A skeptic would call this a contained fraud case with no state behind it. The findings establish no connection to the Chinese government, and China's foreign ministry said it was unfamiliar with the case and restated its opposition to hacking [11]. The answer to the skeptic is the route in. According to CrowdStrike, the reported breaches involved a loan application enquiry service used by financial brokers and an employee mobile support platform, both systems connected to banking operations [17]. CEO Today noted that in large financial organisations, external service providers, employee platforms and customer-facing applications can create vulnerabilities [21].
The suspect profile rests on the attacker's own prompts. In one session the individual asked Claude to draft a cybersecurity researcher CV listing an age of 26, educational details and a location in Maoming, Guangdong [8]. CrowdStrike said those details may belong to the person responsible, and that the evidence does not establish a definitive identity [9].
I'd separate the horizons. Whether one operator can work through a whole country's banks is a question for this decade, and this case does not settle it. This quarter's question is narrower: whether broker-facing services and staff apps sit inside the same testing and monitoring scope as core banking systems. Korean banks will answer it with police investigations open and financial regulators already running an emergency response [15].
What to watch
- Whether CrowdStrike or South Korean police tie the remaining incidents among the nine targeted banks to the same individual.
- Whether investigators confirm or rule out the Maoming identity drawn from the CV the individual asked Claude to write.
- Whether South Korea's financial regulators turn their emergency response into rules covering broker-facing and employee systems.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence50
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
CrowdStrike linked a series of AI-assisted cyberattacks against South Korean financial institutions to a possible suspect in China.
- [2]
CrowdStrike said digital records associated with the attacks suggest the individual responsible may be a 26-year-old based in Guangdong province, though it has not established the suspect's identity.
- [3]
At least nine South Korean banks have reportedly been targeted since late September, though that does not mean all nine suffered successful data breaches.
- [4]
CrowdStrike said the attacker used ARTEX, a Chinese-developed AI penetration-testing platform, with DeepSeek as its primary language model.
- [5]
ARTEX is an open-source penetration-testing platform developed in China that uses AI agents to help automate security assessments; it was designed for legitimate cybersecurity testing.
- [6]
CrowdStrike uncovered Claude Code sessions, configuration files and other digital records associated with infrastructure used in the attacks; the Claude Code sessions provided further evidence about the individual's activities.
- [7]
Researchers uncovered conversations in which the individual sought information about markets for stolen South Korean data and Telegram groups associated with trading compromised information.
- [8]
In another session the individual asked Claude to prepare a cybersecurity researcher resume containing an age of 26, educational details and a location in Maoming, Guangdong province.
- [9]
CrowdStrike said the resume details may belong to the person responsible for the attacks, but the available evidence does not establish a definitive identity.
- [10]
CrowdStrike assessed with moderate confidence that the attacker was a Chinese speaker and financially motivated.
- [11]
The findings do not establish any connection between the attacks and the Chinese government; China's foreign ministry said it was unfamiliar with the case and reiterated its opposition to hacking.
- [12]
Shinhan Bank confirmed that personal information belonging to approximately 25,000 customers had been compromised.
- [13]
KB Kookmin Bank reported that information relating to 119 customers had been exposed.
- [14]
Hana Bank reported a breach affecting 89 customers.
- [15]
Other financial institutions have also reported incidents, prompting police investigations and an emergency response from financial regulators.
- [16]
South Korean President Lee Jae Myung warned that artificial intelligence appeared to have been used in some of the attacks and called for stronger cybersecurity measures capable of responding to increasingly sophisticated AI-enabled threats.
- [17]
According to CrowdStrike, reported breaches involved systems including a loan application enquiry service used by financial brokers and an employee mobile support platform, systems connected to banking operations.
- [18]
The three banks that published customer counts report about 25,208 affected customers combined.
- [19]
Shinhan accounts for about 99% of the confirmed affected customers across the three banks.
- [20]
CEO Today wrote that the investigation shows how commercially available AI technology can be adapted for malicious activity, potentially allowing individuals to conduct increasingly sophisticated attacks with fewer technical resources.
- [21]
CEO Today wrote that in large financial organisations, external service providers, employee platforms and customer-facing applications can create vulnerabilities.
Sources
4 independent publishers whose own reporting we read for this story.
- ceotodaymagazine.comCrowdStrike Links AI Bank Hacks to Suspect in China
1 article · October 8, 2026
- crowdstrike.comAnalysis: the hacker who targeted South Korean banks is likely Chinese-speaking, financially motivated, and used LLMs and open-source Chinese agentic tool ARTEX
1 article
- itnews.com.auCrowdStrike says China-based suspect used AI tools in South Korean bank hacks - iTnews
1 article
- thenextweb.comCrowdStrike links South Korean bank breaches to AI tools and a China suspect
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Threat AttributionFollow
- Penetration testing toolsFollow
- Financial Sector CybersecurityFollow
- AI-Enabled CyberattacksFollow