SEOUL — Global cybersecurity firm CrowdStrike has identified a 26-year-old living in Maoming, Guangdong province, China, as the primary suspect behind a recent series of high-profile cyberattacks targeting major South Korean financial institutions.
The breach, which affected leading institutions including Shinhan Bank and KB Kookmin Bank, compromised sensitive customer data and triggered nationwide security alerts.
How the Suspect Exposed Themselves
According to CrowdStrike's intelligence report, the attacker leveraged AI coding assistants—including Anthropic's Claude Code and a Chinese AI tool named ARTEX—to execute the intrusion and analyze stolen datasets.
However, the perpetrator accidentally revealed their identity through the AI tools:
AI Resume Prompt: In an inadvertent blunder, the hacker instructed Claude Code to build a professional "security researcher resume" highlighting achievements from the South Korean bank penetration.
Digital Footprint: The prompt exposed personal identifying information, including a linked Telegram handle, age (26), educational background, and a specific location in Maoming, Guangdong.
AI Market Queries: The attacker also asked AI models where to sell stolen Korean financial records and how to locate Korean-language data sales channels on Telegram.
Escalating Concerns and Official Response
South Korean authorities and law enforcement have launched an investigation to verify the forensic clues provided by cybersecurity researchers.
While CrowdStrike maintains moderate confidence that the identified individual is the primary actor, experts caution that the details could represent an associate or an operational security misstep rather than a sole culprit.
Meanwhile, reports indicate an individual matching the online identity has denied direct involvement in the breach, claiming to be framed. Investigations into server infrastructure in Hong Kong and multi-country routing IPs remain ongoing.

