ESPNMLB eyes shorter regular season, expanding Division Series to best-of-7RTP DesportoMundial 2027: Francisco Neto pede Portugal fiel à identidade em LarneInquirerHeavy afternoon rains flood parts of KoronadalESPN DeportesDemandan a Jeanie Buss por venta de LakersDaily MaverickJOBURG FIRE: Mayfair family lose home in blaze as overcrowding, illegal connections fuel fire riskThe Jerusalem PostUK counterterror police arrest two Latvian men under National Security Act for RAF base incursionTechCrunchWatch the trailer for ‘The Altruists,’ Netflix’s show about the FTX scandalBusiness AMAI-bedrijf achter Manus haalt meer dan 500 miljoen dollar op na afgeblazen Meta-dealZDF heuteAktuelle Pressemitteilungen des ZDFGlobal NewsHamilton rocked by 2 suspected home explosions, 3 people hospitalizedThe Hollywood ReporterJennifer Coolidge Is Back as Karen for ‘The Watcher’ Season 2BillboardMariska Hargitay Praises Taylor Swift’s Acting — and ‘Best Cookies’ — on Emmys ‘SVU’ Set
The Daily Newsstand · Free, Always
Thursday, October 8, 2026

S Korean banks likely hacked by China-based actor: CrowdStrike

Translate

The suspect behind cyberattacks at South Korean banks was likely a China-based 26-year-old who used a Chinese-developed artificial intelligence (AI) agent and Anthropic’s Claude Code, US cybersecurity company CrowdStrike said.

In a report published on Wednesday, CrowdStrike said it believed the suspect was likely based in China’s Guangdong Province after uncovering personal details linked to the suspected attacker while analyzing AI coding-tool sessions and infrastructure associated with the hacking campaign.

At least nine South Korean banks have disclosed or have been reported by local media as having been targeted by cyberattacks since late last month, prompting South Korean police to launch a probe this week and South Korean President Lee Jae-myung to call for robust response measures.

The CrowdStrike logo is displayed on the Sphere in Las Vegas on Sept. 1.

Photo: Reuters

CrowdStrike senior vice president of counter adversary operations Adam Meyers yesterday told reporters on a call that this was an example of a human adversary leveraging AI agents to conduct widespread attacks.

“And this is significant because it allows one human to target many customers in a very short period of time using the power of AI,” he said.

The case is likely to intensify security concerns over the rise of AI agents and whether organizations are prepared to defend their systems against them.

Shinhan Bank last week said that personal information of about 25,000 of its customers was compromised, while KB Kookmin Bank said that the personal information of 119 of its customers was leaked.

The attacker used ARTEX, a Chinese-developed open-source penetration testing tool, alongside large language models such as Anthropic Claude, CrowdStrike said.

“While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated,” the report said. “This assessment is made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts.”

The individual also asked Claude where threat actors typically sell Korean data breach information and sought assistance in finding Korean Telegram data sales groups, CrowdStrike said.

In another session, the person also requested Claude to create a security researcher resume, which included details such as a Telegram account, age, educational background and a location in Maoming, China, which CrowdStrike said likely belonged to the attacker.

A man who answered a phone number published by CrowdStrike in its report said he had no knowledge of the matter.

Chinese Ministry of Foreign Affairs spokeswoman Mao Ning (毛寧) told a regular news briefing that the ministry was not familiar with the case and that China as a matter of principle has consistently opposed and combated hacking activities.

Anthropic and South Korean police did not respond to requests for comment.

ARTEX is an open-source AI agent for automated penetration testing that was published on GitHub this year by a Chinese security engineer with the handle Autumn. It is not a standalone large language model (LLM), but connects to external LLMs such as ChatGPT, Claude and DeepSeek (深度求索) to help organizations test for vulnerabilities in their networks.

The tool’s GitHub page says it is intended for personal learning, code research and local technical verification and should not be used to conduct real-world testing against online systems or Web sites.

View the original on Taipei Times →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.