The Jerusalem PostFlydubai passenger recounts terrifying dive as analyst warns against learning 'the wrong lesson'ESPNWhy a surprise player tops our rankings of the 25 best freshmenBollywood HungamaGauahar Khan sells Versova duplex for Rs 6.01 crores, bought it for Rs 3.2 crores in 2014ESPN DeportesBitácora de Gil Mora, el niño consentido de Rafael MárquezRTP DesportoWilliam Gomes renova contrato com o FC Porto até 2031PunchPensioners hail NSITF MD over implementation of 23-year-old S’Court judgmentZDF heuteAktuelle Pressemitteilungen des ZDFABC NewsWATCH: 14-year-old cancer survivor now thrivingNMEThom Yorke says Radiohead reunion tour caused “massive” crash in self-confidence: “It took me months”Variety‘NAZA’ Producer James Wilson Says Israeli Government Response to Gaza Doc Has Been ‘Horrible and Scary,’ but Directors are ‘Safe and OK’ConsequenceColombia’s Estéreo Picnic Reveals 2027 Lineup Led by Travis Scott, Charli XCX, and David GuettaBBC NewsTwo Latvian men arrested on suspicion of trespass at RAF base in Cambridgeshire
The Daily Newsstand · Free, Always
Thursday, October 8, 2026

CrowdStrike finds possible bank hacker's CV among exposed AI logs

Translate

Suspected Chinese speaker used Claude Code and agentic pentesting tool ARTEX in attacks on South Korean lenders

CrowdStrike researchers investigating attacks on South Korean financial institutions found exposed AI session logs containing operational details and a resume-writing request that may identify the attacker.

In a report published Wednesday, analyst Ashley Campion said the prompt named "YY," listed a Chinese university and a location in Guangdong, and gave conflicting age information: 26, but initially a birth date in September 2007.

CrowdStrike considers the details likely to belong to the attacker but says it cannot definitively establish that connection.

REG AD

The attacks affected at least five lenders, including Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank, and BNK Busan Bank, according to The Korea Times.

REG AD

In one case, the attackers allegedly breached a loan progress inquiry service and in another, they gained access to a mobile work-support system.

The researchers found references to YY in AI sessions associated with activity involving ARTEX, a recently released open source penetration-testing tool developed in China and used in the attacks alongside Claude Code.

Researchers examined an exposed directory on a server associated with the attacks. A Chinese-language instruction file led them to another server in Hong Kong, where they found session histories, configuration files, and AI memory files documenting the targeting.

The resume prompt included a Telegram username that also appeared in activity targeting a possible Chinese payment platform and in Claude Code sessions seeking vulnerabilities in a Telegram-based NFT gift marketplace, CrowdStrike said.

"The use of agentic AI tooling alongside traditional offensive capabilities highlights the continued evolution observed by CrowdStrike in adversarial tradecraft," Campion said.

"This activity demonstrates how AI tooling can enable a financially motivated threat actor to conduct multiple intrusions within a short time span. CrowdStrike Intelligence assesses that adversaries will likely continue to experiment with implementing AI tooling in their operations to enhance their operational tempo and capabilities."

Police are investigating whether an individual or an organized group carried out the attacks.

Shinhan Bank reported that about 25,000 customers were affected, while KB Kookmin and Hana reported 119 and 89 respectively. Lawmakers have approved plans to summon the heads of five major commercial banks to an October 19 parliamentary audit to answer questions about cybersecurity lapses. ®

View the original on The Register →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.