ESPNFollow live: Brewers in control with NLCS matchup vs. Dodgers in sightDaily MaverickAt least 28 killed in Ukraine, Zelenskiy condemns one of Russia’s most ‘vile strikes’ESPN DeportesRays, a Serie de Campeonato por tercera vez; Yankees, fueraBollywood HungamaShraddha Kapoor, Shakti Kapoor lease Mumbai apartment for Rs 2.5 lakhs monthly rent: ReportInquirerSpeaker Dy hails approval of OFW financial education billSCMP ChinaUS wraps up military mission in Iraq, giving Baghdad room to strengthen China tiesUOLSite distribui criptomoedas em troca de divulgação de conteúdo que incentiva voto em Flávio BolsonaroBusiness AMBusiness AM Sudoku’s 08-10-2026ZDF heuteAktuelle Pressemitteilungen des ZDFVarietyDanny and Oxide Pang’s Josie Ho-Starring Supernatural Thriller ‘The Mage’ Sets Busan Market Debut With Abnormal Studios (EXCLUSIVE)CBS NewsIsaias becomes first hurricane of 2026 Atlantic season, threatens Gulf CoastSRF NewsKrieg im Nahen Osten – Saudi-Arabien meldet Vergeltungsangriffe auf Huthi-Stellungen
The Daily Newsstand · Free, Always
Thursday, October 8, 2026

South Korea bank hack suspect may be 26-year-old in China, U.S. firm says

Translate

SEOUL – The suspect behind recent cyberattacks targeting South Korea’s financial sector may be a 26-year-old based in China’s Guangdong province, U.S. cybersecurity firm CrowdStrike has said.

In a report published on its website on Wednesday, CrowdStrike said it uncovered personal details linked to the suspected attacker while analyzing AI coding-tool sessions and infrastructure associated with a campaign targeting South Korean financial institutions from late September to early October.

CrowdStrike said the attacker used ARTEX, a recently released Chinese-developed open-source penetration testing tool, alongside large language models and assessed with “moderate confidence” that the actor was a Chinese speaker and likely financially motivated.

The firm said one Claude Code session contained a request to create a security researcher resume describing results from the hacking activity.

The prompt included details such as a Telegram account, age, education background and a location in Maoming, Guangdong, the report said.

CrowdStrike said the same Telegram username appeared in other cyber activity, including vulnerability research involving a Telegram-based non-fungible token marketplace and a separate suspected attack on a Chinese payment platform.

The company said the personal details likely belonged to the actor responsible for the activity, but cautioned that currently available information could not definitively identify the attacker.

Authorities in Seoul are investigating cyberattacks that affected multiple financial institutions after banks, including Shinhan Bank and KB Kookmin Bank, reported data breaches.

South Korean police, who have launched a probe, did not immediately respond to a request for comment.

South Korean President Lee Jae Myung said on Tuesday that signs had emerged that AI was used in some of the hacking incidents and called for heightened cybersecurity measures.

View the original on The Japan Times →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.