
A Chinese resident identified as the perpetrator behind recent large-scale hacking attacks targeting South Korea’s financial sector denied involvement, stating that he had nothing to do with the hacks. After a U.S. cybersecurity firm disclosed information believed to be the hacker’s identity, he claimed his personal data had been stolen and misused. The Chinese government also stated that it did not know specific details about the hacking incident, expressing its opposition to both hacking activities and the spread of false information driven by political motives.
According to financial industry sources on the 9th, CrowdStrike, a U.S. cybersecurity firm, claimed in a report released on the 7th that there is a possibility that the recent hacker targeting South Korea’s financial sector is a 26-year-old resident of Guangdong Province, China.
CrowdStrike stated that it discovered clues allowing for identity estimation while analyzing work records from the AI coding tool “Claude Code” left on the server used by the hacker. The hacker had requested the AI to draft a resume for a security researcher, listing his name as “YY,” derived from English initials, and his age as 26. He entered South China University of Technology as his educational background and Maoming, Guangdong Province, China, as his place of residence. A Chinese phone number and the Telegram account “@YY520CN” were also left behind.
However, YY, the user of the aforementioned Telegram account, is known to have claimed in a Telegram conversation with a domestic media outlet that he was uninvolved in the recent financial sector hacking. He refuted the claims by stating that while his name and Telegram account are indeed his own, other information such as age, educational background, and place of residence does not match the facts. He further requested that South Korea conduct specific investigations to avoid implicating him based on incorrect information.
In an interview with another media outlet, YY reportedly stated that while it is true he was born in 2000 and is 26 years old, he resides in Zhengzhou City, Henan Province, not Guangdong Province. He also claimed that his educational background is Henan Normal University, not South China University of Technology, and that after majoring in computer science, he currently works at a convenience store.
In particular, YY refuted the allegations on the grounds that if he were truly a hacker, he would not have left behind information that could be used to trace his identity. He raised the possibility that a Telegram user named “Cola (),” with whom he had previously had conflicts, may have intentionally left his contact information to frame him. He also stated that he has reported the matter to the police and is awaiting investigation by South Korean authorities.
A senior official related to financial sector security said, “The content of the report analyzed by CrowdStrike is highly likely to be accurate,” while adding, “However, if the hacker recorded false information, the report may contain incorrect details.”
The Chinese government also issued a statement regarding the incident. Mao Ning, spokesperson for China’s Ministry of Foreign Affairs, said in a regular briefing on the day, in response to questions about the CrowdStrike report, “I do not know specific details,” and added, “China opposes hacking activities in accordance with the law.” She further stated, “We also oppose the spread of false information driven by political motives.”
Meanwhile, concerns have been raised within the financial sector regarding secondary damages following the release of the report. The report assessed that there is a high possibility that the attacker was motivated by financial gain. Work records from Claude Code secured by CrowdStrike included instances where the hacker asked where leaked personal information from South Korea is typically sold. There were also requests to find Telegram groups trading in South Korean personal data. It has not been confirmed whether actual sales of personal information took place.
A senior official related to financial sector security said, “The issue is that such attacks are occurring more frequently, and given the strong financial motive, the possibility of secondary damages is high,” adding, “I believe attacks by voice phishing organizations centered around hackers will increase.”