
The National Information Resources Service Fire, University and Government Hacks, and the Kimsuky–Phrack Files Expose Deep Vulnerabilities in South Korea’s National Systems
By Jean Cummings
Co-Editor, The Korea Signal
South Korea’s digital security crisis is no longer confined to one ministry or one network. It has spread across government systems, university research networks, the financial sector, and the contractors that support major corporations and public institutions. These are the systems that hold government data, advanced technology, and the assets of ordinary citizens.
The incidents involving government agencies, universities, corporations, and financial institutions should not be treated as isolated cases. A security failure at one point can provide access to systems far beyond the original target.
The National Information Resources Service is one of the government’s most important data facilities. Storing original data and backup data in the same computer room was not a minor administrative mistake. It was clear evidence of how carelessly the South Korean government had managed critical national information systems.
Universities present the same problem. Several Korean universities left security vulnerabilities uncorrected for years, while government-affiliated research institutes could not even determine where hard drives used by former employees had gone. After government remote-work systems and public employee certificates were compromised, a financial company later executed stock sales and overseas transfers based on emails sent by someone impersonating a customer.
South Korea’s systems are vulnerable enough that an attacker does not necessarily need to penetrate the central server of a government agency. Compromising the administrator account of an outside contractor can provide access to the institution that contractor manages. When stolen government certificates and weak customer-verification procedures at financial institutions can also be exploited, the consequences can extend beyond Korean government systems and private assets to information shared with the United States.
South Korean government, research, and military-related systems also contain information connected to the United States and U.S. Forces Korea. South Korea’s security failures therefore create a direct security risk for the United States.
The National Information Resources Service Fire and the Collapse of Government IT Systems
On September 26, 2025, a lithium-ion battery fire broke out at the Daejeon headquarters of the National Information Resources Service. The fire disabled hundreds of government information systems, including Government24, mobile identification services, the national petition system, postal and customs-related services, civil-service platforms, and internal government work systems. The Ministry of the Interior and Safety ultimately reported that 709 systems were affected.
One of the most seriously damaged systems was G-Drive, the work-data repository used by central government officials. More than 191,000 officials from 74 agencies used the system, which stored approximately 858 terabytes of data. The government later said that the data could not be recovered because no separate backup existed. At a time when South Korea faces repeated cyber penetration attempts from China and North Korea, it was reasonable to question why a system containing large volumes of government work product was destroyed without recoverable backup.
The Ministry of the Interior and Safety said that some finalized documents used for approval and reporting remained in the On-nara system. It did not disclose how much working material, shared documentation, or transition material used by public officials had been permanently lost.
On December 30, 2025, the government announced that all 709 affected systems had been restored. In 2026, it also announced plans to place 14 systems transferred to a public-private cloud environment at the Daegu center under integrated management, with round-the-clock monitoring and standardized backup procedures. G-Drive was moved to a system using Naver Works Drive.
Restoring a system, however, does not mean that the data destroyed before restoration was recovered. The government should disclose the scope of the permanently lost material and whether it included documents connected to ROK-U.S. combined operations or other national-security functions. It also has a responsibility to explain how close to the time of the fire the restored systems retained usable data. The South Korean government has remained silent on these questions.
Police booked 19 people in connection with the fire, including the head of the National Information Resources Service, responsible officials, contractor personnel, and workers. Investigators said the battery-rack work proceeded without adequate electrical isolation and insulation measures. Police also cited testimony that the main power source had been disconnected but an auxiliary power source had not.
Publicly released CCTV footage, however, showed workers leaving the site with their equipment shortly after the fire began, without visible panic and without making any significant effort to extinguish the fire. The footage inevitably raised questions about whether simple negligence fully explains what occurred. Yet the publicly disclosed police investigation has remained focused on worker error, safety violations, and supervisory responsibility.
Even under the police explanation, the government bears clear responsibility. Work involving batteries inside a critical national data facility passed through multiple layers of subcontracting and ultimately reached personnel who, according to investigators, failed to carry out basic electrical isolation and insulation procedures.
Then, one week after the fire, on October 3, 2025, a Ministry of the Interior and Safety official involved in responding to the network outage died after falling from a government building in Sejong. Police said he was not a subject of the fire investigation. Allegations later emerged involving excessive work demands and inappropriate conduct by superiors. But the timing of the death, immediately after a major national systems failure, continues to raise serious questions. It is reasonable to ask whether he possessed important knowledge about the cause or handling of the incident.
