← Back to stories
Security

CrowdStrike finds possible bank hacker's CV among exposed AI logs

CrowdStrike researchers investigating attacks on South Korean financial institutions found exposed AI session logs containing operational details and a resume-writing request that may identify the attacker. In a report published Wednesday, analyst Ashley Campion said the prompt named "YY," listed a Chinese university and a location in Guangdong, and gave conflicting age information: 26, but initially a birth date in September 2007. CrowdStrike considers the details likely to belong to the attacker but says it cannot definitively establish that connection. The attacks affected at least five lenders, including Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank, and BNK Busan Bank, according to The Korea Times. In one case, the attackers allegedly breached a loan progress inquiry service and in another, they gained access to a mobile work-support system. …

You're reading a preview. The full article is published by The Register on their website.

Read the full story on The Register