Treasury's 30-year bond sale hits 5.618% high yield on $22B
The US Treasury auctioned $22 billion in 30-year bonds at a 5.618% high yield, achieving strong demand and a B grade.
CrowdStrike says a suspect in South Korean bank hacks asked an AI chatbot where to sell stolen data.
A suspected hacker involved in breaches of South Korean banks queried an artificial intelligence coding tool about where stolen data can be sold. CrowdStrike discovered the exchange by examining session logs stored on open directories that were part of servers controlled by the attacker.
Multiple financial institutions in South Korea have reported customer data breaches in recent days. CrowdStrike published a report on October 7 linking the activity to a penetration testing tool built in China and several large language models.
A series of attacks struck several Korean lenders one after another from late September into early October. Shinhan Bank confirmed its breach on September 30 and disclosed the following day that roughly 25,000 customers had been impacted. The intruder bypassed identity verification on a mobile service used by loan agents to monitor applications.
The leaked information included names, phone numbers, annual income and computed loan ceilings. The data also contained 66 resident registration numbers, which serve as South Korea’s national identification numbers.
KB Kookmin Bank followed on October 2, stating that information on 119 customers had been exposed through a mobile system its employees use. Hana Bank reported 89 customers were affected, while BNK said records belonging to 11 outsourced workers had been taken.
President Lee Jae Myung later raised the AI issue at a Cabinet session. Police have since started a full inquiry.
“In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety,” he said.
CrowdStrike released its findings on October 7. Open directories on servers under the attacker’s control contained histories from Claude Code, Anthropic’s AI coding assistant, as well as configuration files.
“Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files, providing direct insight into the threat actor’s operational methodology and tooling,” the report read.
According to the report, the attacker worked with ARTEX, an open-source agentic penetration testing tool developed in China.
A server based in Hong Kong served as the attacker’s primary infrastructure. An IP address ran the ARTEX instance that CrowdStrike believes was responsible for the Korean attacks.
CrowdStrike stated that the ARTEX instance used DeepSeek v4.1-flash as its primary AI model. The attacker also employed Zhipu AI’s GLM-5.3 and xAI’s Grok 4.6 in other Claude Code sessions.
DeepSeek also appeared in an August report from TeamT5 about Chinese hackers. The Taiwanese firm found that state-linked groups doubled their attack volume after adopting DeepSeek and open-source AI.
In addition to the ARTEX operation, the attacker asked Claude where threat actors typically sell Korean breach data. The same user requested help finding Korean Telegram groups that trade such data.
CrowdStrike has not attributed the campaign to any specific group. The firm assessed with moderate confidence that the actor is likely a financially motivated Chinese speaker. That assessment is based on ARTEX and the Chinese-language prompts.
In another session, the user asked Claude to compose a security researcher résumé highlighting the ARTEX results. The prompt included a Telegram handle, an age of 26, and a location in Maoming, Guangdong.
CrowdStrike said those details probably belong to the attacker but cannot be conclusively tied to them. The firm also noted that the attacker initially entered a 2007 birth date.
The same Telegram handle appeared in Claude Code sessions investigating a Telegram-based NFT gift marketplace for vulnerabilities.
“While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated,” CrowdStrike added.
CrowdStrike said AI tooling can help a financially motivated actor run multiple intrusions in a short span. Earlier, Anthropic also stated that AI now performs advanced attack tasks for low-skill hackers.
CrowdStrike expects attackers to keep experimenting with AI tools. It was among more than 100 companies that signed an August letter warning that AI-enabled cyberattacks will surge.
Share to
Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.
The US Treasury auctioned $22 billion in 30-year bonds at a 5.618% high yield, achieving strong demand and a B grade.
The Atlanta Fed's GDPNow model for Q3 GDP growth was trimmed to 3.6% from 3.7% after weaker wholesale inventories data.
US wholesale inventories rose less than expected in August, while wholesale sales surged.
StoneX strategist Vincent Deluard warns of rising Treasury yields, bullish on Bitcoin and gold post-midterms.