CrowdStrike says hacker behind South Korean bank attacks likely operated from China

1 hour ago 3



A wave of cyberattacks that hit South Korea’s banking sector this fall may trace back to a single person with a laptop and some very capable AI tools. That is the picture painted by CrowdStrike, which says the hacker likely operated from China. The cybersecurity firm’s findings land as South Korean police open a formal investigation. Customers at several major banks are now wondering what exactly walked out the door. What CrowdStrike found CrowdStrike published its report on October 8, 2026. It covers a string of attacks on South Korean financial institutions that ran from late September into early October. According to the analysis, the threat actor is likely a 26-year-old Chinese-speaking man based in Maoming, a city in Guangdong province. CrowdStrike did not tie him to any organized hacking group. CrowdStrike’s read is different: one individual, likely chasing a payday. The firm characterized the campaign as potentially motivated by financial gain rather than espionage or politics. The attacker’s infrastructure included a control server located in Hong Kong. That server effectively served as the remote command post for the operation. The AI toolkit The most striking part of the ...

Read Entire Article