The ministry placed the official’s supervisor on administrative leave and announced a fact-finding investigation. As of August 2026, it has not publicly disclosed what that investigation established or what action followed. The government should disclose what role the deceased official had in the response, how information moved through the chain of command, and what instructions were given before and after his death.
The U.S. Department of War should independently determine whether any systems affected by the fire supported ROK-U.S. information sharing or U.S. Forces Korea. It should also determine whether U.S.-related security information was stored on affected systems and whether any such material was lost or exposed during restoration.
The United States should also establish whether the outage disrupted logistics or administrative support for U.S. Forces Korea. If Chinese-made equipment or outside contractors participated in the recovery process, the scope of their access should be examined. If Seoul does not disclose the relevant information, Washington will have to reconsider how much access South Korean systems should have to U.S.-related information.
Why Universities and Research Institutes Are Major Targets
University servers contain far more than student records. They also hold faculty research, government-funded projects, grant-management information, and work conducted with private companies. Research involving advanced technology and defense-related fields also moves through university networks, faculty email accounts, and laboratory computers.
If North Korean or Chinese actors penetrate these systems, they can identify what a particular professor is developing and who is participating in the research. With access to email and personnel records, they can also track where researchers move and where related technology may follow.
In July 2024, Jeonbuk National University’s OASIS integrated information system was attacked through SQL injection and parameter manipulation. Personal data belonging to approximately 320,000 people was exposed, including resident registration numbers in roughly 280,000 records. Two months later, Ewha Womans University suffered a parameter-manipulation attack that exposed personal information, including resident registration numbers, belonging to approximately 83,000 people.
The Personal Information Protection Commission found that both universities had security vulnerabilities dating back to the original construction of their systems. The weaknesses remained uncorrected for years, and outside attacks were not adequately monitored during nights and weekends. In June 2025, the commission imposed a combined penalty of 966 million won and ordered both universities to establish 24-hour detection and blocking systems.
External hackers are not the only route through which research leaves Korean institutions. Students and researchers have carried data out directly using portable storage devices and cloud services.
In 2025, a Chinese student participating in joint research at a university laboratory in Daejeon copied source code developed by the lab onto an external hard drive and left for China. The supervising professor later persuaded the student to return to South Korea by offering to pay outstanding research compensation, then filed a criminal complaint.
At a graduate school in Seoul, a Vietnamese graduate student researching electric-vehicle battery technology left the university and moved to an overseas research institution. Prosecutors later received the case over allegations that the student had removed research material through a cloud service.
Neither method was sophisticated. One researcher carried source code out on an external drive. Another allegedly accessed research data through the cloud after leaving the university. If a university cannot immediately determine what was copied and sent outside, it may not discover the loss until the research is already abroad. Korean university laboratories can no longer be assumed to be secure repositories for advanced technology.
An audit released on July 28, 2026, by the Board of Audit and Inspection showed even more serious failures at six government-funded research institutions under the Ministry of Science and ICT and the Korea AeroSpace Administration.
The audit identified 27 problems involving hard-drive management and server security. During the previous year, 690 PC hard drives had been removed at five institutions. Of 39 drives previously used by departing employees, 12 were either outside the institution or could not be located.
At the Korea Aerospace Research Institute, a departing employee moved to a university while taking, without authorization, a hard drive containing 60,956 files. The drive included material from four classified or security-designated research projects. A national research institute allowed a storage device containing protected research data to leave the facility and could not immediately account for it.
Server management was no better. Five audited institutions operated 17,073 servers, but antivirus software had been installed on only 374 of them. Some institutions failed to update server operating systems on time, while employees were found to have installed programs that allowed data to be sent from internal computers to outside systems.
The Board of Audit and Inspection ordered further investigation into the 12 missing hard drives and called for stronger rules governing storage devices and server security. But the findings already show how poorly some government-funded research institutions have managed data. External storage devices were controlled while internal hard drives were effectively excluded from asset tracking, and institutions could not locate drives taken by former employees. Under those conditions, they may have no way to determine what research was removed or where it went.
The Chinese student who carried source code to China on an external drive is a direct example of how these weaknesses can be used to remove technology. If Korean universities or research institutions stored U.S.-linked research in the same manner, American technology was exposed to the same weak controls.
