Suspected ransomware attack threatens one of South Korea’s largest companies

Kyowon Group, one of South Korea’s largest education and lifestyle companies, announced shutting down key parts of its internal computer network this weekend following what it described as a suspected ransomware attack.

In a company statement, Kyowon said it identified abnormal activity on Saturday morning, triggering an emergency response plan to isolate the affected servers and prevent hackers compromising more of its systems.

The conglomerate — which is owned by Chang Pyung-soon, one of South Korea’s richest people — said it has “confirmed indications that some data may have been leaked externally due to a ransomware attack. Whether the affected data includes customer information is currently under investigation.”

Since the shutdown, several websites for its affiliate businesses — including its education and travel subsidiaries — have been left inaccessible as the company says it is working to securely restore systems.

Kyowon said it had taken its network offline to “stabilize services and prioritize customer protection” while working with what it described as “professional security personnel” and the relevant government agencies to investigate “the cause of the breach, the scope of its impact and whether any data was affected.”

The hackers behind the attack have issued Kyowon with an extortion demand, reported The Asia Business Daily. There are concerns that a data breach at the company could impact several million individuals, with data including the names and addresses of children who use its educational services, as reported by Chosun.

The company said it reported the security breach to the Korea Internet & Security Agency (KISA) and other investigative authorities shortly after identifying the problem.

“If further investigation confirms that customer information has been leaked, we will notify affected customers promptly and transparently,” states a banner on the conglomerate’s website.

It follows a recent scandal in Seoul over a data breach affecting the country’s largest online retailer, Coupang, reportedly caused by a former employee who has since fled to China.

That was the latest high-profile data breach to have affected South Korean companies, with 27 million customers of SK Telecom and 3 million customers of Lotte Card informed of incidents last year. South Korean officials have pledged to strengthen the country’s data protection laws and introduce harsher penalties for companies that fail to protect customer data.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Alexander Martin

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and is also a fellow at the European Cyber Conflict Research Initiative.

 

Total
0
Shares
Previous Post

Kremlin-linked hackers pose as charities to spy on Ukraine’s military

Next Post

Malicious Chrome Extension Steals MEXC API Keys by Masquerading as Trading Tool

Related Posts

Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin Accounts

Cybersecurity researchers are sounding the alert about an authentication bypass vulnerability in Fortinet Fortiweb WAF that could allow an attacker to take over admin accounts and completely compromise a device. "The watchTowr team is seeing active, indiscriminate in-the-wild exploitation of what appears to be a silently patched vulnerability in Fortinet's FortiWeb product," Benjamin Harris,
Read More

ThreatsDay Bulletin: AI Tools in Malware, Botnets, GDI Flaws, Election Attacks & More

Cybercrime has stopped being a problem of just the internet — it’s becoming a problem of the real world. Online scams now fund organized crime, hackers rent violence like a service, and even trusted apps or social platforms are turning into attack vectors. The result is a global system where every digital weakness can be turned into physical harm, economic loss, or political
Read More