SBS NEWS

News > Economy

Used Claude for a Resume and Got Caught? Clues to the Identity of Financial Sector Hacker Emerge

Jung Da-eun

Published : Oct 8, 2026 4:02 PM

Video

An individual residing in Guangdong Province, China, and estimated to be 26 years old, has been pointed to as a suspected figure behind hacking attacks targeting the South Korean financial sector.

This marks the first time that clues regarding the identity of the attacker in the recent financial sector hacking incident have been captured.

In an analytical report released on October 7, local time, global cybersecurity firm CrowdStrike stated that the attacker is likely a 26-year-old individual residing in Guangdong Province, China.

However, the firm drew a line, explaining that this is a circumstantial estimation and not a definitive identification.

According to CrowdStrike, these clues were exposed while the individual presumed to be the attacker was using the generative AI coding tool "Claude Code."

The individual asked Claude to draft a security researcher resume containing their penetration testing achievements, and personal information such as name initials, a Telegram account, educational background, and place of residence was entered in the process.

It was revealed that this individual also asked Claude where stolen South Korean financial information is typically sold and how to find Korean-language Telegram data sales rooms.

The report stated that the same Telegram account was discovered in connection with other cyberattack circumstances.

Previously, CrowdStrike analyzed that attacks targeting South Korean financial institutions took place between the end of last month and the beginning of this month, and that the attacker utilized a large language model alongside "Artex," an open-source agentic penetration testing tool developed in China.

According to this CrowdStrike analysis, the attacker used a two-tier server structure, taking a Hong Kong-based IP address as the primary control infrastructure to direct the overall attacks while operating the Artex servers actually used in the South Korea attack from separate IP addresses.

The attacker, presumed to be a Chinese speaker, was analyzed as likely having been motivated by financial incentives.

Reported by Jung Da-eun | Video by Kim Ki-hyun | Graphics by Lee Su-min | Produced by SBS Digital News