The U.S. Department of War should determine whether U.S.-related research held by the audited institutions was stored on missing hard drives or personal servers. If Chinese nationals or Chinese institutions had access to that material, the United States cannot rely solely on a South Korean internal investigation to determine the extent of any loss.
Kimsuky, the Phrack Files, and the Government’s Late Discovery of On-nara and GPKI Penetration
Kimsuky, widely identified as a hacking organization operating under North Korea’s Reconnaissance General Bureau, has repeatedly targeted South Korean government institutions as well as journalists, academics, and foreign-policy and security experts. An analysis by Korea University’s Graduate School of Information Security, discussed in the previous issue, also noted activity in material published by the U.S. hacking journal Phrack that resembled techniques associated with Chinese-linked hackers.
While attention focused on whether the attackers were North Korean or Chinese, the more important fact was that South Korea’s internal government network had already been penetrated. The released material contained records of actual access to government systems, and in October 2025 the Ministry of the Interior and Safety acknowledged evidence that attackers had entered On-nara through the government’s G-VPN remote-work system.
Possible compromise involved GPKI administrative digital certificates belonging to 650 users. In 12 cases, both certificate keys and passwords were exposed. Three certificates that were still valid were revoked. The government then required both GPKI and telephone verification for G-VPN access, blocked reuse of On-nara login credentials, and announced plans to move from GPKI-centered authentication toward mobile government IDs and biometric multi-factor authentication.
But revoking certificates and changing login procedures cannot recover documents that attackers may already have opened or downloaded. The government has not disclosed which ministries owned the compromised accounts, which documents were accessed inside On-nara, whether any files were exported, or how long the attackers were inside the government network.
There were also indications that documents from major government ministries and material related to ROK-U.S. combined exercises may have been targeted. It remains unclear what damage information Seoul provided to Washington or whether U.S.-related documents were actually accessed or removed.
The government suggested that credentials may have been exposed when users handled certificates on outside computers. If that explanation is correct, attackers were able to steal certificates and passwords, impersonate legitimate officials, and pass through G-VPN. A remote-work system used by more than 63,000 officials failed to stop access coming from unusual locations and did not block attackers even when login behavior differed from the user’s normal pattern.
This cannot be reduced to careless certificate handling by individual employees. Attackers used authentication issued by the South Korean government to enter internal systems as if they were legitimate officials, and the government detected the penetration only later.
If the U.S. Department of War is examining Chinese influence and access inside South Korea, it should identify which ministries were connected to the compromised accounts. It should also determine whether U.S.-related material appeared in the attack data showing activity similar to Chinese-linked hackers and whether stolen credentials were used to reach information connected to combined operations or U.S. Forces Korea.
Small Contractors and Subcontractors as Back Doors Into the Entire System
South Korean government agencies and large corporations maintain their own security organizations, but much of the actual operation of their networks and security equipment is handled by smaller contractors and subcontractors. Major government IT and security systems are installed and maintained by outside firms, while universities, hospitals, and financial companies also depend heavily on contractors to develop and operate their computer systems.
Outside developers and maintenance personnel receive administrator accounts, VPN access, and the ability to change server settings or control systems remotely. An attacker therefore does not have to break directly into the central server of a government agency or major corporation. Compromising one poorly protected contractor account may be enough to enter every institution that employee manages.
If a maintenance company’s VPN is compromised, customer servers are exposed with it. If a cloud system operated by a contractor serving multiple institutions is infected, every customer using that environment can be attacked. This is how small contractors become back doors into government agencies and major corporations.
In September 2025, the Qilin ransomware group publicly identified 28 South Korean asset-management companies as victims and called the campaign the “Korean Leak.” According to AhnLab, some of the affected companies operated file servers through the same IT-management provider. The compromise of that provider’s server may therefore have exposed multiple asset-management companies at once.
The attackers did not need to penetrate all 28 firms separately. Compromising one company that managed servers for multiple customers could provide access to every client using the same system. South Korea’s outsourced IT structure has already created a route through which one provider can become the entry point to numerous organizations.
The National Information Resources Service has also announced plans to place 14 public information systems at its Daegu center under a single integrated managed-service provider. Concentrating administrative authority over several government systems in one company means that one compromised account can expose multiple public systems at the same time. Abuse by an insider would also extend beyond a single agency.
