A suspected cyberattacker behind intrusions into at least nine South Korean financial firms got caught in an unusual trap: his own chat history with an AI assistant.
Between late September and early October 2026, several South Korean banks suffered breaches targeting authentication weaknesses in legacy backend systems. Analysis by South Korean security firm Enki WhiteHat pinpointed server-side validation flaws that let an intruder reach restricted records. The operation moved fast because the attacker did not craft manual payloads from scratch. Security firm CrowdStrike reported that the operator deployed ARTEX, an open-source, automated penetration testing tool built in China that automates multi-target network assaults.
The intrusion unravelled when researchers stumbled upon exposed public directories left open on the attacker's own server. Sitting inside those unprotected folders were complete session logs from Anthropic's Claude Code.
The chat records revealed that the operator turned to Claude to help write a CV. In the prompt, the user asked the assistant to draft a resume highlighting his work as a security researcher, citing his unauthorized access into South Korean banks through ARTEX. Generating that document tied his personal identifiers straight to the operational logs.
Denials and Diplomatic Friction
The revelation quickly turned contentious. The 26-year-old identified through the server records disputed the findings, telling observers he works at a convenience store in China's Henan province and claims someone else framed him by planting his details.
The fallout reached government levels on Thursday. China's Foreign Ministry dismissed the research findings, calling them politically motivated.
"As a principle, China has always opposed and combated hacking activities in accordance with the law, and we are even more opposed to spreading false information for political purposes," Foreign Ministry spokesperson Mao Ning said during a briefing. Mao added that AI holds a deep impact on digital infrastructure, urging international bodies to establish unified cybersecurity protocols and increase cross-border dialogue.
Whether the individual named in the Claude Code files ran the campaign directly or became an unwitting scapegoat remains disputed by those involved. For now, South Korean financial regulators and international security teams continue tracing the network infrastructure behind the ARTEX attacks.
ADFiled by The AI Desk
Models, assistants and the companies and chips behind them, reported from what was released and what was claimed, with the difference kept clear.
More from this desk →
Be the first to comment
Join the argument. No password, just your email or a passkey.