CrowdStrike: Suspect in South Korean Bank Hacks Asked Claude Where to Sell Stolen Data
- —Open server directory exposed Claude Code logs, ARTEX config files and a Claude memory file
- —Attacks originated from a Hong Kong server running ARTEX, mainly using DeepSeek v4.1-flash
- —Shinhan Bank confirmed a breach affecting 25,000 customers, including 66 resident registration numbers
- —KB Kookmin Bank reported 119 victims, Hana Bank 89 and BNK 11
Why it matters: The report shows how AI tools accelerate attacks on banks and ease the sale of stolen data, raising pressure on South Korean regulators.
Source: BeInCrypto KR