Security agency: Hackers used LLM combined with AI penetration tools to attack South Korean financial institutions, leaking data of approximately 68,000 people
Odaily reports that security firm CrowdStrike released an intelligence report stating that an unidentified hacker, between late September and early October, combined large language models (LLMs) with the domestic open-source AI penetration testing tool ARTEX to launch targeted cyberattacks against multiple South Korean financial institutions and steal data.
After analyzing the hacker's exposed open directory, it was found that they employed a dual-server architecture centered on a Hong Kong IP, and used models including Claude Code, GLM-5.3, Grok 4.6, and DeepSeek v4.1-flash accessed through an API proxy to orchestrate the attack process. The hacker also asked Claude how to monetize the leaked South Korean data in Telegram groups. According to estimates by South Korean media, at least seven South Korean financial institutions were attacked, including KB Kookmin Bank, Shinhan Bank, and Hana Bank, with personal data of approximately 68,000 people leaked, involving sensitive information such as annual income and loan limits.
