Hacker Asked Claude About Selling Data Stolen From Korean Banks
CrowdStrike said an unidentified attacker used AI tools to breach South Korean financial institutions from late September into early October. The cybersecurity firm said the campaign exposed customer data and involved Anthropic’s Claude, China-developed ARTEX, and other large language models.
CrowdStrike found Claude Code session histories and ARTEX files on infrastructure linked to the attacks. The attacker also asked Claude where stolen Korean data was commonly sold and sought Korean Telegram groups involved in data trading. The company assessed with moderate confidence that the operator was a Chinese speaker and financially motivated. Separate session records suggested the person may be 26 and based in Guangdong, China, but CrowdStrike said the identity remains unconfirmed.
The attacks targeted systems including a bank loan inquiry service and an employee mobile support system. Recent breaches at Shinhan Bank and KB Kookmin Bank have also raised concerns about customer data exposure. The case highlights how agentic AI tools can accelerate cyberattacks while creating new challenges for financial institutions and regulators.
Why it matters
AI-assisted attacks could increase the speed and scale of financial cybercrime. Banks may face higher security costs and greater customer data risks.


