Korea intensifies efforts to track hackers behind bank cyberattacks韩国加大力度追踪银行网络攻击背后的黑客
Authorities are stepping up efforts to identify the hackers behind an unprecedented series of artificial intelligence (AI)-assisted cyberattacks ta...

Authorities are investigating AI-assisted cyberattacks targeting major Korean financial institutions Thursday, while CrowdStrike identified a possible Chinese-speaking, financially motivated actor. The attacks affected at least five lenders last week and exposed personal information belonging to customers. Police are examining whether an individual or organized group was responsible, as financial authorities consider easing network separation rules to strengthen AI-based defenses.
CrowdStrike said the attacker used ARTEX, a Chinese-developed autonomous penetration-testing tool, with DeepSeek V4.1-Flash, GLM-5.3 from Zhipu AI and Grok 4.6 in separate Claude Code sessions.
A Claude Code session contained a possible profile of a security researcher from South China University of Technology in Maoming, Guangdong Province, but the information was inconsistent and remained unverified.
Police identified 28 IP addresses connected to the attacks and said most appeared to conceal the attacker’s actual traces.
Shinhan Bank said about 25,000 customers were affected, while KB Kookmin Bank reported 119 affected customers and Hana Bank reported exposure of information belonging to 89 customers.
The National Assembly’s Policy Affairs Committee approved summoning the heads of KB Kookmin, Shinhan, Hana, Woori and NH NongHyup banks for an Oct. 19 audit.
Published Oct 8, 2026 4:06 pm KST
China-based suspect possibly linked to recent hackings on Korean banks
Financial Services Commission Chairman Lee Eog-weon speaks during a parliamentary audit at the National Assembly in Seoul, Thursday. Yonhap
Authorities are stepping up efforts to identify the hackers behind an unprecedented series of artificial intelligence (AI)-assisted cyberattacks targeting Korea's major financial institutions, Thursday, as a global cybersecurity firm pointed to a possible suspect based in China.
CrowdStrike said in a report released the previous day that the threat actor was likely a Chinese speaker and financially motivated.
The firm assessed that the attacker may have been a Chinese-speaking individual, citing the use of ARTEX, a Chinese-developed autonomous penetration-testing tool and Chinese-language prompts observed during the attacks.
In its report, CrowdStrike suggested that the attacker primarily used DeepSeek's V4.1-Flash as the large language model backend for ARTEX, while also using GLM-5.3 from Chinese AI company Zhipu AI and Grok 4.6 in separate Claude Code sessions.
A key clue emerged from a Claude Code session in which the attacker asked the AI tool to draft a resume for a security researcher. The information entered into the session included an age of 26, an educational background at South China University of Technology and a location in Maoming, Guangdong Province, according to the report.
However, it remains unclear whether the information is genuine.
The individual had initially entered a September 2007 birth date, which would make the person 19 this year, before later listing the age as 26.
Yet these findings may provide early clues about the possible identity of the person behind the attacks as Korean law enforcement authorities accelerate their probe.
Police said they are investigating multiple possibilities, including whether the attacks were carried out by an individual or an organized group. They cautioned that an IP address alone cannot establish an attacker's whereabouts, as IP addresses can be routed through other locations.
Of the 28 IP addresses identified in connection with the attacks so far, most were found to have been used to conceal the attacker's actual traces, according to police.
A person walks past ATMs belonging to major banks in Seoul, Wednesday. Yonhap
The probe centers on a series of cyberattacks carried out last week that affected at least five lenders, including Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank and BNK Busan Bank.
Shinhan Bank reported that about 25,000 customers were affected, with names, phone numbers, annual income and loan limits exposed. KB Kookmin reported 119 affected customers, while Hana Bank said personal information belonging to 89 customers was exposed.
The attacks have also prompted calls for an overhaul of cybersecurity defenses across the financial sector.
Financial Services Commission Chairman Lee Eog-won acknowledged that the government's early response to AI-assisted cyberattacks had been inadequate.
"Even in some very basic areas, our response has been inadequate. We need to thoroughly review these issues and make changes," Lee said during a parliamentary audit on Thursday.
"To prevent attacks using AI, we ultimately have no choice but to use AI in defending them," he said, adding that the government is considering easing network separation rules to allow financial institutions to use AI more actively for cybersecurity.
Financial authorities have been discussing easing network separation rules for cybersecurity purposes since June, with the aim of allowing financial institutions to use external AI and security services to identify vulnerabilities more quickly.
The latest attacks have also prompted broader scrutiny of cybersecurity practices in the banking sector.
Earlier in the day, the National Assembly's Policy Affairs Committee approved a plan to summon the heads of the country's five major commercial banks — KB Kookmin, Shinhan, Hana, Woori and NH NongHyup — as witnesses for the Financial Supervisory Service parliamentary audit on Oct. 19.
Park Sang-hyuk, a ruling Democratic Party of Korea lawmaker and the committee's secretary, said the bank CEOs would be questioned about their responsibility for cybersecurity lapses.
"We will seek specific commitments from financial institutions to increase security investments and address vulnerabilities so that they view security not as a cost, but as an investment in providing better financial services," Park said.
