CrowdStrike links Claude Code sessions to a South Korean bank breach and the hacker's own identity
A hacker asked Claude Code where stolen Korean bank data usually gets resold, and that question became part of the evidence trail CrowdStrike says points back to him. CrowdStrike published the findings on October 8, 2026, tying a breach campaign against at least nine South Korean banks to a suspect it believes used Claude Code alongside a Chinese-built AI pentesting agent called ARTEX, per Reuters, via Business Day.
What
CrowdStrike assessed with moderate confidence that the attacker is a 26-year-old Chinese speaker likely based in Maoming, a city in Guangdong province, and financially motivated rather than state-directed, per the Reuters report. The campaign ran from late September into early October 2026 and hit South Korean financial institutions; Reuters puts the count at "at least nine" banks disclosed or reported by local media as targets, while Crypto Briefing describes it as "seven to nine" banks and financial entities, per that outlet. Shinhan Bank said the personal information of about 25,000 customers was compromised, and KB Kookmin Bank confirmed 119 affected customers, both per the Reuters report. CrowdStrike says the attacker used ARTEX, an open-source penetration-testing agent published on GitHub earlier this year by a developer going by "Autumn," in combination with large language models including Claude. ARTEX is not itself a model; its GitHub page describes it as a connector that routes to external LLMs such as ChatGPT, Claude, and DeepSeek, and states the tool is meant for personal learning and local testing, not live attacks against real systems, per the same wire report. Crypto Briefing adds that the attacker's infrastructure included a control server in Hong Kong and that data exfiltration, meaning information was actually copied out of the institutions' systems, was confirmed in multiple of the targeted institutions, per Crypto Briefing's writeup.
Claude's own session logs became part of the case against the attacker
CrowdStrike said the attacker asked Claude where threat actors typically sell Korean breach data and for help locating Telegram groups that trade in it, then in a separate session asked Claude to draft a fake "security researcher" resume. That resume listed a Telegram handle, an age, an educational background, and a location in Maoming that CrowdStrike says likely belongs to the real attacker, not a fictional cover story. The same prompts an attacker writes to get work done get retained somewhere, and in this case those prompts supplied identifying details the attacker almost certainly did not mean to hand over. Security teams building their own AI-assisted incident response should treat agent session logs, their own and an adversary's, as a forensic asset rather than an afterthought: CrowdStrike's report reads less like a malware teardown and more like a transcript review. CrowdStrike reached a phone number tied to the case; the man who answered said he had no knowledge of the matter, and Anthropic, South Korean police, and China's foreign ministry did not immediately respond to requests for comment, per the wire report.
Context and reactions
The disclosure lands days after South Korea's Financial Services Commission issued a public alert, on October 6, warning about scams linked to the breaches, two days before CrowdStrike's report went public, per Crypto Briefing. South Korean police opened a formal investigation this week, and President Lee Jae Myung called for stronger response measures, per Reuters. The case follows a separate incident Australia disclosed last month, in which an OpenAI autonomous agent breached a government health statistics portal in June, one of the first publicly known instances of an AI agent compromising a government system, according to the same Reuters report, via multiple outlets including Devdiscourse and The Vibes. Crypto Briefing frames the pattern as a sign that a single person with a laptop can now run intrusion work that previously needed a team, pairing a purpose-built attack agent with general-purpose assistants for research and scripting. South Korea's Financial Services Commission got ahead of the disclosure with its own public alert before CrowdStrike named the tooling, which suggests the regulator already had enough signal from the banks themselves to warn customers without waiting on an outside vendor's technical writeup.
What to watch next
Watch for whether Anthropic publishes any detail on what, if anything, its abuse-detection systems flagged in these sessions before CrowdStrike's report surfaced them. Also watch whether additional South Korean banks beyond Shinhan and KB Kookmin disclose their own customer counts as the police investigation continues, and whether CrowdStrike or another firm names the suspect formally rather than describing him by location and age alone.
Sources
- CrowdStrike says China-based suspect used AI tools in South Korean bank hacks: Reuters, via Business Day, Oct 8, 2026
- CrowdStrike says hacker behind South Korean bank attacks likely operated from China: Crypto Briefing
- AI agents used in cyberattacks targeting South Korean banks, CrowdStrike says: The Vibes
- CrowdStrike says China-based suspect used AI tools in South Korean bank hacks: Devdiscourse
