header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

Multiple South Korean financial institutions suspected of being hit by AI attacks, hackers left identity clues in Claude Code

Beating AI News Flash: From late September to early October, at least 7 financial institutions in South Korea suffered consecutive data breaches, including Shinhan Bank, Kookmin Bank, and Hana Bank. Among them, approximately 25,000 customers of Shinhan Bank and approximately 40,000 customers of Yegaram Savings Bank were affected. The leaked information includes names, phone numbers, annual income, and loan limits. No theft of funds has been discovered so far.


The attacks mainly targeted banks' peripheral business systems, including loan inquiry services used by loan intermediaries, as well as employee mobile office systems. Multiple attacks involved overlapping IP addresses, and South Korean regulators suspect they were carried out by the same attacker. On October 6, South Korean President Lee Jae-myung said the attacks may have used AI.


On October 7, cybersecurity company CrowdStrike released more specific evidence. Investigators found that the attacker used two servers, one located in Hong Kong, used to control the attack activities; the other running the open-source AI penetration testing system ARTEX. Because some server directories were publicly accessible, investigators obtained ARTEX configuration files, Claude Code chat logs, and AI memory files.


ARTEX can connect to different large models, automatically find vulnerabilities, plan testing steps, and invoke security tools. The configuration files show that the attacker mainly used DeepSeek v4.1-flash to drive ARTEX. In addition, the attacker also used Claude Code and invoked GLM-5.3 and Grok 4.6 in other sessions.


The Claude Code chat logs also exposed other activities of the attacker. He once asked where leaked South Korean data is usually sold, and how to find related Telegram trading groups. He also asked AI to help write a security researcher resume, requiring that the results of using ARTEX for penetration testing be included.


In the prompt for writing the resume, the attacker left information such as age 26, Maoming, Guangdong, South China University of Technology, phone number, and Telegram account, but the date of birth filled in did not match the age. CrowdStrike judged that the attacker may use Chinese and was motivated by profit, but his true identity has not yet been confirmed.


On October 8, South Korea's Kyunghyang Shinmun contacted the user of the above Telegram account. The person claimed to work at a convenience store in Henan and said someone deliberately used his information to frame him. However, the reporter found that the account also appeared in the administrator lists of two Telegram communities related to DDoS attacks. His claim has not yet been verified, and South Korean police are still investigating.

举报 Correction/Report
Correction/Report
Submit
Add Library
Visible to myself only
Public
Save
Choose Library
Add Library
Cancel
Finish