

The National Information Resources Service Fire, University and Government Hacks, and the Kimsuky–Phrack Files Expose Deep Vulnerabilities in South Korea’s National Systems
By Jean CummingsCo-Editor, The Korea Signal
South Korea’s digital security crisis is no longer confined to one ministry or one network. It has spread across government systems, university research networks, the financial sector, and the contractors that support major corporations and public institutions. These are the systems that hold government data, advanced technology, and the assets of ordinary citizens.
The incidents involving government agencies, universities, corporations, and financial institutions should not be treated as isolated cases. A security failure at one point can provide access to systems far beyond the original target.
The National Information Resources Service is one of the government’s most important data facilities. Storing original data and backup data in the same computer room was not a minor administrative mistake. It was clear evidence of how carelessly the South Korean government had managed critical national information systems.
Universities present the same problem. Several Korean universities left security vulnerabilities uncorrected for years, while government-affiliated research institutes could not even determine where hard drives used by former employees had gone. After government remote-work systems and public employee certificates were compromised, a financial company later executed stock sales and overseas transfers based on emails sent by someone impersonating a customer.
South Korea’s systems are vulnerable enough that an attacker does not necessarily need to penetrate the central server of a government agency. Compromising the administrator account of an outside contractor can provide access to the institution that contractor manages. When stolen government certificates and weak customer-verification procedures at financial institutions can also be exploited, the consequences can extend beyond Korean government systems and private assets to information shared with the United States.
South Korean government, research, and military-related systems also contain information connected to the United States and U.S. Forces Korea. South Korea’s security failures therefore create a direct security risk for the United States.
The National Information Resources Service Fire and the Collapse of Government IT Systems
On September 26, 2025, a lithium-ion battery fire broke out at the Daejeon headquarters of the National Information Resources Service. The fire disabled hundreds of government information systems, including Government24, mobile identification services, the national petition system, postal and customs-related services, civil-service platforms, and internal government work systems. The Ministry of the Interior and Safety ultimately reported that 709 systems were affected.
One of the most seriously damaged systems was G-Drive, the work-data repository used by central government officials. More than 191,000 officials from 74 agencies used the system, which stored approximately 858 terabytes of data. The government later said that the data could not be recovered because no separate backup existed. At a time when South Korea faces repeated cyber penetration attempts from China and North Korea, it was reasonable to question why a system containing large volumes of government work product was destroyed without recoverable backup.
You are unauthorized to view this page. Please log in to read this page in full.
이 페이지를 보실 권한이 없습니다. 이 글 전문과 한글 버전을 읽으시려면 로그인을 먼저 해주십시오.
Please renew your membership or subscribe a membership if you didn't yet. Thank you.
멤버십을 갱신하시거나, 만약 구독하지 않으셨다면 구독을 먼저 해주시기 바랍니다. 감사합니다.
정기구독 신청하기 ← click here to subscribe. 여기를 클릭해서 구독해 주세요.




[…] The Korea Signal 원문 분석 읽기 → ♥ 좋아요 (댓글 0개) […]