“Financial-sector hacker used AI to find where personal data is sold”
- Input
- 2026-10-08 10:05:53
- Updated
- 2026-10-08 10:05:53

[Financial News] A hacker targeting South Korean financial firms has been found to have used generative artificial intelligence (AI) to search for places where leaked Korean data is sold. After attacking financial institutions with an AI-based penetration-testing tool, the attacker also asked AI about channels for trading the stolen information.
Clues that could help identify the attacker have also emerged, lending weight to the possibility that the hacking was motivated by financial gain.
Global cybersecurity company CrowdStrike said in an analysis report released on the 7th (local time) that its review of records of a hacker’s use of generative AI in an attack on South Korean financial institutions showed that the attacker used ARTEX, an open-source AI penetration-testing tool developed in China, and asked the generative AI Claude where leaked Korean data is typically sold. The attacker also instructed AI to find groups on Telegram related to the sale of Korean data.
However, it has not been confirmed whether any attempt was made to sell personal information or whether any actual transaction took place.
CrowdStrike found records of conversations with Claude Code, Claude’s coding tool, as well as ARTEX configuration files, in a public directory on a server managed by the attacker. The analysis found that the attacker used a server based in Hong Kong as the main attack infrastructure and ran ARTEX on a separate server. The attacker connected DeepSeek, a Chinese AI model, to ARTEX and was found to have used several large language models (LLMs), including GLM and Grok, for additional tasks.
Clues that could help identify the attacker were also found. The attacker entered initials, a Telegram account, education, place of residence, and other details while asking Claude Code to write a résumé for a security researcher that included penetration-testing results achieved using ARTEX.
The records included information indicating that the person was 26 and lived in Maoming, Guangdong Province, China.
Notably, the Telegram account used to write the résumé also appeared in records related to other cyberattacks. The same account name was found in a session examining vulnerabilities in a Telegram-based non-fungible token (NFT) gift-trading platform, as well as in an attack believed to have targeted a payment platform in China. CrowdStrike said these circumstances suggest the personal information may belong to the attacker, while noting that the identity cannot be confirmed based on the information currently available.
[email protected] Hye-rim Choi Reporter