周四,韩国多家大型金融机构遭到人工智能辅助网络攻击,当局正在对此展开调查。与此同时,CrowdStrike公司识别出一名可能以经济利益为目的、讲中文的攻击者。上周,至少五家贷款机构受到影响,客户个人信息遭到泄露。警方正在调查此次攻击是由个人还是有组织团伙所为,金融监管机构也在考虑放宽网络隔离规则,以加强基于人工智能的防御措施。
CrowdStrike 表示,攻击者使用了中国开发的自主渗透测试工具 ARTEX,并在不同的 Claude Code 会话中分别使用了 DeepSeek V4.1-Flash、智普人工智能的 GLM-5.3 和 Grok 4.6。
Claude Code 会话中包含一个可能来自广东省茂名市华南理工大学的安全研究人员的个人资料,但该信息前后矛盾,尚未得到证实。
警方已确认与攻击有关的 28 个 IP 地址,并表示其中大多数似乎都掩盖了攻击者的实际踪迹。
新韩银行表示约有 25,000 名客户受到影响,而 KB 国民银行报告称有 119 名客户受到影响,韩亚银行报告称有 89 名客户的信息泄露。
国会政策事务委员会批准传唤 KB 国民银行、新韩银行、韩亚银行、友利银行和 NH 农协银行的负责人,于 10 月 19 日接受审计。
发布于2026年10月8日下午4:06(韩国标准时间)
一名中国籍嫌疑人可能与近期韩国银行遭黑客攻击事件有关。
周四,金融服务委员会主席李玉元在首尔国会出席国会审计听证会并发表讲话。(韩联社)
周四,韩国当局正加紧努力,以查明针对韩国主要金融机构的一系列前所未有的人工智能 (AI) 辅助网络攻击背后的黑客。与此同时,一家全球网络安全公司指出,一名嫌疑人可能身在中国。
CrowdStrike 在前一天发布的一份报告中称,该威胁行为者很可能是讲中文的人,并且有经济动机。
该公司评估认为,攻击者可能是一名讲中文的人,理由是攻击者使用了中国开发的自主渗透测试工具 ARTEX,并且在攻击过程中观察到了中文提示。
CrowdStrike 在其报告中指出,攻击者主要使用 DeepSeek 的 V4.1-Flash 作为 ARTEX 的大型语言模型后端,同时还在单独的 Claude Code 会话中使用了来自中国人工智能公司智普人工智能的 GLM-5.3 和 Grok 4.6。
报告显示,攻击者在一次 Claude Code 会话中获取了关键线索。在会话中,攻击者要求该人工智能工具为一名安全研究人员撰写简历。输入的信息包括:年龄 26 岁,毕业于华南理工大学,居住地为广东省茂名市。
然而,目前尚不清楚该信息是否属实。
该用户最初输入的出生日期是 2007 年 9 月,这意味着他今年 19 岁,之后又将年龄改为 26 岁。
然而,随着韩国执法部门加快调查,这些发现或许能为揭露袭击幕后黑手的身份提供早期线索。
警方表示,他们正在调查多种可能性,包括攻击是由个人还是有组织的团伙实施的。他们提醒说,仅凭IP地址无法确定攻击者的位置,因为IP地址可以路由到其他位置。
警方表示,目前已查明与这些攻击有关的 28 个 IP 地址中,大多数都被用来掩盖攻击者的实际踪迹。
周三,一名行人走过首尔各大银行的自动取款机。(韩联社)
此次调查的重点是上周发生的一系列网络攻击,至少有五家贷款机构受到影响,其中包括新韩银行、KB国民银行、韩亚银行、Yegaram储蓄银行和BNK釜山银行。
新韩银行报告称,约有2.5万名客户受到影响,其姓名、电话号码、年收入和贷款额度等信息被泄露。KB国民银行报告称有119名客户受到影响,而韩亚银行则表示有89名客户的个人信息被泄露。
这些攻击也促使人们呼吁对整个金融行业的网络安全防御进行全面改革。
金融服务委员会主席李玉元承认,政府早期对人工智能辅助网络攻击的反应不足。
李显龙总理周四在国会审计会上表示:“即使在一些非常基础的领域,我们的应对措施也不够充分。我们需要彻底审查这些问题并做出改变。”
“为了防止利用人工智能进行攻击,我们最终别无选择,只能利用人工智能来防御攻击,”他说道,并补充说,政府正在考虑放宽网络隔离规则,允许金融机构更积极地利用人工智能进行网络安全保护。
自 6 月以来,金融监管机构一直在讨论放宽网络安全方面的网络隔离规则,目的是允许金融机构使用外部人工智能和安全服务来更快地识别漏洞。
最近的攻击事件也促使人们对银行业网络安全措施进行更广泛的审查。
当天早些时候,国会政策事务委员会批准了一项计划,传唤该国五大商业银行——KB国民银行、新韩银行、韩亚银行、友利银行和NH农协银行——的负责人,作为金融监督院10月19日国会审计的证人。
韩国执政党共同民主党议员、该委员会秘书朴相赫表示,将对银行首席执行官就网络安全漏洞的责任进行质询。
朴先生表示:“我们将寻求金融机构做出具体承诺,增加安全投资并解决安全漏洞,使他们将安全视为提供更好金融服务的投资,而不是成本。”