CrowdStrike links South Korea bank breaches to 26-year-old suspect in China
Cybersecurity firm CrowdStrike reported that a 26-year-old suspect in China may be behind a wave of cyberattacks on South Korea's largest banks, leveraging open-source AI penetration software and large language models.

Cybersecurity firm CrowdStrike reported that a 26-year-old suspect operating from China may be responsible for a series of cyberattacks infiltrating South Korea's largest banks. In an analysis authored by CrowdStrike's Ashley Campion, the firm assessed that the threat actor was likely Chinese-speaking, financially motivated, and may have executed the campaign as a solo operator.[1][2][3][4][5][6][7][8][9]
The campaign targeted at least nine South Korean financial institutions, resulting in compromised customer information at Shinhan Bank and KB Kookmin Bank. Investigators tied the intrusions to Chinese-language prompts and discovered attempts by the attacker to gain access to Korean data-selling groups.[3]
CrowdStrike's technical review revealed the attacker deployed an advanced AI-driven workflow using ARTEX, an open-source agentic penetration tool, supported primarily by DeepSeek v4.1-Flash. The perpetrator also incorporated Zhipu AI's GLM-5.3 and Grok 4.6 during Claude Code sessions, likely accessing DeepSeek through the proxy service xcai[.]pro. Infrastructure tracking identified a two-server architecture consisting of a primary Hong Kong-based IP address alongside IP 38.244.50[.]120 hosting the ARTEX instance.[4][7]
Key facts
- CrowdStrike identified a 26-year-old suspect operating from China as the possible culprit behind cyberattacks on major South Korean banks.
- The hacking campaign targeted at least nine banks and compromised customer information at Shinhan Bank and KB Kookmin Bank.
- CrowdStrike's analysis by Ashley Campion assessed the perpetrator was likely Chinese-speaking, financially motivated, and may have operated alone.
- The attacker used the open-source penetration tool ARTEX backed by DeepSeek v4.1-Flash, which was likely accessed via the reseller xcai[.]pro.
- The threat actor supplemented operations with GLM-5.3 and Grok 4.6 in Claude Code sessions and utilized a Hong Kong IP alongside IP 38.244.50[.]120.
- Investigators linked the attack to Chinese-language prompts and attempts to gain access to Korean data-selling groups.
Sources · 7 sources
- RE
Reuters@ReutersPost on X ·
Suspect behind South Korea bank hacks may be 26-year-old in China, cybersecurity firm says https://t.co/VoL6FEAgIg https://t.co/VoL6FEAgIg
Open source - TS
The Straits Times@straits_timesPost on X ·
Suspect behind South Korea bank hacks may be 26-year-old in China, cybersecurity firm says https://t.co/G1ERWWH6En
Open source - AI
Analytics Insight@analyticsinmePost on X ·
𝐒𝐨𝐮𝐭𝐡 𝐊𝐨𝐫𝐞𝐚 𝐁𝐚𝐧𝐤 𝐇𝐚𝐜𝐤𝐬: 𝟐𝟔-𝐘𝐞𝐚𝐫-𝐎𝐥𝐝 𝐢𝐧 𝐂𝐡𝐢𝐧𝐚 𝐒𝐮𝐬𝐩𝐞𝐜𝐭𝐞𝐝 A 26-year-old China-based suspect may be behind a string of cyberattacks targeting South Korean banks. CrowdStrike says AI tools, Chinese-language prompts, and attempts to access Korean data-selling groups were linked to the campaign. At least nine banks were targeted, while customer information was compromised at Shinhan Bank and KB Kookmin Bank. #CyberAttack #SouthKorea #Cybersecurity #AI #Banking #China #analyticsinsight #analyticsinsightmagazine Read More 👇 https://t.co/SkHgmnauXI
Open source - TE
Techmeme@TechmemePost on X ·
Analysis: the hacker who targeted South Korean banks is likely Chinese-speaking, financially motivated, and used LLMs and open-source Chinese agentic tool ARTEX (Ashley Campion / CrowdStrike) (Visit Techmeme dot com for the link and full context!)
Open source - TS
The Straits Times@straits_timesPost on X ·
Suspect behind South Korea bank hacks may be 26-year-old in China: Crowdstrike https://t.co/YihN5p3kPb
Open source - RE
Reuters@ReutersPost on X ·
CrowdStrike says China-based suspect used AI tools in South Korean bank hacks https://t.co/1PmtB0Cp8U https://t.co/1PmtB0Cp8U
Open source - AC
Andrew Curran@AndrewCurran_Post on X ·
Last week some of South Korea's biggest banks were hit by a cyberattack. Thanks to a report from CrowdStrike tonight, we now know the entire hack may have been done by a single person. He used a combined stack of an open-source AI penetration tool named ARTEX, DeepSeek v4.1-Flash, GLM-5.3, Grok 4.6, and Claude Code.
Open source - CB
Crypto BriefingArticle ·
CrowdStrike says hacker behind South Korean bank attacks likely operated from China The incident highlights the rising threat of individual cybercriminals using advanced AI tools, prompting urgent calls for enhanced cybersecurity measures. The post CrowdStrike says hacker behind South Korean bank attacks likely operated from China appeared first on Crypto Briefing .
Open source - BL
Bloomberg@businessPost on X ·
The hacker suspected of infiltrating some of South Korea’s largest banks this month may have used AI tools to carry out the attacks from China, cybersecurity firm CrowdStrike says https://t.co/MFjiiUvzrV
Open source

