A suspected China-based cybercriminal has allegedly targeted South Korean banks using an artificial intelligence coding tool to carry out cyberattacks, raising concerns about the growing use of AI in financial cybercrime. Cybersecurity firm CrowdStrike said the attacker used Claude Code, an AI-powered coding assistant, as part of a campaign that has targeted several banks since late September.
The suspected attacker, identified as a 26-year-old Chinese-speaking individual, was linked to the activity through information uncovered during an investigation into the campaign.
What Did CrowdStrike Discover?
CrowdStrike said its cybersecurity researchers identified a suspected China-based attacker who had been using AI-assisted tools in cyber operations targeting South Korean financial institutions.
The company said the attacker used Claude Code, a coding assistant developed by Anthropic, during the campaign.
Researchers identified details linked to the suspected attacker while examining AI coding-tool sessions and infrastructure associated with the hacking activity.
The findings suggest that AI coding tools are becoming part of cybercriminal operations, potentially allowing attackers to carry out technical tasks more quickly.
However, the information available does not establish that the AI system independently conducted the attacks.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
How Was AI Used in the Cyberattacks?
The suspected attacker reportedly used Claude Code as part of the cyberattack campaign against South Korean banks.
CrowdStrike described the case as an example of an attacker using AI to assist with malicious cyber operations.
Adam Meyers, CrowdStrike’s senior vice-president of counter-adversary operations, said the incident demonstrated how a human attacker could use artificial intelligence to conduct widespread attacks.
He said the technology could allow a single individual to target numerous organisations within a relatively short period.
The concern is that AI tools can increase the speed and scale of cyber operations, potentially reducing the time needed to prepare and execute attacks.
Meyers described the activity as an example of a human adversary leveraging AI agents to conduct widespread attacks.
Which South Korean Banks Were Targeted?
At least nine South Korean banks have disclosed or been reported as having been targeted by cyberattacks since late September.
The attacks prompted South Korean police to launch an investigation and President Lee Jae Myung to call for stronger response measures.
CrowdStrike’s findings have raised concerns about whether AI-assisted cyber operations could make such attacks more difficult for financial institutions to detect and prevent.
However, the available information does not establish that the suspected attacker was responsible for every reported incident involving the nine banks.
Investigators are continuing to examine the circumstances surrounding the cyberattacks.
Was Customer Information Compromised?
The incidents have also raised concerns about the security of customer information held by South Korean banks.
Shinhan Bank said personal information belonging to approximately 25,000 customers had been compromised.
KB Kookmin Bank reported that personal information relating to 119 customers had been leaked.
The disclosures highlight the potential consequences of cyberattacks against financial institutions, where customer records and other sensitive information may be exposed.
The available information does not establish that these reported data breaches were directly caused by the suspected attacker identified by CrowdStrike.
Why Are AI-Assisted Cyberattacks a Growing Concern?
The use of AI coding assistants in cyber operations presents a new challenge for organisations responsible for protecting financial systems.
Traditionally, sophisticated cyberattacks often require considerable technical knowledge, preparation and time.
AI-assisted tools can help users complete coding and other technical tasks more efficiently, potentially increasing the capabilities of malicious actors.
Meyers said the significance of the case lay in the ability of a human attacker to target many organisations in a short period using AI.
He warned that the use of such technology could allow attackers to expand their operations without requiring the same level of manual effort.
The incident has added to concerns about whether existing cybersecurity systems are sufficiently prepared to defend against attacks involving AI agents.
What Does This Mean for Banks and Cybersecurity?
The reported attacks underline the importance of protecting financial institutions against increasingly sophisticated cyber threats.
As attackers adopt AI-assisted tools, banks may face attempts that can be prepared and carried out more rapidly than conventional attacks.
The South Korean incidents have already prompted police investigations and calls for stronger response measures.
The disclosure of customer information at two banks also demonstrates the potential impact of security breaches on individuals whose personal details are held by financial institutions.
For cybersecurity teams, the case raises questions about their ability to identify AI-assisted attacks quickly and prevent attackers from gaining access to sensitive systems.
The investigation into the suspected attacker and the wider campaign remains significant as authorities assess the extent of the incidents.
The420 Takeaway: “One Hacker, AI Tools and Multiple Banking Targets”
The suspected use of Claude Code in attacks targeting South Korean banks highlights how artificial intelligence may increase the speed and reach of cybercriminal activity. CrowdStrike’s findings suggest that an individual attacker can potentially use AI assistance to target multiple organisations within a short period. With customer information already reported compromised in separate banking incidents, the case reinforces the need for financial institutions to strengthen their ability to detect, investigate and respond to emerging cyber threats.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics