Hacker Doxxed Himself to CrowdStrike by Asking AI to Write His Resume
When high-stakes bank heists meet terminal laziness, modern cybercrime reaches peak comedy. An attacker raided South Korean banks, only to leave his entire identity in public AI prompt logs.
Cybersecurity analysts at CrowdStrike managed to unmask a threat actor behind breaches at major South Korean financial institutions without needing an elaborate undercover sting. The culprit simply left an exposed server hosting the full chat logs of his coding sessions with Claude Code, DeepSeek, GLM, and Grok.
Instead of locking down his command-and-control server, the hacker left public directories containing raw AI assistant memory files and chat histories alongside his attack tool configurations. Inside these logs, investigators discovered a prompt where the attacker politely asked the AI to polish his CV for a legitimate security researcher role.
To make the application pop, the operator explicitly instructed the AI to highlight his recent live breaches against South Korean targets as verified work experience. The prompt included personal details: an age of 26, an alma mater at South China University of Technology, residence in Maoming, and a direct Telegram handle.
The AI logs also captured the attacker asking models where to unload the stolen goods on the black market and seeking underground trading groups. The compromised targets included Shinhan Bank with roughly 25,700 leaked records, alongside KB Kookmin Bank and Hana Bank with dozens of customer accounts exposed.
The era of mysterious phantom hackers is officially replaced by script kiddies using frontier neural networks to generate cover letters out of active criminal evidence. Modern threat intelligence no longer requires decrypting encrypted relays when the adversary outsources both the felony and the self-doxxing to a chatbot.
Source: CrowdStrike
Comments
Help shape the next version: Add context or suggest a correction. AI review can add points toward a rewrite. Reviews and updates may take time; a full meter does not guarantee a new version.