BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Guides

CrowdStrike Suspects A 26-Year-Old In China Hacked Korean Banks With Claude Code

CrowdStrike said a suspected attacker behind recent South Korean bank hacks may be a 26-year-old in China who used Anthropic's Claude Code and a Chinese penetration-testing tool. Key Points:

AnonymousCryptoCompass newsroom
October 8, 2026
3 min read
NEWS
CrowdStrike Suspects A 26-Year-Old In China Hacked Korean Banks With Claude Code
CryptoCompass editorial visual for guides coverage.

CrowdStrike said a suspected attacker behind recent South Korean bank hacks may be a 26-year-old in China who used Anthropic's Claude Code and a Chinese penetration-testing tool.

Key Points:

  • CrowdStrike has not tied the campaign to a named group and rates its findings on the operator at moderate confidence.
  • A resume request in a Claude Code session listed an age of 26 and a location in Maoming, Guangdong.
  • At least nine South Korean banks have been targeted since late September, and the suspect's identity remains unconfirmed.

CrowdStrike Report Findings

The U.S. cybersecurity firm said in a report published Wednesday that it found personal details tied to the attacker while analyzing AI coding sessions and servers used in the campaign. The attacks ran from late September to early October.

Its analysts examined open directories on attacker-controlled servers that held Claude Code session histories, memory files and configuration files for ARTEX, an open-source penetration-testing agent developed in China. In one session, the user asked Claude to draft a security researcher resume. The prompt listed a Telegram account, an age of 26, an education entry for South China University of Technology and a location in Maoming, a city in Guangdong province.

CrowdStrike said the details likely belonged to the attacker but acknowledged they were difficult to link definitively. A man who answered a phone number listed in the report told reporters he had no knowledge of the matter.

Also Read:How Much Does Anthropic's CEO Make? IPO Filing Has The Answer

Claude Code, ARTEX Use

No named hacking group has been blamed. CrowdStrike described the operator as "likely a Chinese speaker and financially motivated," an assessment it rated at moderate confidence based on the Chinese-developed tool and Chinese-language prompts. ARTEX appeared on GitHub this year as a tool that connects to outside language models, and its page says it is meant for personal learning and should not be used against live systems.

The logs also hint at a profit motive.

The user asked Claude where stolen Korean data is typically sold and how to find Telegram groups that trade it. ARTEX ran mainly on DeepSeek v4.1-flash, while other Claude Code sessions drew on GLM-5.3 from Zhipu AI and Grok 4.6, and CrowdStrike expects attackers to keep adopting such tools to move faster.

South Korean Bank Breaches

At least nine South Korean banks have disclosed attacks or been named in local media reports since late September, prompting a police investigation this week and a call from President Lee Jae Myung for a robust response.

Shinhan Bank said personal information of about 25,000 customers was compromised through a loan broker inquiry service, while KB Kookmin Bank reported 119 customer records leaked from an employee work-support system. On Oct. 3, a Korea Financial Security Institute official confirmed that investigators traced Shinhan attack logs to ARTEX, adding that a hacker used the AI as a tool and it did not act alone.

Read Next:OpenAI's 722 AI Math Papers Are Public, Now Mathematicians Must Judge Them