CrowdStrike says South Korean bank hacker likely operated from China
In brief
- CrowdStrike said the hacker behind South Korean bank attacks likely operated from China.
- CrowdStrike didn't tie the suspect to any organized hacking group and cited likely financial motives.
- ARTEX was among the attacker's tools, plus Claude and Claude Code for research and scripting, CrowdStrike said.
- Seven to nine institutions were hit, Crypto Briefing reported; Shinhan cited about 25,000 affected customers.
What CrowdStrike's report says
According to CrowdStrike's analysis, as reported by Crypto Briefing, the threat actor was likely a 26-year-old Chinese-speaking man based in Maoming, a city in Guangdong province. The firm didn't tie him to any organized hacking group.
It also characterized the campaign as potentially motivated by financial gain (rather than espionage or politics). The attacker's infrastructure included a control server located in Hong Kong, according to the report.
All of that is CrowdStrike's assessment. The firm's own wording is "likely."
The AI angle
CrowdStrike said the attacker relied on ARTEX, a Chinese-developed penetration-testing agent. The report said the attacker also used other AI models, including Claude and Claude Code, for research and scripting tasks.
That's the part CrowdStrike chose to put front and center. The firm framed the incident as part of a trend in which individual actors use sophisticated AI technology to commit cybercrime that once required far more resources. In other words, it's a story about what one person with the right tooling can now pull off, at least in CrowdStrike's reading of the evidence.
Banks, regulators and police
Per Crypto Briefing's account, the breaches touched at least seven to nine South Korean banks and financial entities, and data exfiltration (meaning information was actually copied out of the institutions' systems) was confirmed in several cases. Shinhan Bank reported approximately 25,000 affected customers, while KB Kookmin Bank confirmed 119, the outlet reported.
South Korea's Financial Services Commission issued an alert on October 6, two days before CrowdStrike's report went public, warning the public about potential scams linked to the breaches. South Korean police have launched a formal investigation into the attacks, and President Lee Jae Myung has called for strengthened cybersecurity measures, according to the same report.
Frequently asked questions
What AI tools did CrowdStrike say the South Korean bank hacker used?
CrowdStrike said the attacker relied on ARTEX, a Chinese-developed penetration-testing agent. According to the report, the attacker also used other AI models, including Claude and Claude Code, for research and scripting tasks.
How many South Korean banks and customers were affected by the attacks?
Crypto Briefing reported that the breaches touched at least seven to nine South Korean banks and financial entities, with data exfiltration confirmed in several cases. Shinhan Bank reported approximately 25,000 affected customers and KB Kookmin Bank confirmed 119, according to the outlet.
Who does CrowdStrike think was behind the attacks?
CrowdStrike assessed that the threat actor was likely a 26-year-old Chinese-speaking man based in Maoming, Guangdong province. The firm didn't tie him to any organized hacking group and said the campaign was potentially motivated by financial gain rather than espionage or politics.


