After hacking South Korean banks with AI, he asked Claude to write his resume — and it all went wrong
Multiple South Korean banks have been hacked, and the president ordered a full investigation. A CrowdStrike report indicates the perpetrator is suspected to be a 26-year-old Chinese national who carried out the attack using the open-source AI penetration tool ARTEX and Claude Code. However, because he enabled directory listing on his server, security researchers were able to easily access all of his chat logs and resume request, exposing everything. No matter how powerful AI is, it can't save you from a basic configuration mistake.
Multiple banks in South Korea were recently hacked, leading to the leakage of tens of thousands of people's personal information, and President Lee Jae-myung personally ordered a full investigation. On October 7, cybersecurity firm CrowdStrike released a report indicating the hacker behind the attack is likely a 26-year-old Chinese man.

The incident dates back to late September, when multiple South Korean financial institutions suffered successive cyberattacks. CrowdStrike's investigation found that the attacker used ARTEX, an open-source AI penetration testing tool developed in China, which primarily connects to DeepSeek V4.1-Flash, and also used GLM-5.3, Grok 4.6 and Claude Code to assist with operations.
He set up two servers: one located in Hong Kong for command and control, and the other to run ARTEX. The IP address of the ARTEX instance is 38.244.50[.]120, and a large number of configuration files are stored on the Hong Kong IP server.
Up to this point, the operation showed some level of technical skill. Then he did something incredibly absurd.
He enabled directory listing on his server. Security researchers barely had to exert any effort to find CLAUDE.md, Claude Code's conversation history, ARTEX configuration files, and even managed to dig out Claude's memory files.
It was basically broadcasting the entire attack process to the public internet.
Researchers found more absurd details as they looked through the data. He asked Claude: Where is leaked South Korean data usually sold? Are there any specific Telegram groups for trading this data?
And it gets worse. The most ridiculous part is that he asked Claude to help him write a resume for a cybersecurity researcher position.
The resume included this personal information: Name YY, phone number 17820191556, Telegram @YY520CN, age 26, educational background South China University of Technology, current location Maoming, Guangdong Province.
Wait, there's also a contradiction in the report: He initially provided a date of birth of 2007-09-22. By that calculation, he would only be 18 or 19 years old in 2026, not 26. Netizens have already asked: "If he was born in 2007, how can he be 26?" It might have been a random fabrication, or just a typo in the information.
Following the Claude Code conversation history, CrowdStrike reconstructed the entire attack process. Every detail, from the proxy IPs he used, his server architecture, to his model calls, was fully documented. Nine proxy IPs alone were listed in the records.
Here was a person who could skillfully use multiple large language models, Agents and cyberattack tools, launch an attack on South Korean financial institutions, and even knew to use proxy servers to hide his location. Yet he couldn't even configure basic directory access permissions correctly on his server.
One netizen commented: "A typical transition from script kiddie to AI kiddie. He gained a powerful spear thanks to AI, but his own defenses were easily broken because he lacks the foundational knowledge." Another said: "Claude Code basically sold him out, the chat logs are more detailed than official logs."
Even more ironically, he ended up asking Claude to help him find a cybersecurity researcher job. Netizens joked: "He'll be recruited by the relevant authorities any day now." "This indirectly proves that AI's capabilities on the offensive side are far stronger than on the defensive side." Others quipped: "Maoming really produces talented people."
No matter how powerful AI is, it can't make up for such a ridiculous security hole left by human error.
Reference report: [Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)
发布时间: 2026-10-08 21:40