HomeSecurityCrowdStrike links South Korean bank breaches to AI tools and...

CrowdStrike links South Korean bank breaches to AI tools and suspect from China

The person behind a wave of cyberattacks on South Korean banks may be a 26-year-old man living in China's Guangdong province, according to US cybersecurity firm CrowdStrike. The case has raised concerns among South Korean authorities and the international community, as the attacks are not linked to any known hacking group, complicating the situation.

See also: CrowdStrike "bets" on the browser: Acquisition of Seraphic Security

Article image: CrowdStrike links South Korean bank breaches to AI tools and a China suspect

CrowdStrike presented its findings in a report published on October 7, which Reuters, noting the age and location connection. However, the company says it cannot confidently link these details to the attacker. The lack of such certainty highlights the challenges cybersecurity experts face when trying to track and identify attackers in such a complex and interconnected environment.

The attacks targeted South Korean financial companies from late September to early October, resulting in data theft. The attackers used ARTEX, a free Chinese AI tool designed to conduct virtual attacks to identify security vulnerabilities, as well as Anthropic’s Claude Code and other AI models. This use of AI technologies for malicious purposes highlights the growing trend of cybercriminals exploiting advanced technologies, which poses a serious threat to data security.

CrowdStrike discovered the attacker’s AI chat logs in open folders on servers operated by the attacker. In one chat, the user asked Claude to create a resume that included age, university, and residence in Guangdong. However, a previously provided date of birth did not match the reported age, according to the report. This discrepancy could indicate an attempt at deception or simply a mistake, but in either case it adds an additional layer of complexity to the investigation.

CrowdStrike expressed moderate confidence that the attacker speaks Chinese and is likely motivated by financial gain. The attacks were not linked to any known hacking group, suggesting that it may be a lone attacker or a new, unknown group. In other conversations, the user asked where the Korean breach data was being sold, which reinforces the assumption that the motive is financial.

See also: FalconFlank: Zero-day in CrowdStrike Falcon for privilege escalation

CrowdStrike links South Korean bank breaches to AI tools and suspect from China

Reuters contacted a phone number listed in the report, and the person who answered said he was unaware of the situation. Anthropic, South Korean police and China’s foreign ministry did not immediately respond to requests for comment. The silence could be due to a variety of reasons, including the ongoing investigation or a desire to keep details that could affect its outcome private.

Meanwhile, South Korean police launched a formal investigation on Oct. 6, covering seven financial institutions, including Shinhan Bank, KB Kookmin Bank and Hana Bank. Reuters has identified at least nine banks that have been targeted since late September. Shinhan said personal data of about 25,000 customers was exposed, while KB Kookmin reported a figure of 119. The figures show the scale of the breach and the serious consequences for the banks’ customers.

Additionally, President Lee Jae Myung addressed the AI ​​aspect during a cabinet meeting the same day, stating, “In some hacking cases, details of possible use of AI have emerged,” as reported by the Korea JoongAng Daily. This report underscores the importance of understanding and addressing new threats arising from AI technology.

See also: CrowdStrike reveals coordinated multi-agency investigations across five sectors

CrowdStrike links South Korean bank breaches to AI tools and suspect from China

This case follows the Australian revelation that an OpenAI agent hacked a government health statistics portal. The continued rise in incidents involving AI in cyberattacks makes it clear that organizations need to strengthen their defenses and closely monitor developments in the field of artificial intelligence. This case is a reminder of the need for international cooperation and information sharing to combat cybercrime.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS