The recent cyberattacks disrupting multiple South Korean banks may have been orchestrated by a young individual operating from China’s Guangdong province, according to an analysis by CrowdStrike.
- Suspect likely a Chinese-speaking 26-year-old in Guangdong
- Hacking utilized AI tools and Chinese penetration testing software
- South Korean banks affected include Shinhan and KB Kookmin
What happened
Multiple South Korean financial institutions, including major banks Shinhan and KB Kookmin, reported data breaches from cyberattacks occurring between late September and early October 2026. US cybersecurity firm CrowdStrike analyzed the incident and uncovered evidence pointing toward a 26-year-old suspect residing in Maoming, Guangdong province, China. The investigation focused on AI coding tool sessions and infrastructure linked to the attack campaign.
CrowdStrike noted the use of ARTEX, a new Chinese open-source penetration testing framework, combined with large language models in the hacker’s operations. Personal details such as a Telegram username, education background, and location were found within AI session prompts, helping to associate the attacker to related cyber activities including vulnerability research targeting both NFT marketplaces and Chinese payment platforms.
Why it matters
The case highlights a growing trend of cyberattacks leveraging AI technologies and readily accessible hacking tools, complicating attribution and raising the stakes for international cybersecurity defenses. Financial institutions remain prime targets due to the potential for significant disruption and financial gain.
Identifying the attacker as a likely financially motivated Chinese speaker operating from Guangdong underlines challenges in cross-border cybercrime enforcement. South Korea's government and security agencies must enhance cooperation and invest in advanced detection to counter AI-augmented threats as President Lee Jae Myung emphasized the need for strengthened cybersecurity measures following the breaches.
What to watch next
Further developments from South Korean authorities’ ongoing investigations will be critical in verifying CrowdStrike’s findings and potentially unearthing additional threat actor profiles or infrastructure. Monitoring if AI-based tools continue to play a central role in cyberattacks across the region is essential for anticipating and mitigating future risks.
Financial institutions in South Korea and nearby regions will likely increase investments in cybersecurity, focusing on countermeasures against AI-assisted hacking techniques and reinforcing defenses around critical infrastructure. International collaboration in exposing and prosecuting cybercriminals operating across borders, especially from jurisdictions like China, will also be an important dimension of the response.