Chinese Media Report Guangdong Link to South Korea Bank Hacks

Chinese-language outlets highlight CrowdStrike findings as Beijing offers no official response to alleged China-based cyberattack

October 8, 2026 at 10:34 AM
icon-facebook icon-twitter icon-whatsapp

Key Points

  • Suspect’s identity and location remain unconfirmed
  • Hacker allegedly used Chinese-developed ARTEX and DeepSeek
  • South Korean police are investigating breaches at seven financial firms

SEOUL: Chinese-language media have reported allegations that a hacker possibly based in China’s Guangdong province used artificial intelligence tools to attack South Korean financial institutions, while China’s Foreign Ministry has not publicly commented on the findings.

China Press reported on Thursday that a CrowdStrike investigation had identified a possible 26-year-old suspect from Guangdong. The Chinese-language service of South Korea’s Yonhap News Agency, in a report by Yoon Hong-kyung, stressed that the person’s identity had not been established.

Chinese technology publication Digital Today, in a report by Hwang Chi-gyu, likewise described the suspected attacker as a Chinese-language user and highlighted the use of Chinese-developed AI technology.

There has been no public response from China’s Foreign Ministry to the allegations. Reuters said the ministry did not immediately respond to its request for comment.

CrowdStrike has not attributed the campaign to a named hacking group and said it assessed that the attacker was likely a Chinese speaker and financially motivated. The assessment was based on moderate confidence.

CrowdStrike said the attacks against South Korean financial organisations were carried out from late September to early October and involved ARTEX, an open-source AI-powered penetration-testing tool developed in China, together with several large language models.

The cybersecurity firm said its investigators found Claude Code session histories, ARTEX configuration files and other material on servers linked to the attacks. One server in Hong Kong appeared to be the attacker’s main infrastructure, while another hosted ARTEX and was likely used in attacks against South Korean financial institutions.

The ARTEX system primarily used DeepSeek v4.1-flash as its large language model, while GLM-5.3 from China’s Zhipu AI and Grok 4.6 were also used in separate Claude Code sessions, CrowdStrike said.

The use of Chinese-developed technology does not by itself establish that the attacker was operating from China or had any connection with the Chinese government. ARTEX is an open-source tool designed for penetration testing and was developed by a Chinese security engineer using the online handle “Autumn.” Its GitHub documentation says it is intended for personal learning, code research and local technical verification and should not be used for real-world attacks against online systems.

Clues Point to Possible Guangdong Suspect

CrowdStrike said one Claude Code session contained a request to prepare a security researcher résumé that included an age of 26, an educational background at South China University of Technology and a location in Maoming, a city in Guangdong.

The same session contained other personal information, including a Telegram account. CrowdStrike found that the account had appeared in other cyber-related activity, but said the available evidence was insufficient to conclusively establish that the information belonged to the person behind the South Korean attacks.

The cybersecurity firm said the attacker also asked Claude where stolen South Korean data was typically sold and sought help locating Telegram groups involved in trading Korean data. Those exchanges provided evidence of a possible financial motive.

CrowdStrike said the campaign involved traditional offensive cyber capabilities alongside AI agents, allowing the attacker to conduct multiple intrusions in a relatively short period.

South Korea Probes Multiple Breaches

The investigation follows a series of cyberattacks affecting South Korean financial institutions, including Shinhan Bank, KB Kookmin Bank, Hana Bank and other financial companies.

CrowdStrike said the compromised systems included a loan inquiry service used by financial brokers at one bank and an employee mobile work-support system at another.

South Korean authorities have launched an investigation into the attacks, which have raised concerns about the use of AI to automate cyber intrusions and move more rapidly between targets.

South Korean financial authorities have also taken measures to strengthen security controls and prevent secondary crimes involving leaked personal information.

The case comes as governments and cybersecurity companies increasingly examine how AI agents can be used for offensive cyber operations. The South Korean attacks are particularly notable because they appear to have combined an agentic penetration-testing tool with several AI models rather than relying on a single system.

For now, the evidence establishes a connection between the attacks and Chinese-developed technology, as well as clues pointing to a possible Chinese-speaking operator. It does not establish Chinese government involvement, nor has CrowdStrike conclusively identified the alleged attacker.

The compromised systems included a loan-progress inquiry service used by financial brokers at one South Korean bank and a mobile work-support system for employees at another, CrowdStrike said.

The attacks formed part of a wider series of breaches affecting South Korean financial institutions, including Shinhan Bank, KB Kookmin Bank and Hana Bank.

Chinese AI technology at the centre

CrowdStrike said it identified two key servers during its investigation. One, located in Hong Kong, appeared to be the attacker’s main infrastructure, while another hosted ARTEX and was likely used in attacks against South Korean financial organisations.

The ARTEX installation primarily used DeepSeek v4.1-flash as its large language model. GLM-5.3 from China’s Zhipu AI and Grok 4.6 were also used through Anthropic’s Claude Code, CrowdStrike said.

The findings highlight how AI systems developed for legitimate cybersecurity and software-development purposes can be combined with other tools to automate or accelerate criminal activity.

CrowdStrike also found a Claude Code session in which the user asked the AI to prepare a security researcher résumé containing personal details, including an age of 26, an educational background at South China University of Technology and a location in Maoming, Guangdong.

The company cautioned that these details did not definitively identify the attacker.

A Telegram username associated with the résumé request also appeared in other cyber activity. However, CrowdStrike said the evidence was insufficient to conclusively establish the person’s identity.

The investigation found further evidence of a possible financial motive. The attacker asked Claude about marketplaces where stolen South Korean data could be sold and about Telegram groups involved in trading such information.

South Korean authorities are investigating a series of cyberattacks against financial institutions and have ordered banks and other financial companies to inspect systems exposed to external access and strengthen authentication and access controls.

Financial authorities also issued a consumer alert over possible phishing scams and loan fraud following the breaches, warning that stolen personal information could be used for secondary crimes.

South Korean President Lee Jae Myung said earlier this week that there were signs AI models had been used in some of the bank attacks and called for a rapid investigation and stronger cybersecurity measures.

CrowdStrike’s findings add a new dimension to the investigation by pointing to the use of Chinese AI technology and a possible China-based operator. However, the company did not say that the attacks were directed or sponsored by the Chinese government.

South Korean regulators have also stressed that no confirmed evidence shows banking account information was transferred to China and have warned against spreading unverified claims about where stolen data may have gone.

The case illustrates a growing challenge for cybersecurity authorities: AI tools developed in China, the United States, and elsewhere can be accessed globally, so the technology’s origin alone is insufficient to identify who is behind an attack.

icon-facebook icon-twitter icon-whatsapp