Exposed AI logs may help identify hacker behind South Korean bank attacks
CrowdStrike researchers investigating attacks on South Korean financial institutions found exposed AI session logs that included a request to write a CV. The prompt may help identify the person behind the activity, but CrowdStrike says it cannot confirm that the details belong to the attacker. The case matters because the logs also document the use of AI tools during multiple intrusions.
The attacks affected at least five lenders, including Shinhan Bank, KB Kookmin Bank and Hana Bank. Shinhan said about 25,000 customers were affected; KB Kookmin and Hana reported 119 and 89 respectively. The logs linked activity to Claude Code and ARTEX, an open-source penetration-testing tool developed in China, while police investigate whether an individual or group was responsible. Bank chiefs are due to be summoned to a parliamentary audit on 19 October.
- Exposed AI logs included a CV-writing request that may point to an attacker.
- At least five South Korean lenders were targeted.
- Shinhan reported about 25,000 affected customers.
New here? Start with this
South Korean banks including Shinhan Bank, KB Kookmin Bank and Hana Bank have been hit by cyberattacks. Multiple financial institutions have been breached, affecting tens of thousands of customer accounts.
Security researchers discovered exposed records from artificial intelligence tools that were used during the attacks. The discovery is significant because these records may help identify the attacker and demonstrate how artificial intelligence is being used in cyberattacks against banks.
Police are investigating whether a single person or a group was responsible for the attacks. The breaches have prompted heightened attention to cybersecurity at South Korean financial institutions.
AI Art Asia Culture Cybersecurity Technology World
Read the full article at the source →
Originally published by The Register as “CrowdStrike finds possible bank hacker’s CV among exposed AI logs”.