Kyowon Group, a major South Korean education and lifestyle conglomerate, confirmed it suffered a ransomware attack that disrupted operations and forced the company to shut down parts of its internal network to contain the incident. Kyowon reported detecting abnormal activity and isolating affected servers, with multiple affiliate websites and services becoming inaccessible during recovery efforts. The company said it notified the Korea Internet & Security Agency (KISA) and is working with government authorities and external security specialists to investigate the cause and scope.
Kyowon stated there are indications of external data leakage and later confirmed that an attacker exfiltrated data, while it continues to determine whether customer information was included. Korean media reporting cited in coverage suggested the potential exposure could involve millions of accounts and that a large portion of Kyowon’s server estate may have been impacted; reporting also indicated the attackers issued an extortion demand. Kyowon said it will provide transparent updates and notify customers if the investigation confirms customer data was affected.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
By 2026-01-14, South Korean media and authorities reported that up to 9.6 million registered accounts, representing about 5.5 million unique individuals, could be impacted. Concerns included possible exposure of personal information across multiple subsidiaries.
On 2026-01-14, Kyowon publicly confirmed it suffered a ransomware attack involving data exfiltration. The company said an attacker had stolen data and that it was investigating whether customer information was included.
In the days following the intrusion, the incident caused major operational disruption across Kyowon affiliates, with several education and travel-related websites becoming inaccessible. Reporting indicated the compromise may have affected roughly 600 of the company's 800 servers.
After detecting the attack, Kyowon notified the Korea Internet & Security Agency and other investigative authorities. It also engaged external security experts and government agencies to investigate the cause, scope, and impact.
On 2026-01-10, Kyowon Group detected abnormal activity consistent with a ransomware attack. The company isolated affected servers, shut down parts of its internal network, and started restoration efforts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
rescana.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.