Hacker Used AI to Target South Korean Banks, CrowdStrike Says
The US security firm alleges a 26-year-old used a local AI agent and Claude Code to break into bank systems, though it admits the clues may not point to one person.
CrowdStrike – (Special Correspondent/Web Desk) – A US cybersecurity company says one person is behind the recent attacks on South Korean banks. CrowdStrike made the claim on Thursday. It says the suspect is 26 years old and was likely working from southern China.
The firm says the hacker used a locally built AI agent together with Anthropic’s Claude Code. These tools helped the attacker get into bank systems much faster than a person could alone.
South Korean police have opened an investigation. At least nine banks said their systems were targeted in late September. The attacks shocked the public and raised fresh worries about online safety.
Some customers were hit harder than others. Shinhan Bank said the personal details of about 25,000 customers were leaked. KB Kookmin Bank said the data of 119 customers was exposed.
President Lee Jae Myung has asked for a strong response. He wants officials to act quickly and make sure such attacks do not happen again.
CrowdStrike says it found clues by studying the AI coding sessions and the systems used in the campaign. Those records pointed to a likely location in Guangdong province in China.
The company did not name the attacker. It says the person probably speaks Chinese. It also says the hacker used ARTEX, a Chinese open-source tool normally used for penetration testing.
One detail stands out. The attacker reportedly asked Claude Code to write a cybersecurity resume. To do this, the person shared an age of 26, an education history and a location in Maoming, Guangdong.
CrowdStrike warns that these details cannot prove who the hacker is. Anyone can type false facts into an AI tool. The firm says the clues are useful but not final.
The company also believes the attacker wanted to make money. The person reportedly asked Claude to help find a market where the stolen customer data could be sold.
Adam Meyers, a senior vice president at CrowdStrike, spoke to reporters by phone. He called the case a clear example of a human using AI agents to run wide attacks.
He said this matters because one person can now go after many targets in a very short time. In the past, that kind of reach needed a larger team.
Experts say this is a warning for every bank and company. AI tools can save time for honest workers, but they can also help criminals work at a much larger scale.
Banks may now need stronger monitoring and faster alerts. They may also need to train staff to spot AI-driven threats early.
For customers, simple steps can help. Change your banking passwords, turn on two-step login and check your account for strange activity. Be careful with calls, texts and emails that ask for personal details.
Police have not yet said whether anyone has been arrested. The probe is still going on, and more facts may come out in the coming days.
For now, the case shows how fast cybercrime is changing. It also shows why banks, tech firms and governments must work together to keep money and personal data safe.
Comments are closed, but trackbacks and pingbacks are open.