Local Chorus
Local news from local sources, read in your language.
Developing, 7× more reports
Verified

CrowdStrike says hacker behind Korean bank attacks may be a 26-year-old in Guangdong

🇰🇷 South Korea 19:24 IT & software Business9 Tech2 Official updated 46 min ago first reported by 서울신문

In short

Cybersecurity firm CrowdStrike said in a report released on October 7 that the attacker behind a series of breaches at seven South Korean financial firms may be a 26-year-old living in China's Guangdong province. The clues came from the attacker's own use of the AI coding tool Claude Code, and CrowdStrike said the attacker ran the operation from a Hong Kong server and mainly used Chinese AI model DeepSeek. CrowdStrike stressed this is an inference from circumstantial evidence, not a confirmed identification.

Read the full story 2 min read

Global cybersecurity firm CrowdStrike said in an analysis report released on October 7 local time that the person behind hacking attacks on South Korean financial institutions may be a 26-year-old living in Guangdong province, China. Yonhap reported it is the first clue to the attacker's identity in the case. CrowdStrike said this is an inference based on circumstantial evidence and not a definitive identification, Yonhap and Dong-A Ilbo reported. [ 2 , 5 ]

According to CrowdStrike, the clues surfaced while the attacker was using the generative AI coding tool Claude Code. The attacker asked it to write a security researcher resume describing their penetration-testing work, entering name initials, a Telegram account, education and place of residence. Bloter reported the record included residence in Maoming, Guangdong, and an age of 26, but that some details conflicted, such as a date of birth that did not match the age, so false information or another person's identity could not be ruled out. The attacker also asked where stolen Korean financial information is usually sold and how to find Korean-language Telegram data-selling channels, Yonhap reported. [ 2 , 3 , 5 ]

CrowdStrike said the same Telegram account name appeared in a session probing vulnerabilities in a Telegram-based NFT gift marketplace and in an attack targeting a Chinese payment platform. It said this suggests the same person may be involved but that the identity cannot be confirmed from the information so far. [ 2 , 3 ]

Per the report, the attacker used a Hong Kong IP address as main control infrastructure and ran the ARTEX instance used against Korea from a separate IP address, plus nine proxy IP addresses. ARTEX is an open-source agentic penetration-testing tool developed in China. The core AI driving it was DeepSeek's lightweight model v4.1-Flash, accessed through a third-party reseller, and the attacker also used Zhipu AI's GLM-5.3 and Grok 4.6 in Claude Code sessions, Yonhap reported. CrowdStrike assessed with medium confidence that the attacker, presumed to be a Chinese speaker, was financially motivated. [ 2 , 3 ]

The breaches were confirmed from late last month to early this month at Shinhan, KB Kookmin, Hana and BNK Busan banks, Yegaram and Welcome savings banks, and Hyundai Capital. Financial authorities said the attacking IP addresses differed but the same attacker appeared to switch IPs. Bloter reported the Financial Supervisory Service shared 28 deduplicated attack IPs with the sector on October 6, and that police have assigned 4 teams and 28 officers, opened a formal investigation and are pursuing international cooperation. Bloter said there has been no official police announcement naming the Guangdong individual as a suspect. [ 2 , 3 ]

Why it matters

Yonhap reported this is the first clue to the attacker's identity in the hacking of Korean financial institutions, which police are investigating. Bloter noted that the attacker's nationality and identity remain unconfirmed and that police have not named a suspect.

Key facts

  • CrowdStrike said in a report released on October 7 local time that the attacker may be a 26-year-old living in Guangdong province, China. [ 2 , 3 , 4 , 5 ]
  • CrowdStrike said the identification is an inference from circumstantial evidence, not a definitive identification. [ 2 , 5 ]
  • The clues were exposed when the attacker asked Claude Code to write a security researcher resume, entering name initials, a Telegram account, education and place of residence. [ 2 , 3 , 5 ]
  • The attacker used a Hong Kong-based server as main control infrastructure and carried out the attacks on Korea from a separate server, mainly using DeepSeek. [ 2 , 4 , 5 ]
  • Breaches were confirmed at seven financial firms: Shinhan, KB Kookmin, Hana and BNK Busan banks, Yegaram and Welcome savings banks, and Hyundai Capital. [ 2 ]
  • CrowdStrike assessed with medium confidence that the attacker was financially motivated. [ 2 , 3 ]
  • Police have deployed 4 teams and 28 officers and opened a formal investigation under the Information and Communications Network Act, according to Bloter. [ 3 ]

Confirmed by several sources

  • CrowdStrike's October 7 report said the attacker may be a 26-year-old living in Guangdong province, China. [ 2 , 3 , 4 , 5 ]
  • The attacker used a Hong Kong-based server as main control infrastructure and used Chinese AI model DeepSeek. [ 2 , 4 , 5 ]
  • The identifying details were exposed when the attacker asked Claude Code to write a security researcher resume. [ 2 , 3 , 5 ]
  • The attacker asked the AI where stolen Korean financial information could be sold. [ 2 , 3 , 5 ]
  • CrowdStrike assessed financial motivation with medium confidence. [ 2 , 3 ]

Still unclear

  • Whether the Guangdong 26-year-old is actually the attacker. CrowdStrike called it an inference, not a definitive identification, and police have not named a suspect.
  • Whether the personal details entered into Claude Code are genuine. Bloter reported the date of birth and age did not match, so false or borrowed details cannot be ruled out.
  • Whether all the financial institution attacks were carried out by the same person. Bloter said this cannot be concluded from the evidence so far.
  • Whether stolen information was actually sold or profit made. Bloter reported this has not been confirmed.

What local media are saying

Official sourcesYonhap detailed the CrowdStrike report, including the Hong Kong server setup, DeepSeek and other models used, and the seven affected firms, while noting CrowdStrike's caveat. [ 2 ]
Technology mediaBloter emphasised that the identity is unconfirmed, pointed to inconsistencies in the personal details, and reported on the police investigation and the 28 attack IPs. [ 3 ]
Business mediaKukmin Ilbo, Chosun Ilbo and Dong-A Ilbo led with the Guangdong 26-year-old and the use of DeepSeek and a Hong Kong server, with Dong-A noting the attacker asked where to sell stolen data. [ 1 , 4 , 5 ]

Timeline, local time

  1. Kukmin Ilbo reports a clue to trace the financial-sector hacker: a 26-year-old in Guangdong using DeepSeek. [ 1 ]
  2. Yonhap publishes a detailed report on CrowdStrike's findings. [ 2 ]
  3. Bloter reports the identity remains unconfirmed and details the police investigation. [ 3 ]
  4. Chosun Ilbo reports the attacker used a Hong Kong server and DeepSeek. [ 4 ]
  5. Dong-A Ilbo reports the attacker looked into where to sell stolen data. [ 5 ]