Crypto insigtX

Multiple South Korean Financial Institutions Suspected of AI-Assisted Cyberattacks; Claude Code Reveals Identity Clues

Between late September and early October, at least seven financial institutions in South Korea suffered consecutive data breaches, including Shinhan Bank, Kookmin Bank, and Hana Bank. Approximately 25,000…

Published
Market
Crypto
Source
insigtX

Between late September and early October, at least seven financial institutions in South Korea suffered consecutive data breaches, including Shinhan Bank, Kookmin Bank, and Hana Bank. Approximately 25,000 customers of Shinhan Bank and around 40,000 customers of Yegaram Savings Bank were affected, with leaked data including names, phone numbers, annual income, and loan amounts. No fund theft has been discovered so far. The attacks primarily targeted bank peripheral business systems, including loan inquiry services used by loan brokers and employee mobile office systems. Multiple attacks involved overlapping IP addresses, leading South Korean regulators to suspect they were carried out by the same attacker. On October 6, South Korean President Lee Jae-myung stated that the attacks may have utilized AI. On October 7, CrowdStrike reported that the attacker used a server based in Hong Kong to control the attacks, along with another server running the open-source AI penetration testing system ARTEX. Investigators obtained ARTEX configuration files, Claude Code chat logs, and AI memory files. The configuration showed the attacker primarily used DeepSeek v4.1-flash to drive ARTEX, also used Claude Code, and invoked GLM-5.3 and Grok 4.6 in other sessions. Chat logs revealed that the attacker inquired about channels for selling leaked South Korean data and related Telegram trading groups, and also asked the AI to draft a security researcher resume incorporating ARTEX penetration testing achievements. The prompts left clues including age 26, Maoming, Guangdong, South China University of Technology, and contact information, though the date of birth did not match the stated age. CrowdStrike assessed that the attacker may use Chinese and act for profit motives, but has not yet confirmed the true identity.

insigtX content is informational and educational, not investment advice.