cd /news/ai-safety/crowdstrike-finds-possible-bank-hack… · home › topics › ai-safety › article
[ARTICLE · art-147623] src=machinebrief.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

CrowdStrike finds possible bank hacker's CV among exposed AI logs

CrowdStrike researchers found exposed AI session logs containing a resume-writing prompt that may identify the attacker behind intrusions at five South Korean lenders, including Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank, and BNK Busan Bank, according to a report published Wednesday by analyst Ashley Campion. The prompt named "YY," listed a Chinese university and a Guangdong location, and gave conflicting age information of 26 versus a September 2007 birth date; CrowdStrike said it cannot definitively establish the details belong to the attacker. The attacks used the open source Chinese penetration-testing tool ARTEX alongside Claude Code, and Shinhan Bank reported about 25,000 customers affected while KB Kookmin and Hana reported 119 and 89 respectively; South Korean lawmakers have approved plans to summon the heads of five major commercial banks to an October 19 parliamentary audit.

read2 min views1 publishedOct 8, 2026
CrowdStrike finds possible bank hacker's CV among exposed AI logs
Image: Machinebrief (auto-discovered)

Source:

The Register Suspected Chinese speaker used Claude Code and agentic pentesting tool ARTEX in attacks on South Korean lenders

CrowdStrike researchers investigating attacks on South Korean financial institutions found exposed AI session logs containing operational details and a resume-writing request that may identify the attacker. In a report published Wednesday, analyst Ashley Campion said the prompt named "YY," listed a Chinese university and a location in Guangdong, and gave conflicting age information: 26, but initially a birth date in September 2007. CrowdStrike considers the details likely to belong to the attacker but says it cannot definitively establish that connection. The attacks affected at least five lenders, including Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank, and BNK Busan Bank, according to The Korea Times. In one case, the attackers allegedly breached a loan progress inquiry service and in another, they gained access to a mobile work-support system. The researchers found references to YY in AI sessions associated with activity involving ARTEX, a recently released open source penetration-testing tool developed in China and used in the attacks alongside

ClaudeCode. Researchers examined an exposed directory on a server associated with the attacks. A Chinese-language instruction file led them to another server in Hong Kong, where they found session histories, configuration files, and AI memory files documenting the targeting. The resume prompt included a Telegram username that also appeared in activity targeting a possible Chinese payment platform and in Claude Code sessions seeking vulnerabilities in a Telegram-based NFT gift marketplace, CrowdStrike said. "The use ofagentic AItooling alongside traditional offensive capabilities highlights the continued evolution observed by CrowdStrike in adversarial tradecraft," Campion said. "This activity demonstrates how AI tooling can enable a financially motivated threat actor to conduct multiple intrusions within a short time span. CrowdStrike Intelligence assesses that adversaries will likely continue to experiment with implementing AI tooling in their operations to enhance their operational tempo and capabilities." Police are investigating whether an individual or an organized group carried out the attacks. Shinhan Bank reported that about 25,000 customers were affected, while KB Kookmin and Hana reported 119 and 89 respectively. Lawmakers have approved plans to summon the heads of five major commercial banks to an October 19 parliamentary audit to answer questions about cybersecurity lapses. ® Get AI news in your inbox

Daily digest of what matters in AI.

── more in #ai-safety 4 stories · sorted by recency
── more on @crowdstrike 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/crowdstrike-finds-po…] indexed:0 read:2min 2026-10-08 · —