Suspect behind South Korea bank hacks may be 26-year-old in China, cybersecurity firm says

Reuters | October 08, 2026 at 01:28 AM UTC
Bearish 77% Confidence Majority Agreement
Read Original Article

Key Points

  • The attacker allegedly used ARTEX, a Chinese-developed open-source penetration testing tool, alongside large language models, and CrowdStrike assesses with 'moderate confidence' the actor is Chinese-speaking and financially motivated
  • Personal details including a Telegram account, age, education background, and location in Maoming, Guangdong were found in a Claude Code session requesting creation of a security researcher resume describing the hacking results
  • South Korean President Lee Jae Myung said signs emerged that AI was used in the hacking incidents and called for heightened cybersecurity measures as police launched an investigation

AI Summary

Summary: South Korea Bank Cyberattacks Linked to Suspected Chinese Hacker

U.S. cybersecurity firm CrowdStrike has identified a potential suspect behind recent cyberattacks on South Korea's financial sector—a 26-year-old individual allegedly based in Maoming, Guangdong province, China.

Key Details:

The attacks targeted multiple South Korean financial institutions, including Shinhan Bank and KB Kookmin Bank, occurring between late September and early October. CrowdStrike's investigation uncovered personal details linked to the suspect through analysis of AI coding-tool sessions and attack infrastructure.

Technical Findings:

The attacker utilized ARTEX, a recently released Chinese-developed open-source penetration testing tool, combined with large language models (LLMs). CrowdStrike assessed with "moderate confidence" that the actor is a Chinese speaker and likely financially motivated.

Evidence emerged from a Claude Code session containing a request to create a security researcher resume documenting the hacking activity. This prompt included identifying details such as a Telegram account, age, educational background, and the Guangdong location. The same Telegram username appeared in other cyber activities, including vulnerability research on a Telegram-based NFT marketplace and a suspected attack on a Chinese payment platform.

Official Response:

South Korean authorities have launched investigations into the data breaches. President Lee Jae Myung acknowledged on Tuesday that AI appeared to have been used in the hacking incidents and called for enhanced cybersecurity measures.

Caveats:

CrowdStrike cautioned that while the personal details likely belong to the responsible actor, currently available information cannot definitively confirm the attacker's identity. South Korean police have not yet commented on the findings.

Model Analysis Breakdown

Model Sentiment Confidence
GPT-5-mini Bearish 80%
Claude 4.5 Haiku Bearish 72%
Gemini 2.5 Flash Neutral 80%
Consensus Bearish 77%