Korean Bank Hacker Asked Claude Where to Sell the Stolen Data, CrowdStrike Says
Key Summary
A suspected Korean bank hacker asked an AI coding tool where to sell stolen breach data, according to CrowdStrike. The attacker used a Chinese-built AI penetration testing tool and several language models, including ARTEX and DeepSeek. Several South Korean banks have disclosed customer data leaks, with the intruder slipping past identity checks on a mobile service loan agents use to track applications.
Attack Pattern
The suspected attacker behind South Korea's recent bank breaches asked an AI coding tool where breach data sells. CrowdStrike found the request in session logs stored in open directories on attacker-controlled servers. Several South Korean banks have disclosed customer data leaks over the past week.
Analysis
CrowdStrike's October 7 report says the campaign used a Chinese-built AI penetration testing tool and several language models. The attacker worked with ARTEX, an open-source agentic penetration testing (pentesting) tool developed in China. An IP address ran the ARTEX instance that CrowdStrike says was likely behind the Korean attacks.
Motivation
The attacker also asked about Telegram markets where breach data sells. CrowdStrike has not named any group behind the campaign. It assessed with moderate confidence that the actor is likely a financially motivated Chinese speaker.
Implications
CrowdStrike said AI tooling can help a financially motivated actor run multiple intrusions in a short span. Previously, Anthropic also said that AI now performs advanced attack tasks for low-skill hackers. CrowdStrike expects attackers to keep experimenting with AI tools.