Cyberattacks against South Korean government agencies and local authorities surged in the first seven months of this year, adding to a run of security incidents that has already hit some of the country’s biggest companies.
Security systems at 44 central government agencies and 17 metropolitan and provincial governments flagged 1.57 billion suspected attacks from January through July, according to data obtained by Democratic Party lawmaker Park Jung-hyun.
That works out to about 7.4 million a day and is already 33 percent higher than the total recorded during all of 2025.
Officials later screened those alerts for false positives and other irrelevant activity. They confirmed 353,748 cases as actual attacks. Central government agencies were the targets in 90 percent of them. Nineteen of the 44 agencies had already exceeded their 2025 totals by July, with the total up 26.3 percent overall.
The numbers were released days after another case put government systems under scrutiny.
A hacker believed to be Chinese claimed earlier this month to have breached 88 Korean government bodies and more than 20 companies over six days. The hacker said the stolen material included personal, financial and military information. Authorities have not confirmed the full scope of the claims and are checking the material provided. Some companies named by the hacker disputed parts of the account.
Other public-sector cases have raised questions over how long breaches can go unnoticed. Seoul’s public bicycle service Ttareungi was hacked in June 2024, exposing information tied to about 4.62 million users. The breach was uncovered later during a separate police investigation.
Most cases are not uncovered or handled by the police, however.
An Interior Ministry official said government agencies notify the National Intelligence Service when a hacking incident occurs. Police or prosecutors are generally contacted only when there is clear evidence of a criminal offense.
“The NIS, as the agency overseeing cybersecurity in the public sector, is responsible for sharing hacking-related information with local governments and the private sector,” the official said.
The rise in public-sector attacks comes after a string of major breaches in the private sector.
Coupang disclosed in November 2025 that information tied to 33.7 million customer accounts had been exposed. Lotte Card said two months earlier that a breach affected 2.97 million customers. KT also reported a network intrusion involving about 20,000 subscribers and unauthorized mobile payments. This month, a government investigation found that a June attack on streaming service TVING compromised about 39.54 million accounts, although the figure includes multiple accounts held by the same users.
Separate KISA data shows that companies and other organizations reported 8,565 cyber incidents between 2021 and June this year. Annual reports rose from 640 in 2021 to 2,383 last year. Another 1,236 were filed in the first half of 2026. Small and medium-sized businesses accounted for 81.6 percent of the total.
Korea tightened its data protection law on Sept. 11, allowing fines of up to 10 percent of total revenue in some repeated or large-scale breaches involving intentional misconduct or gross negligence.
mjh@heraldcorp.com