The U.S. Department of War cannot limit its review to large Korean companies that hold direct contracts with U.S. Forces Korea. Major companies may win the contracts, but the people who actually operate systems and maintain facilities are often employed by lower-tier subcontractors. Personnel with no direct contractual relationship with the U.S. government may still have access to internal systems and security equipment at U.S. military facilities.
The Pentagon should determine whether those subcontractors use Chinese remote-access equipment or China-linked cloud services and whether administrator accounts remain active after personnel leave a project. If one Korean contractor supports several U.S. military facilities while also managing South Korean government systems, a single compromised account could expose both environments through the same route.
Looking only at major companies with direct U.S. contracts will miss the workers and subcontractors who actually log into servers and operate equipment. Any Pentagon investigation into Chinese access inside South Korea must follow the administrator privileges down to the lowest level of the contracting chain.
Cyber Insecurity Reaches the Financial and Securities Sector
South Korea’s financial sector has also seen security failures move beyond data exposure into actual stock sales and overseas transfers.
In 2017, Korea Investment & Securities was reportedly compromised through an administrator account by a hacker using a China-based IP address. Reports said customer information was leaked and that the incident appeared in a financial-regulatory disciplinary document. The fact that an internal administrator account at a major financial company was taken over through access originating in China showed that the Korean financial system had already become a direct target of outside actors.
In 2025, the Qilin ransomware group publicly named several South Korean asset-management companies as victims and threatened to release additional material allegedly taken from them. Some of the affected firms reportedly operated file servers through the same IT-management provider, raising the possibility that attackers reached multiple companies through a single service provider. Even strong internal security at a financial firm becomes meaningless if an outside company with administrator privileges is compromised.
In 2026, another case showed how little technical sophistication may be needed. An individual impersonating a foreign investor allegedly sent email instructions that resulted in actual stock sales and overseas transfers at LS Securities.
According to the investor, a third party used an email address similar to the customer’s real address between July 2025 and February 2026 and sent instructions to sell stock and transfer funds. LS Securities allegedly accepted those instructions as genuine and sent approximately $3.33 million to accounts in the United States and Vietnam over 19 separate transfers.
The investor filed a damages suit seeking 7.01867 billion won, alleging that LS Securities failed to notice differences in the email address and did not conduct additional identity verification. LS Securities has said that a Financial Security Institute inspection found no evidence that its own systems or email had been hacked and that employees followed the rules in effect at the time. Police and civil litigation have not yet produced a final conclusion.
There is currently no confirmed evidence that China or North Korea was involved in the LS Securities case. But the fact that someone could create an email address resembling that of a customer, issue instructions to sell stock and transfer large sums overseas, and have those instructions processed 19 times is itself serious. The attacker apparently did not need to hack the brokerage’s internal network. Deceiving the employee handling the account was enough.
The investor also alleges that LS Securities did not call the customer’s registered telephone number even after repeated instructions to send large sums to overseas accounts that had not previously been used. If no telephone or video confirmation occurred, then the company’s identity-verification process effectively depended on an email message.
The previous issue warned that when SIM-related information and other personal data are stolen together, attackers can use them in financial fraud. When that information meets weak identity verification at a financial institution, an attacker can impersonate an account holder and order stock sales or overseas transfers without ever penetrating the financial company’s server.
Japan has already reported cases in which stolen securities accounts were used to purchase specific Chinese stocks and artificially push up their prices. If attackers control multiple accounts at the same time, they can do more than steal from individual investors. They can manipulate thinly traded stocks, take profits through separate accounts, and disrupt the market itself.
South Korea has opened large parts of its financial, telecommunications, and industrial economy to Chinese capital and companies while maintaining weak account controls and communications authentication. At the same time, the Lee Jae-myung government has responded passively to security problems involving China while encouraging the public to invest in stocks and allowing market overheating to continue. Under those conditions, stolen accounts can be used more easily for price manipulation and asset theft.
South Korean financial institutions use U.S. dollar clearing and international transfer networks and also manage U.S.-based investment accounts and transaction records for Korean companies. If administrator accounts at Korean financial institutions or their IT providers are compromised by Chinese or North Korean hackers, the exposure can extend beyond Korean customers to transactions and money flows between U.S. financial institutions and Korean companies. That creates a direct security problem for the United States.
