HomeSecuritySouth Korea: Kyowon Group suffers ransomware attack

South Korea: Kyowon Group suffers ransomware attack

Kyowon Group , one of South Korea 's most established business groups, has revealed a serious cybersecurity incident, confirming that a ransomware attack caused widespread disruption to its operations and the possible exposure of customer data . The case adds to a long list of cyberattacks that have hit major Korean companies in recent years.

Kyowon ransomware

From suspicious activity to confirmed ransomware incident

Kyowon announced earlier this week that it had detected suspicious malicious activity on its systems, without providing details. In a later update, the company confirmed that it was a ransomware attack, in which the perpetrator gained unauthorized access and stole data.

Although the company avoided specifying the exact scope of the leak, it admitted that an external data leak occurred, which has raised alarm among both customers and the competent authorities.

See also: Betterment: Hackers gained access to internal systems

Who is the Kyowon Group and why is the attack significant?

Kyowon Group is a major player in the Korean market, with businesses ranging from education and publishing to digital learning tools, hospitality and a wide range of consumer services. The size and diversity of its operations explain why the incident is considered high-risk.

South Korea: Kyowon Group suffers ransomware attack

According to Korean media, Kyowon manages more than 9.6 million registered accounts, corresponding to approximately 5.5 million individuals. This means that if a leak of personal data, the consequences could be far-reaching.

Extensive technical damage to systems

The same reports state that the ransomware attack affected approximately 600 of Kyowon's 800 servers, a figure that demonstrates the extent of the technical damage. The service outages were felt by users, leading the company to immediately publicly acknowledge the incident.

See also: Monroe University: 2024 data breach affects 320,000 people

Kyowon said it immediately notified the Korea Internet and Security Agency (KISA) and began working with cybersecurity experts to fully investigate the attack.

Scope of data leak unclear

In its latest official statement , the company confirmed that the attacker had obtained some data, but it is not yet clear whether any personal customer information. Kyowon pledged that if a user data leak is confirmed, there will be transparent and immediate information.

South Korea: Kyowon Group suffers ransomware attack

At the same time, the restoration work of online services is in the final stage, aiming for a full return to normality.

No claim of responsibility from ransomware group – for now

So far, no known ransomware group has publicly claimed responsibility for the attack, leaving open questions about both the identity of the perpetrators and whether the data will be released or sold. Journalistic attempts to obtain further comment from Kyowon have not yielded results by the time of publication.

See also: AZ Monica Hospital: Servers offline due to cyberattack

Escalation of cyberattacks in South Korea

The Kyowon case is part of a worrying pattern of massive breaches in South Korea. In December 2025, Coupang disclosed a data breach affecting 33.7 million customers, while Korean Air announced an incident that exposed employee personal information. Meanwhile, SK Telecom admitted that malware from 2022 had led to the leak of USIM data of 27 million subscribers. Around the same time, Dior’s Korean store confirmed a customer order data leak.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

These successive attacks highlight the increasing pressure on the country's large businesses and the importance of investing in modern, resilient cybersecurity strategies.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS