The Korean National Police Agency (KNPA) warned that North Korean hackers breached the network of one of the country's largest hospitals, Seoul National University Hospital (SNUH), to steal sensitive medical information and personal details.
See also: Hacker Joseph James O'Connor confessed to hacking into celebrity Twitter accounts

See also: Google: Offers dark web report to Gmail users in the US
The incident occurred between May and June 2021 and the police have been conducting a thorough investigation over the past two years to identify the perpetrators.
According to the law enforcement agency's press release, the attack was attributed to North Korean hackers, based on the following information:
- the intrusion techniques observed in the attacks
- IP addresses that have been independently linked to North Korean threat actors
- the website registration details
- the use of specific North Korean language and vocabulary
Local media in South Korea linked the attack to the hacking group Kimsuky, but the police report does not explicitly mention the specific threat group.
The attackers used seven servers in South Korea and other countries to launch an attack on the hospital 's internal network .
Police said the incident resulted in the exposure of data for 831,000 people, most of whom were patients; 17,000 of the people affected were current and former hospital employees.
The KNPA press release warned that North Korean hackers may attempt to infiltrate information and communications networks across various industries, emphasizing the need for enhanced security measures and procedures, such as implementing security patches, managing system , and encrypting sensitive data.

See also: RapperBot botnet: New version with cryptomining capabilities
North Korean hackers have been linked in the past to intrusions into hospital networks, aiming to steal sensitive data and extort ransom from healthcare organizations.
More specifically, the US government has flagged the Maui ransomware threat as such, warning the healthcare sector that it needs to increase its defenses against the North Korean operation.
Immediately after this warning, Kaspersky security researchers linked the Maui ransomware operation to a specific activity group called Andariel (also known as “Stonefly”), which is believed to be a subgroup of Lazarus.
The Lazarus group is known for targeting South Korean entities with ransomware since April 2021.
Information source: bleepingcomputer.com