Personnel connected to U.S. Forces Korea, U.S. government employees, and employees of American defense companies also use South Korean telecommunications and financial services. If their financial and personal information is combined, attackers can reconstruct an individual’s daily life and financial circumstances, impersonate the individual or a family member, or select that person for direct targeting. If the information of Americans living near U.S. military installations is exposed, the danger extends beyond ordinary financial fraud into U.S. national security.
Any Pentagon investigation into Chinese influence and access inside South Korea should therefore include the financial sector. If Korean financial institutions or their IT providers stored information concerning U.S.-linked personnel, the United States should determine whether there were China-linked access records or signs that data was transferred outside the network. That is the only way to establish whether South Korea’s financial system has been used to identify or track Americans.
Conclusion: The Question Is Not Only Whether South Korea Is Being Attacked, but Whether It Can Recover
The National Information Resources Service fire, technology losses at universities and research institutes, penetration of government work networks, and failures in the financial sector all point to the same problem. South Korea’s critical systems remain vulnerable to attack, and after an incident the government has repeatedly struggled to determine the full extent of the damage.
That is what the U.S. Department of War should examine. The fact that South Korea is being targeted by China and North Korea is already clear. The more important question is whether the South Korean government can quickly identify the loss of information connected to the United States and immediately notify Washington. The United States should not rely only on government statements from Seoul. It should verify whether the underlying systems can actually protect U.S.-related information.
If South Korea cannot control its national networks, research institutions, and financial systems, China and North Korea do not need to fire a missile to disrupt the country’s basic functions. Information related to the alliance and support for U.S. Forces Korea can be exposed through the same weaknesses. Washington should judge Seoul not by how often it speaks about the alliance, but by whether it can actually protect the information and operating environment on which that alliance depends.
Against this background, South Korea’s Ministry of National Defense announced in July 2026 a proposed revision to its military management regulations that would allow units equipped with CCTV and patrol alternatives to discontinue nighttime sentry duties under certain conditions. If internal military security is increasingly entrusted to CCTV systems, a compromise of those systems could create a back door through which China or North Korea could gain visibility into activities inside South Korean military facilities. At a time when national networks and research institutions have already suffered repeated security breaches, expanding reliance on electronic surveillance inside military installations is not a minor issue. The public comment period for the proposed revision runs through August 10. After the Ministry of National Defense determines whether and in what form the revision will be finalized, I will examine separately how reducing nighttime sentry duties and increasing reliance on CCTV could affect security inside South Korean military installations.
| Sources 1. National Information Resources Service Fire and Government Network Disruption Ministry of the Interior and Safety (MOIS), Restoration of All 709 Systems Affected by the National Information Resources Service Fire (December 30, 2025); Ministry of the Interior and Safety recovery reports and official materials concerning the National Information Resources Service fire; National Police Agency investigation announcements and publicly released investigative materials. 2. Cybersecurity at Universities and Government-Funded Research Institutes Personal Information Protection Commission (PIPC), Administrative Penalties Imposed on Two Universities for Personal Information Breaches Caused by Inadequate Security Measures (June 12, 2025). Board of Audit and Inspection (BAI), Audit of Cybersecurity Management in Public Information Systems (Science and Technology Research Sector) (July 28, 2026). 3. Kimsuky and Government Network Intrusions Phrack Magazine, Issue #72, APT Down: The North Korea Files (August 19, 2025). Korea University Graduate School of Information Security, APT-Down Revisited: Analysis of Nation-State Hacking Materials and Security Implications (August 22, 2025). Ministry of the Interior and Safety, official briefing on the compromise of the On-nara government work system, G-VPN, and GPKI administrative certificates (October 17, 2025). 4. Cybersecurity of Small Contractors, Third-Party Vendors, and the Financial Sector AhnLab ASEC threat analysis reports on the Qilin ransomware campaign (“Korean Leak”) and financial-sector cyber incidents (2025–2026). Korea Internet & Security Agency (KISA), national cyber incident statistics and publicly available cybersecurity reports (2025–2026). Publicly available investigative materials, court filings, and news reports related to the LS Securities case. 5. Ministry of National Defense Military Management Directive Republic of Korea Ministry of National Defense, Public Notice No. 2026-333, Proposed Amendment to the Military Management Directive (July 21, 2026; public comment period through August 10, 2026). |




[…] The Korea Signal 원문 분석 읽기 → ♥ 좋아요 (댓글 0개) […]