기사 메일전송
With the Chuseok holiday approaching, network instability... "Fear of hacking has grown"
  • Yonhap News
  • September 29, 2025 at 3:45 PM
기사수정

Network Instability Ahead of Chuseok Holiday... "Fear of Hacking Grows"


Concerns arise over firewall and intrusion detection system paralysis due to National Resource Management Office fire


Vulnerability of Onnara system pointed out... Security alert for Chuseok holiday


Amidst the paralysis of 600 major administrative information systems due to a fire at the National Resource Management Office in Daejeon, concerns are mounting that cyberattacks could intensify during this period of service instability.


The government estimates approximately four weeks will be required to relocate the 96 completely destroyed systems to the Daegu National Resource Management Center, signaling a period of cybersecurity vulnerability lasting nearly a month.


Experts have warned that hackers may exploit the government's weakened cybersecurity during the upcoming Chuseok holiday to launch intensified attacks, urging for swift and robust defense measures.


The National Intelligence Service oversees the management of the government's information systems, and no specific countermeasures have been disclosed yet.


IT Security Incident (PG)IT Security Incident (PG) [Illustration by Kang Min-ji]


◇ Government Systems on High Alert After National Resource Management Office Fire


The fire at the National Resource Management Office's computer room has likely led to the destruction or paralysis of security equipment, such as firewalls and intrusion detection systems (IDS), for administrative information systems.


These systems detect threats from traffic entering from outside to inside the network. In terms of home security, this situation is akin to CCTV cameras or surveillance sensors designed to catch intruders being burned or damaged.


A cybersecurity expert analyzed on the 29th, "Although further investigation into the internal situation is needed, it is reasonable to assume that a security gap may arise in government administrative systems if the equipment needs to be repaired or replaced."


He added, "It is crucial to first determine whether only the security equipment is affected or if interconnected systems have also sustained damage and need replacement. If the interconnected security systems are operational but the equipment is paralyzed and has stopped functioning, swift action is required."


Professor Yoon Joo-beom of Sejong University's Department of Information Security expressed concern, stating, "It is understood that information protection systems are also being recovered along with the paralyzed servers and equipment due to this fire. The risk of hacking can be considered significantly increased until full recovery."


Professor Yoon advised, "It is regrettable that security concerns might have been lower if the cloud disaster recovery (DR) system was well-established, but this is a long-term issue. For now, it is urgent to prioritize the swift normalization of systems and enhance security through manual defense methods."


This suggests implementing manual monitoring by additional security experts or employing artificial intelligence (AI)-based defense measures to block cyber intrusions that were previously handled by firewalls or automatic detection systems.


Anticipating a surge in security demand following the National Resource Management Office fire, the stock prices of cybersecurity companies saw a sharp rise as soon as the stock market opened on the 29th.


Financial authorities have also stated their preparedness for a potential increase in cyber incidents such as hacking, taking advantage of the current chaos.


Joint Investigation of National Resource Management OfficeJoint Investigation of National Resource Management Office (Daejeon=Yonhap News) Reporter Kim Jun-beom = On the morning of the 29th, police officials are inspecting the condition of the Uninterruptible Power Supply (UPS) lithium-ion batteries that caught fire at the National Resource Management Office (National Resource Management) in Yuseong-gu, Daejeon. Previously, a lithium-ion battery fire occurred at the National Resource Management Office, which houses government computer systems, on the 26th, causing a large-scale paralysis of government computer services. 2025.9.29 psykims@yna.co.kr


◇ Onnara System, Identified as Already Breached, Faces Hacking Threat


Amidst the overall weakened security of administrative information systems due to the National Resource Management Office fire, the "Onnara System," an internal work network, has been identified as requiring the most urgent action.


The Onnara System is a network used to integrate document creation, approval, and other tasks across all government ministries and was included in the list of 96 major administrative information systems that were completely destroyed in the fire.


The US cybersecurity publication 'The Hacker's Journal' reported, citing white hat hackers who re-hacked cyber attackers identified as having breached South Korean government agencies and telecommunication companies last month, that the Onnara System may have been attacked.


There were claims that hackers obtained various information from this system, including official documents, reports, and meeting minutes. If these claims are valid, it implies that vulnerabilities within the Onnara System may have already fallen into the hands of hackers.


Concerns are rising that this information could be exploited to further increase the risk of breaches during the current service paralysis period.


'The Hacker's Journal' also analyzed that government systems, including those of the Ministry of the Interior and Safety, the Ministry of Foreign Affairs, the Ministry of Unification, and the Ministry of Oceans and Fisheries, were also hacked. This highlights the need for enhanced security in these administrative agencies following the National Resource Management Office fire.


A security expert commented, "It seems easier for hackers who are not usually active to plan criminal activities in the current situation, and there is a risk that information shared on the dark web could be misused. Vigilance is particularly required as the Chuseok holiday is approaching."


Meanwhile, following the paralysis of administrative information systems, the financial sector and others have been issuing numerous guidance messages via text and KakaoTalk regarding identity verification and document issuance procedures. This is expected to lead to an increase in smishing and voice phishing crimes that mimic these communications.


A representative from the Korea Internet & Security Agency (KISA) stated, "While it does not appear to be at an alert level yet, we are strengthening monitoring in preparation for an increase in smishing and phishing attempts." Yonhap News



What do you think of this article?
recommend
0
great
0
moved
0
정기구독배너
Go to Mobile Site