AI chat records point to China-based suspect in Korean cyberattacks

by Ryu Yuna Posted : October 8, 2026, 11:08Updated : October 8, 2026, 11:08
ATMs of Koreas major banks in downtown Seoul AJP Yoo Na-hyun
ATMs of Korea's major banks in downtown Seoul. AJP Yoo Na-hyun
SEOUL, October 8 (AJP) —The culprit behind the latest wave of cyberattacks on South Korean financial firms may be a 26-year-old living in China’s Guangdong province, according to U.S. cybersecurity firm CrowdStrike Wednesday.

CrowdStrike claimed it found the clues while examining servers linked to the attacks. They included records of the suspected hacker's interactions with Claude Code, an artificial intelligence (AI)-powered coding tool developed by Anthropic.

The records showed that the person had asked Claude to help write a resume describing past experience in identifying security weaknesses in computer systems. The request included personal details such as initials, a Telegram account, education history and a location.

The same username also appeared in separate activity involving a Telegram-based marketplace for non-fungible tokens (NFTs) and a suspected attack on a Chinese payment platform. CrowdStrike said the overlap suggested the same person may have been involved in these activities.

The records also offered clues to the attacker's motives. In other exchanges with Claude, the person asked where stolen Korean data was typically sold and how to find Korean-language Telegram groups trading such information.
 
An infographic shows the seven South Korean financial companies affected by recent cyberattacks the systems targeted and the scale of reported exposure as of Oct 4 2026 Source Financial authorities and industry reports
An infographic shows the seven South Korean financial companies affected by recent cyberattacks, the systems targeted and the scale of reported exposure as of Oct. 4, 2026. Source: Financial authorities and industry reports
The investigation also showed how the person combined overseas servers with AI-powered tools to target South Korean financial institutions.

The attacker was found to have used a server in Hong Kong to control the operation and a separate server running ARTEX, a Chinese-developed open-source tool designed to identify and test security weaknesses in computer systems. The ARTEX server was believed to have been used in the attacks on South Korean financial firms.

The person also used nine additional internet protocol (IP) addresses to change connection routes and make the attacks harder to trace.

The ARTEX tool mainly used DeepSeek's v4.1-flash, an AI model designed for faster, more efficient processing, accessed through a third-party provider rather than directly. The attacker also used other AI models, including GLM-5.3 from China's Zhipu AI and Grok 4.6, during separate interactions with Claude Code.

The findings come amid a series of cyberattacks on seven South Korean financial companies between late September and early October. The companies include Shinhan Bank, KB Kookmin Bank, Hana Bank and BNK Busan Bank, along with Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital.

Authorities suspect the same attacker may have switched IP addresses while using AI tools to carry out automated attacks against multiple institutions. Police are investigating after traces of ARTEX were found on a server linked to the bank attacks.