CrowdStrike Links South Korean Bank Breach Suspect to AI Query on Selling Data

CrowdStrike says a suspected attacker in recent South Korean bank breaches asked an AI coding assistant where stolen data could be sold. The request was discovered in session logs stored on attacker-controlled servers. Several South Korean banks have disclosed customer data leaks over the past week.
CrowdStrike says it has connected a person suspected in recent South Korean bank intrusions to a question posed to an AI coding assistant about possible buyers for stolen information.
That question appeared in session records kept on servers the attacker controlled. The finding comes as multiple South Korean banks have reported customer data leaks in the last week.
If confirmed, the link between an alleged bank intruder and an AI assistant query could heighten concerns about how easily AI tools may be used to seek markets for stolen data. South Korean bank customers may face greater risk of fraud or identity misuse, while lenders could review security and incident response. The episode may also prompt broader discussion about monitoring misuse of AI services, though its actual consequences remain uncertain.