VibeTimes
#사회

Hacker Behind South Korean Financial Sector Cyberattacks Traced to 26-Year-Old Residing in China

박세미박세미 기자· 10/8/2026, 1:42:21 PM· Updated 10/8/2026, 1:42:21 PM

As the possibility has emerged that the hacking attacks targeting South Korea's financial sector were carried out by a 26-year-old residing in Guangdong Province, China, police are using this as an investigative lead. According to News1 reporting on Monday, police are verifying various suspicions while narrowing down the hacking route.

Global cybersecurity firm CrowdStrike announced in an analysis report released Monday (local time) that it had obtained records of Claude (a generative AI) conversations used in the hacking of South Korean financial institutions, and discovered some identity information in the process. The conversation records included discussions about where the hacker would sell the personal data stolen from financial institutions, along with a resume containing information on a 26-year-old living in Guangdong Province. However, CrowdStrike added that the attacker cannot be definitively identified based on the information currently available.

Police conducted a preliminary investigation (pre-indictment probe) into the hacking incidents targeting KB Kookmin, Shinhan, Hana, and BNK Busan Bank before launching a formal investigation on charges of violating the Information and Communications Network Act. Considering the gravity of the case, the National Police Agency's Cyber Terror Investigation Unit was designated as the dedicated investigative team, organized into four teams of 28 members led by the head of the Cyber Terror Response Division.

Analysis of attack traces is also underway. Police announced the previous day that analysis of the IP addresses used in the hacking confirmed that many of them were for laundering purposes. Efforts to identify the purposes of the remaining IP addresses are ongoing through international cooperation.

Police are reviewing whether this case qualifies for referral to the Major Crime Investigation Agency (MCIA). Among cybercrimes, cases eligible for MCIA referral are violations of the Information and Communications Network Act through hacking of national critical infrastructure, and violations of the Electronic Financial Transactions Act through hacking of electronic financial infrastructure. Although the financial institutions affected in this case do not fall under national critical infrastructure, the case could qualify for referral if the compromised systems are deemed electronic financial infrastructure. Police have requested an authoritative interpretation from the Financial Services Commission.

Related Articles