What CrowdStrike found
A string of breaches at South Korean financial institutions last week prompted a deep dive by US cybersecurity firm CrowdStrike, which says the suspected attacker may have leaned on AI while operating from China. Their analysis indicates the individual used Anthropic's Claude for research and to compose a résumé that appears to belong to the perpetrator, identifying a 26-year-old located in Guangdong.
The digital trail and AI stack
Investigators are pulling clues from the attacker's own AI activity. CrowdStrike says it could not definitively identify the person, but relied on logs from Claude Code sessions and additional online artifacts. IP addresses linked to the breaches hosted open directories that showed Claude activity, and the suspected attacker likely targeted Korean lenders using a Hong Kong-based IP address.
The review suggests possible use of DeepSeek's V4.1 Flash model, introduced last month, together with tools put out by Z.ai and Elon Musk's x.AI. Cybersecurity experts also highlighted ARTEX, an AI tool developed in China for defensive purposes, as part of the attacks. The individual requested Claude's assistance in locating Korean data sales groups on Telegram. While Claude is banned in China, it can still be accessed through virtual private networks.
Attribution in cyberattacks shapes sanctions, regulation, and bank costs. Market Briefs covers financial security free every morning.
What officials are saying
South Korean police are investigating, with estimates suggesting the intrusions affected around 68,000 people. On Sunday, the Financial Services Commission said it had no evidence that any financial account data went to China. One angle working in investigators' favor: the open nature of AI models is offering breadcrumbs they can follow.
Why this matters for your money
Banks facing AI-boosted intrusions is a reminder that data risks evolve as the tools do. The silver lining for everyday customers is that regulators are already on the case and, so far, have not seen proof of account information flowing to China. Expect tougher questions for banks about how they spot unusual access, lock down customer records, and vet the tech they rely on. When your bank can show its work on those basics, your savings tend to sleep better.
Who is behind a breach matters as much as the breach itself. Get the free Market Briefs daily newsletter and follow it.
