Live Prices
Regulation

Korean Bank Hacker Used Anthropic's Claude to Find Data Buyers, CrowdStrike Discovers

TheCryptoDesk Editorial · 2m read
Korean Bank Hacker Used Anthropic's Claude to Find Data Buyers, CrowdStrike Discovers

A hacker targeting South Korean financial institutions used Anthropic's Claude Code and Chinese open-source AI tools to compromise customer data and seek buyers on Telegram, according to an October 7 report by cybersecurity firm CrowdStrike.

South Korean Lenders Face Consecutive Data Leaks

A series of cyber intrusions impacted multiple major South Korean banking institutions between late September and early October. Shinhan Bank confirmed its security breach on September 30, revealing the following day that approximately 25,000 customers were affected through an exploited mobile loan application service.

  • Shinhan Bank: Exposed names, phone numbers, annual income, loan limits, and 66 resident registration numbers.
  • KB Kookmin Bank: Disclosed on October 2 that data on 119 customers leaked via an employee mobile system.
  • Hana Bank: Confirmed 89 affected customers.
  • BNK: Reported that records for 11 outsourced workers were compromised.

In response to the incidents, South Korean President Lee Jae Myung raised concerns over AI-assisted cyber threats during a Cabinet meeting, triggering a full-scale police investigation.

Open Server Logs Expose Hacker's Prompts and AI Tools

CrowdStrike uncovered session histories, configuration files, and memory logs left exposed on open directories hosted on a Hong Kong-based server. The attacker utilized ARTEX, an open-source agentic penetration testing tool built in China, powered by the DeepSeek v4.1-flash language model. Additional session logs showed interactions involving Zhipu AI’s GLM-5.3 and xAI’s Grok 4.6.

Logs revealed the intruder asked Claude where stolen South Korean breach data is typically traded and sought specific Korean Telegram groups operating in illicit data sales. Another prompt instructed the model to draft a security resume listing a Telegram handle, an age of 26 (after previously entering a 2007 birth date), and a location in Maoming, Guangdong. That same Telegram handle was previously observed probing a Telegram-based NFT gift marketplace for security flaws.

CrowdStrike assessed with moderate confidence that the adversary is a financially motivated Chinese speaker. Cyber risks involving digital assets and hacking remain a growing priority for global law enforcement, as seen when authorities convicted a crypto hacker in New York for laundering stolen funds.

Why It Matters

The integration of agentic AI frameworks like ARTEX with commercial language models shows how artificial intelligence lowers the technical barrier for cybercriminals executing multi-target intrusions. As automated pentesting tools become more accessible, traditional security perimeters face severe vulnerabilities from rapid, AI-driven exploitation. Regulatory bodies and financial institutions will likely need to enforce stricter controls on AI system access and endpoint security to prevent widespread automated breaches.

Read next