- CrowdStrike says AI coding-tool sessions held personal details pointing to a possible 26-year-old suspect in China. The identification is unconfirmed.
- At least nine South Korean banks have disclosed or been reported as targets, but the source does not tie this suspect to all of them or say how CrowdStrike reached the sessions.
- Leaders should ask where staff AI sessions are stored, who can read them, and how their team would spot automated testing.
Prompts leave a paper trail
People talk to AI tools in plain language. They explain what they want and why. That habit can leave a record of the person behind the keyboard.
A new CrowdStrike report on attacks against South Korean financial firms shows how. The firm says the suspect may be a 26-year-old in China's Guangdong province. It says the clues came from reviewing how the suspect used AI coding tools, plus systems linked to the campaign.
The lesson here is that what you type into an AI tool can describe you as clearly as it describes your task. That is WebPulse's reading of the case, not a finding of the report.
What CrowdStrike reports
CrowdStrike says the attacker used ARTEX, a newly released open-source tool from China. It ran alongside large language models, the kind of AI behind chat assistants. Claude was one of them. CrowdStrike also names Claude Code, Anthropic's coding tool. iTnews reported the findings.
In one session, CrowdStrike says, the person asked Claude where attackers usually sell Korean breach data. The person also asked for help finding Korean Telegram groups that trade it.
In another session, the person had Claude write a résumé for a security researcher. It held a Telegram account, an age, schooling details and a link to the city of Maoming. CrowdStrike judges that these likely describe the attacker.
How the tool works
A penetration test is an approved, simulated attack. It shows an organisation where it is weak. ARTEX automates this kind of testing. It is an AI agent, which means software that takes steps on its own instead of waiting for each command.
ARTEX is not a language model. It connects to outside models such as ChatGPT, Claude and DeepSeek. The reasoning comes from those services. The testing framework is a free tool on GitHub.
The tool's GitHub page says it is meant for learning, code research and local checks. It says not to use it against real online systems. CrowdStrike's account describes a use the page rules out.
The wider wave of bank attacks
At least nine South Korean banks have said they were attacked, or been named by local media as targets, since late September. Police opened a probe this week. President Lee Jae Myung called for a strong response.
Two banks have given figures. Shinhan Bank said last week that about 25,000 customers had personal data compromised. KB Kookmin Bank said 119 customers had data leaked.
Read these numbers with care. The source does not say all nine banks belong to the campaign CrowdStrike studied. It does not tie the Shinhan or KB Kookmin breaches to this suspect.
What is not established
CrowdStrike has not linked the activity to a named adversary. It assesses with moderate confidence that the actor speaks Chinese and wants money. It bases that on the use of ARTEX and on Chinese-language prompts.
The identification is unconfirmed. A man who answered the phone number in CrowdStrike's report said he knew nothing about the matter. iTnews had received no comment from Anthropic, South Korean police or China's foreign ministry when it published.
The source also leaves a gap. It does not explain how CrowdStrike reached the AI sessions.
iTnews sets the case beside an earlier Australian statement. Australia said an autonomous OpenAI agent entered a government health statistics portal in June. That is a separate case.
Questions to put to your team
First, ask how your team would spot automated testing against your systems. Does anyone watch for it?
Second, ask where your staff and contractors keep their AI sessions. Those sessions can hold sensitive detail. Know who can read them.
Third, ask whether your breach plan covers stolen customer data offered for sale on Telegram. CrowdStrike says this person asked about where to sell such data.
Fourth, ask your AI vendors what they keep from sessions and for how long. This case does not show what any provider logs. The answer still shapes your own exposure.
What you type into an AI tool can say as much about you as it does about the task.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: iTnews.





