South Korea

Country

Ransomware Attack at South Korean Auto Parts Supplier, Namyang Industrial

August 6, 2026

South Korean manufacturer Namyang Industrial Co., Ltd., also known as NAMYANG NEXMO, suffered a ransomware attack in August.
Barracuda ransomware group claimed credit for the August 6 attack at the South Korean auto parts supplier, according to a report in Undercode News.
Namyang Industrial is a supplier within the automotive manufacturing environment. NAMYANG NEXMO is an automotive-parts manufacturer producing steering and braking components, with manufacturing operations in Korea and overseas facilities.

read more

Multi-regional Cyberattack at Luxury Fashion Brand Louis Vuitton

July 2, 2025

Louis Vuitton was the victim of a multi-region cyberattack in July 2025. The attack impacted customers in the UK, South Korea, Turkey, and Portugal. The unauthorized party accessed data such as names, contact information, and purchase history. No financial or payment data was compromised. Louis Vuitton notified affected customers and relevant authorities, including the UK’s Information Commissioner’s Office (ICO) and the CNIL in Europe. The company is investigating the incident while strengthening its security systems.

read more

Cyberattack at Agricultural Machinery Maker Daedong-USA

January 23, 2024

Wendell, North Carolina-based Daedong-USA, Inc., a maker of agricultural machinery, suffered a cybersecurity incident. The incident involved unauthorized access to certain systems and occurred on or around January 23, 2024. In October 2024 the company’s investigation discovered an unauthorized party obtained certain personal information of 10,643 victims.

read more

Remote Control Malware Targets South Korean Company’s Large Machine & Equipment Design Files

April 15, 2024

In April 2024, the North Korean hacking organization Andariel exploited vulnerabilities of the VPN information security software used by targeted construction and machinery companies to replace update files in their systems with malware.

In addition to the VPN products, Andariel also exploited vulnerabilities in server security products. The threat actors were able to distribute remote control malware DoraRAT with the aim of using it to transfer large machine and equipment-related design files to the C2 server, according to South Korean intelligence.

read more

North Korean hackers attack South Korea’s construction sector

January 15, 2024

The Kimsuky hacker group distributed malware through the website of a professional association in the construction sector, according to the South Korean intelligence.

The malware was hidden in the security authentication software used to log into the website. As a result, the personal computers of local government, public institutions, and construction company staff who accessed the website were infected.

It is believed that the attackers exploited a file upload vulnerability on the professional association’s website to alter the security authentication software in a “meticulously” planned operation. “It is presumed that the hackers aimed to use the compromised credentials of officials in the construction sector as a foothold to steal critical information about major construction projects and technical data from companies involved,” the KCIC said.

read more

Samsung Data Breach

March 19, 2020

Samsung admitted what it calls a “small number” of users could indeed read other people’s personal data following an unexplained Find my Mobile notification.
Users said they found strangers’ personal data displayed to them. Find My Mobile is a Samsung app that comes pre-loaded with its Android devices and can only be disabled, not uninstalled. The only way to uninstall Samsung apps is to wipe the operating system completely and install a different ROM.
The company has admitted a data security breach did occur.
A company spokeswoman said, “A technical error resulted in a small number of users being able to access the details of another user. As soon as we became of aware of the incident, we removed the ability to log in to the store on our website until the issue was fixed.”

read more

Samsung Hit in Cyberattack, Again

July 28, 2022

For the second time this year in a span of less than six months, electronics giant South Korea-based Samsung, suffered a data breach this past July, but the company did not discover it until early August.
After discovery, the company found the attackers stole personal data from customers.
“At Samsung, security is a top priority,” the company said in an advisory it posted September 2 almost a month after discovering the incident. “We recently discovered a cybersecurity incident that affected some customer information.
“In late July 2022, an unauthorized third party acquired information from some of Samsung’s U.S. systems. On or around August 4, 2022, we determined through our ongoing investigation that personal information of certain customers was affected. We have taken actions to secure the affected systems, and have engaged a leading outside cybersecurity firm and are coordinating with law enforcement.”
This was the second attack against Samsun this year and third since 2020.

read more

Samsung Hit in Cyberattack

March 5, 2022

South Korea-based Samsung suffered a cyberattack over the weekend, but it doesn’t see there being any impact on its business or customers, company officials said Monday.
South American hacking group Lapsus$ said it had stolen 190GB of confidential data, including source code, from the tech giant’s servers. The group also posted snapshots of data online.
Samsung confirmed in a statement there was a security breach, but it said there was no compromise of customer personal information.
“We were recently made aware that there was a security breach relating to certain internal company data. Immediately after discovering the incident, we strengthened our security system,” the company said.

read more

South Korea’s Atomic Agency Suffers Hack Attack

May 14, 2021

The intrusion took place in May by what is believed to be an attack group operating out of North Korea, said a KAERI spokesperson. The incident occurred May 14 and the attackers got in through a vulnerability in a virtual private network (VPN) server. KAERI is the government organization that conducts research on nuclear power and nuclear fuel technology.

read more