HomeSecurityNorth Korean hackers breached a major hospital in Seoul

North Korean hackers breached a major hospital in Seoul

The Korean National Police Agency (KNPA) warned that North Korean hackers breached the network of one of the country's largest hospitals, Seoul National University Hospital (SNUH), to steal sensitive medical information and personal details.

See also: Hacker Joseph James O'Connor confessed to hacking into celebrity Twitter accounts

North Korean hackers
North Korean hackers breached a major hospital in Seoul

See also: Google: Offers dark web report to Gmail users in the US

The incident occurred between May and June 2021 and the police have been conducting a thorough investigation over the past two years to identify the perpetrators.

According to the law enforcement agency's press release, the attack was attributed to North Korean hackers, based on the following information:

  • the intrusion techniques observed in the attacks
  • IP addresses that have been independently linked to North Korean threat actors
  • the website registration details
  • the use of specific North Korean language and vocabulary

Local media in South Korea linked the attack to the hacking group Kimsuky, but the police report does not explicitly mention the specific threat group.

The attackers used seven servers in South Korea and other countries to launch an attack on the hospital 's internal network .

Police said the incident resulted in the exposure of data for 831,000 people, most of whom were patients; 17,000 of the people affected were current and former hospital employees.

The KNPA press release warned that North Korean hackers may attempt to infiltrate information and communications networks across various industries, emphasizing the need for enhanced security measures and procedures, such as implementing security patches, managing system , and encrypting sensitive data.

North Korean hackers breached a major hospital in Seoul

See also: RapperBot botnet: New version with cryptomining capabilities

North Korean hackers have been linked in the past to intrusions into hospital networks, aiming to steal sensitive data and extort ransom from healthcare organizations.

More specifically, the US government has flagged the Maui ransomware threat as such, warning the healthcare sector that it needs to increase its defenses against the North Korean operation.

Immediately after this warning, Kaspersky security researchers linked the Maui ransomware operation to a specific activity group called Andariel (also known as “Stonefly”), which is believed to be a subgroup of Lazarus.

The Lazarus group is known for targeting South Korean entities with ransomware since April 2021.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS