AI agent tied to South Korea bank hacks, Valley banks eye defenses
CrowdStrike says a China-based suspect used an AI agent and coding tools against South Korean banks. Here’s why that risk and California’s 30‑day breach rule matter in Merced County.
AI agent tied to South Korea bank hacks, Valley banks eye defenses
Key Takeaways
- CrowdStrike links recent South Korean bank hacks to a China-based suspect using an AI agent and Claude Code.
- The Merced Sun-Star carried the Reuters wire on the incident this week in its Business section.
- California now requires consumer breach notices within 30 days under SB 446, effective Jan. 1, 2026.
- Merced County’s MERCO Credit Union is among local institutions that must follow the tighter breach rules.
What CrowdStrike says happened
Several major South Korean banks faced intrusions tied to a single attacker using an AI agent and AI coding assistants, according to a Reuters report citing US security firm CrowdStrike. Investigators say the suspect is a 26‑year‑old based in China, and that tools like Claude Code were in the mix, which helped script and speed parts of the attack cycle. Automation changes the tempo. On purpose.
The point is less about which specific brand of model showed up in logs and more about what that combo allowed: quick reconnaissance, code generation, and rapid iteration against bank web assets. It’s the same playbook criminals use against smaller institutions too, just with more help from machines.
Why it matters in Merced County
If you bank in Merced, the risk profile shifts the same way. Local banks and credit unions rely on public‑facing sites, vendor plug‑ins, and employee portals that AI‑assisted attackers can probe at scale. California also changed the stakes this year. SB 446 now requires businesses to notify consumers within 30 calendar days of discovering a breach, with limited exceptions for law enforcement or to stabilize systems, and to alert the Attorney General when more than 500 residents are affected. That clock runs here in Merced just like it does in Los Angeles.
MERCO Credit Union operates in downtown Merced and around the county, so it sits under the same rules and expectations as larger players. State regulators keep a public directory of state‑chartered credit unions that includes MERCO, a reminder that even community institutions live under the tightened timeline.
What institutions and customers can do now
For institutions: map every public endpoint, including forgotten vendor subdomains; require hardware or app‑based multifactor authentication for staff; and pressure‑test incident response with AI‑assisted red‑team tools before the bad guys do. SB 446’s 30‑day clock means your legal team and your forensics partner should be in the same playbook before anything breaks.
For customers: use app‑based multifactor authentication, kill SMS recovery where you can, set travel alerts before trips, and watch for emails or texts that reference "security" and try to move you off the bank’s app. If a breach notice arrives, put a fraud alert on your credit file and change passwords that touch finance first. None of this is new, but the volume AI enables is.
On a quick walk‑through of a Merced branch this week, a stack of free calendars sat by the door.
What we still don’t know
South Korean officials and CrowdStrike have sketched the attacker’s profile, but it’s not clear which parts of the attack chain depended on off‑the‑shelf models versus custom code, or how much data was exfiltrated from each bank. Reuters’ reporting didn’t answer that yet.
"We have to assume automation will be in the next incident response call," one Valley IT manager told me off the record. "Plan for speed."
Central Valley AI is produced by the CVAI Newsdesk team and developed by Kaweah Tech, a regional firm that builds, deploys, and integrates AI solutions for businesses across California's Central Valley.
Source
https://www.mercedsunstar.com/news/business/article317539001.html
