BTC $82,434.81 -1.33%
ETH $2,535.01 -1.68%
BNB $760.78 -0.78%
XRP $1.40 -3.42%
SOL $113.18 -3.03%
TRX $0.3352 +0.43%
DOGE $0.0871 -1.90%
ADA $0.2500 -1.88%
BCH $293.92 -2.88%
LINK $13.00 -2.53%
HYPE $85.29 -4.12%
AAVE $171.46 -0.55%
SUI $1.11 -0.68%
XLM $0.1983 -2.48%
ZEC $1,206.48 -7.54%
AAPL $337.22 +0.09%
AMZN $259.20 +2.29%
GOOGL $354.08 +2.38%
MSFT $527.10 +0.05%
META $717.42 -2.48%
NVDA $235.55 -0.50%
TSLA $374.38 -0.74%
SNDK $1,674.64 +3.07%
INTC $110.71 -0.40%
SPCX $166.43 -1.32%
MU $1,073.57 +5.68%
AMD $637.86 +0.47%
BTC $82,434.81 -1.33%
ETH $2,535.01 -1.68%
BNB $760.78 -0.78%
XRP $1.40 -3.42%
SOL $113.18 -3.03%
TRX $0.3352 +0.43%
DOGE $0.0871 -1.90%
ADA $0.2500 -1.88%
BCH $293.92 -2.88%
LINK $13.00 -2.53%
HYPE $85.29 -4.12%
AAVE $171.46 -0.55%
SUI $1.11 -0.68%
XLM $0.1983 -2.48%
ZEC $1,206.48 -7.54%
AAPL $337.22 +0.09%
AMZN $259.20 +2.29%
GOOGL $354.08 +2.38%
MSFT $527.10 +0.05%
META $717.42 -2.48%
NVDA $235.55 -0.50%
TSLA $374.38 -0.74%
SNDK $1,674.64 +3.07%
INTC $110.71 -0.40%
SPCX $166.43 -1.32%
MU $1,073.57 +5.68%
AMD $637.86 +0.47%

artex

All
Article
Flash

Multiple financial institutions in South Korea suspected of being attacked by AI, clues about Claude Code's identity revealed

At the end of September and the beginning of October, at least seven financial institutions in South Korea experienced data breaches, including Shinhan Bank, Kookmin Bank, and Hana Bank. Approximately 25,000 customers of Shinhan Bank and about 40,000 customers of Yegaram Savings Bank were affected, with leaked information including names, phone numbers, annual income, and loan limits; no theft of funds has been discovered so far.The attacks primarily targeted loan inquiry services used by loan intermediaries and peripheral banking systems such as employee mobile office systems. Multiple attacks involved overlapping IP addresses, leading South Korean regulatory authorities to suspect they were carried out by the same attacker. On October 6, South Korean President Yoon Suk-yeol stated that these attacks may have utilized AI.On October 7, CrowdStrike reported that the attackers controlled the attack using a server located in Hong Kong, with another running the open-source AI penetration testing system ARTEX. Investigators obtained the ARTEX configuration files, Claude Code chat records, and AI memory files. The configuration indicated that the attackers primarily used DeepSeek v4.1-flash to drive ARTEX, also utilized Claude Code, and had previously called GLM-5.3 and Grok 4.6 in other sessions. The chat records showed that the attackers inquired about channels for selling the leaked data in South Korea and related Telegram trading groups, and instructed the AI to draft a resume for a security researcher that included information such as 26 years old, Maoming, Guangdong, South China University of Technology, and contact details, but the birth date did not match the age. CrowdStrike assessed that the attackers might be using Chinese and aimed for profit, but their true identity has not yet been confirmed.
app_icon
ChainCatcher Building the Web3 world with innovations.