The South Korean government is under threat from hacking attacks that could expose sensitive information about the state's nuclear power plants. The hackers are demanding a ransom to keep the information from being published.
KHNP claims nothing was stolen.
In December 2014, the Korea Hydro and Nuclear Power (KHNP) plant in South Korea was attacked by a hacker called “Who am I = No nuclear power,” which has since released technical documents and personnel information from the plant.
Additional information was revealed regarding the plant's computer systems (Monte Carlo N–Particle computer code (MCNP5)), including its user manual, which information is accessible via the Internet without any restriction.
The Hackersare based in South Korea.
The latest publication of the stolen files, the sixth in a series, related to the nuclear reactor (APR) 1400, was posted on the social networking site Twitter by a user under the name of an anti-nuclear group in Hawaii.
KHNP admitted to the attack that took place in December, but despite this - as it claims - this attack did not affect the safety of the nuclear plant.
the hackers initially appeared to be based in Hawaii, after extensive investigations it turned out that the attack was carried out from South Korea.
The ransom amounts to hundreds of thousands of dollars.
According to press reports, his message said: "I need money. There are many countries in Northern Europe, South Asia and America that would be willing to buy this information about nuclear plants. The fear that all of this information will be sold will undermine the President's efforts to export nuclear reactors.".
The hackers did not disclose the amount of ransom they are demanding, but they warned the South Korean government that by trying to save a few hundred million dollars, it ultimately runs the risk of losing much more.
KHNP claims that the latest information leaked by the hacker group does not include any significant information and data, and that this data could have been obtained early last year, before the internal server crashed and stricter security measures were taken.
