China-based hacker used AI agent, Claude Code to target South Korean banks: CrowdStrike

Shinhan Bank said that personal information of their 25,000 customers was leaked

By
Web Desk
|
China-based hacker used AI agent, Claude Code to target South Korean banks: CrowdStrike
China-based hacker used AI agent, Claude Code to target South Korean banks: CrowdStrike

A US cybersecurity company CrowdStrike has alleged that the cyberattacks on South Korean banks were orchestrated by a 26-year-old, who used a locally developed AI agent alongside Anthropic’s Claude Code to secure access into the banks’ systems.

CrowdStrike says that it discovered the personal details of the hacker while analysing the AI coding tool sessions and infrastructure used in the hacking campaign and revealed that the suspect was likely operating from China’s Guangdong province.

Earlier, South Korean police launched a probe after at least nine banks revealed that their systems were targeted in a hacking attempt in late September. The attacks have prompted the South Korean President Jae Myung to call for robust response measures.

Shinhan Bank said that personal information of their 25,000 customers was leaked while KB Kookmin Bank revealed that personal information of 119 customers was compromised during the hacking attempt.

“It was an example of a human adversary leveraging AI agents to conduct widespread attacks,” Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told reporters via a telephonic conversation on Thursday.

He said, “This is significant because it allows one human to target many customers in a very short period of time using the power of AI.”

CrowdStrike did not name the attacker directly but suspected that a Chinese speaker was involved who used China’s locally developed open-source penetration tool ARTEX to get access into South Korean banks.

The attacker reportedly asked Claude Code to prepare a cybersecurity resume and supplied personal information, including an age of 26, educational background and a location in Maoming, Guangdong. CrowdStrike cautioned that these details could not definitively identify the hacker.

The US cybersecurity company alleged that the attacker likely wanted to sell the personal data of customers as he asked Claude to help them find the right market for the data stolen through breach.