American cybersecurity company CrowdStrike said the suspect behind cyberattacks on South Korean financial organizations carried out in late September and early October may be a 26-year-old resident of China's Guangdong province. In a report published on the company's website on Wednesday, October 8, the company said personal details linked to the suspect were identified while analyzing sessions of AI-powered coding tools. While studying infrastructure connected to the attack campaign, analysts linked traces left in those sessions to one another. According to Reuters, the person has not yet been positively identified — the conclusion rests on an assessment by CrowdStrike analysts, and the investigation is ongoing.

Suspect Traced Through a Claude Code Session

CrowdStrike specialists studying the attack-related infrastructure found a prompt in one Claude Code session requesting a resume for a security researcher. The prompt asked to describe the results of attack activity in the resume and included the Telegram account, age, education details, and an address in Maoming, Guangdong province. It was precisely these details — the account, the age indicator, the education information, and the specific address — that allowed analysts to link the session to a particular person.

The report says that based on those details, the company assessed that the suspect may be 26 years old and living in Maoming. Analysts compared the session data with infrastructure tied to the attack campaign and concluded that they are linked. However, CrowdStrike left it open that the person's exact identity has not yet been confirmed: this is a preliminary assessment, and no official identification has been made.

ARTEX and Large Language Models

According to the report, the attacker used the recently released Chinese-developed open-source penetration testing tool ARTEX alongside large language models. ARTEX is an open-source penetration testing tool; its recent release and Chinese development are specifically noted in the CrowdStrike analysis. The company determined that the attacker used the tool side by side with large language models — that is, actively used AI capabilities in the course of the attack.

CrowdStrike assessed the attacker, with "moderate confidence," as a Chinese-speaking individual likely driven by financial motives.

CrowdStrike assessed the attacker, with moderate confidence, as a Chinese-speaking individual likely driven by financial motives. — CrowdStrike

In an analysis published on the company's official blog, the company confirmed that the campaign was active from late September to early October 2026. The analysis, headlined "Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance," notes that the attacker used the ARTEX tool and large language models, and that he may be a Chinese-speaking individual with financial interests. In other words, the company repeated the same assessment in two sources — in both its report and the analysis on its official blog: moderate confidence, Chinese-speaking, likely financial motivation.

Investigation Continues in Seoul

Seoul officials are investigating cyberattacks that affected several financial organizations. The investigation began after banks reported data breaches and covers multiple financial institutions. Major banks such as Shinhan Bank and KB Kookmin Bank reported data leaks — and the official investigation began in the wake of those reports. The wave of attacks came in late September and early October, covering the same time period as the campaign CrowdStrike analyzed.

South Korean President Li Je Myong said Tuesday that early signs had emerged of AI being used in some hacking incidents. That statement aligns with the CrowdStrike report's conclusions: both sources point to the possible use of AI tools in the attacks.

What Remains Unknown

The most important open question at this stage is the suspect's identity. CrowdStrike itself acknowledged that the person has not been positively identified, and the conclusion about the 26-year-old Maoming resident is given as a preliminary assessment. Reuters also emphasizes this caution in its story: the person has not been officially identified. In the headline of the analysis on the company's official blog, the attacker is called an "unknown threat actor" — another sign that identification is not complete.

Full details on the exact scale of the attacks and the extent of the damage have not yet been published. The investigation in Seoul is ongoing, and officials have not disclosed additional details so far. CrowdStrike's assessment — moderate confidence — is also not a final conclusion but the result of a preliminary analysis based on available data.