CrowdStrike Finds Suspected Bank Hacker’s Resume in Exposed AI Logs
Summary
CrowdStrike researchers investigating attacks on South Korean financial institutions found exposed AI session logs that included operational details and a resume-writing request potentially identifying the attacker. The request referred to a person identified as “YY,” named a Chinese university and Guangdong location, and contained conflicting age information; CrowdStrike said it likely belonged to the attacker but could not confirm the link. The attacks reportedly affected at least five lenders: Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank, and BNK Busan Bank. Investigators said the attackers allegedly breached a loan-progress inquiry service at one institution and a mobile work-support system at another. The AI sessions were associated with ARTEX, a recently released open-source penetration-testing tool developed in China, and Claude Code. An exposed directory led researchers from a Chinese-language instruction file to a Hong Kong server containing session histories, configuration files, and AI memory files documenting the targeting. The resume request included a Telegram username that also appeared in activity involving a possible Chinese payment platform and a Telegram-based NFT gift marketplace. CrowdStrike said the combination of agentic AI tools and traditional offensive techniques could help a financially motivated actor conduct multiple intrusions in a shorter period, while warning that adversaries are likely to keep experimenting with AI. Police are investigating whether an individual or an organized group was responsible. Shinhan reported about 25,000 affected customers, while KB Kookmin and Hana reported 119 and 89 respectively. South Korean lawmakers approved plans to summon the heads of five major commercial banks for an October 19 parliamentary audit on cybersecurity lapses.