기사 메일전송
Yes24 Hit by Ransomware Twice... "Became Hacker's Prey"
  • Yonhap News
  • August 11, 2025 at 2:51 PM
기사수정

Yes24 Hit by Ransomware Twice... "Became a Hacker's Prey"


Government Report "Negotiating with Attackers to Restore Systems Risks Re-infection," Already Warned


Security Industry Emphasizes Thorough Investigation & Decisive Response... "Leaving a Precedent Puts Korean Companies at Risk"


Yes24 HeadquartersYes24 Headquarters [Yonhap News file photo. Reproduction and redistribution prohibited]


Yes24, South Korea's largest online bookstore, has become a target of repeated ransomware attacks, making it difficult to avoid criticism that its response to the first attack two months ago was flawed from the outset.


The situation, where security vulnerabilities were fully exposed, led to the normalization of systems by complying with the criminal group's demands, effectively making them vulnerable to further attacks.


The ransomware attack on Yes24 dates back two months.


Yes24 suffered a service outage for five days on June 9 due to a ransomware hack that paralyzed its app and internet communication network.


At the time, Yes24 did not immediately notify users of the hacking incident and faced public criticism for its opaque response process.


Most notably, it was reported that the situation was resolved by paying virtual assets as ransom to the attackers, raising significant concerns among cybersecurity experts.


Ultimately, another ransomware attack occurred just two months after the initial incident, leading to concerns both within and outside the cybersecurity industry that while the perpetrators are yet to be identified, succumbing to threats could turn companies into prey for hacker groups.


A source told Yonhap News on the 11th, "Ransomware attacks can happen again, and if the fact that negotiations were held with criminals becomes known externally, companies inevitably become a target for hacking groups. First, we need to investigate whether the same ransomware group carried out the re-attack."


Yes24 HeadquartersYes24 Headquarters [Yonhap News file photo. Reproduction and redistribution prohibited]


Another source emphasized, "When a ransomware attack occurs, it is crucial to identify the cause and implement subsequent security measures. It seems that this aspect may have been somewhat insufficient. While restoring internal backup data to ensure uninterrupted service is important, pinpointing the exact cause in cooperation with the government is paramount."


Given the series of major cyberattacks in Korea, including the SK Telecom hacking incident and the repeated ransomware attacks on Yes24 and Seoul Guarantee Insurance, there is a need for systemic improvements such as strengthening response systems and establishing backup systems.


Previously, the Ministry of Science and ICT and the Korea Internet & Security Agency (KISA) pointed out in their first-half cyber threat trend report that one in four companies that reported ransomware attacks did not have a backup system that allowed for rapid recovery in the event of a hack.


Specifically, in the case of Yes24, it was identified that "the most significant problem was the lack of an off-site backup system, such as storing key data in external storage or the cloud, to prepare for ransomware infection."


It further stated, "Ultimately, there were many regrets and concerns expressed by external cybersecurity experts regarding the normalization of systems through negotiation with the attackers (hackers), as well as the risk of re-infection."


The "worst-case scenario" predicted in the government report has now become a reality.


Both within and outside the industry, there is a unified call for a decisive response, warning that if this incident is not handled properly, Korean companies could become targets for international ransomware criminal groups.


An industry source expressed concern, saying, "With Bitcoin prices soaring, it's a favorable market for criminals. If it's confirmed that attacking Korea yields payment, hackers from all over the world could flock here. Yes24 has set a very bad precedent."


The source added, "It's not just telecommunications companies, but also businesses providing public services. The extent to which the government should have legal response authority is also a key point. In this case, given the initial conflict with the government, it is difficult to rule out the possibility that smooth cooperation did not occur in accident investigation and other areas." Yonhap News



What do you think of this article?
recommend
0
great
0
moved
0
정기구독배너
Go to Mobile Site