**CrowdStrike** identified a suspected 26-year-old living in China as being behind a recent hacking attack targeting South Korean commercial banks. The individual is believed to have used Anthropic’s Claude Code and Chinese-made penetration-testing tools.
Key points
CrowdStrike did not link this attack to any specific hacking group, and rated its confidence in identifying the operator as “moderate.”
A request to write a résumé in a Claude Code session revealed the person was 26 years old and lived in Maoming, Guangdong Province.
Since the end of last September, at least nine Korean banks have been targeted, and the suspect’s real identity has not yet been confirmed.
Key points from the CrowdStrike report
In a report released on Wednesday, US cybersecurity firm CrowdStrike said it obtained identifying clues—believed to be personal information—during its analysis of the AI coding sessions and servers used in this attack campaign. The attack activity was understood to have been concentrated between the end of September and the beginning of October.
In the process of examining an open directory of servers controlled by the attackers, the analysis team found Claude Code session records and memory files, as well as configuration files for an open-source penetration-testing agent called “ARTEX,” developed in China. In one session, a user asked Claude to write a “security researcher resume.” The prompt included a Telegram account, the age of 26, an educational history at South China University of Technology, and a residence in Maoming, Guangdong.
While CrowdStrike believes these pieces of information are likely the attacker’s actual human details, it acknowledged that it is difficult to treat them as conclusive evidence. A man reached by a phone number listed in the report reportedly denied any connection to the incident outright.
Also to read: How much is the annual salary of Anthropic’s CEO? IPO documents revealed it
Circumstances involving the use of Claude Code and ARTEX
No specifically named hacking organization has yet been identified regarding this attack. CrowdStrike described the operator as “someone who appears to be a Chinese-language user and has financial motives,” and rated the reliability of this assessment as “medium” based on factors such as the use of Chinese-developed tools and Chinese-language prompts.
ARTEX is a tool that appeared on GitHub this year; it is a penetration-testing agent designed to integrate with external large language models (LLMs). The GitHub page describes it as “for personal learning,” and explicitly states not to use it against systems in real operation.
The log details also reveal the attackers’ intent to pursue profits.
The user left a question for Claude asking, “Where are the stolen Korean data typically traded?” and “How can I find the Telegram groups that buy and sell this data?” ARTEX appears to have run mainly on DeepSeek v4.1-flash, while other Claude Code sessions used models such as Zhipu AI’s GLM-5.3 and Grok 4.6. CrowdStrike said it expects attackers to actively adopt a variety of AI coding tools to increase the speed and efficiency of their attacks.
Hacking damage from Korean commercial banks spreads
At least nine Korean banks have disclosed the fact that they were attacked since the end of last September, or were targeted through coverage by domestic media. As a result, police investigations started this week, and President Lee Jae-myung ordered a strong response.
Shinhan Bank said that personal information of about 25,000 customers was leaked through a loan applicant inquiry service, and KB Kookmin Bank reported that information for 119 customers leaked from an employee work support system. On October 3, a Financial Security Institute official said it traced the Shinhan Bank breach incident logs to ARTEX and explained, “The hacker used AI as a tool, but AI did not independently carry out the attack.”
Next to read: OpenAI’s 722 AI math papers—now it’s the mathematicians’ turn to evaluate
