South Korea faced repeated large-scale cyberattacks that disrupted banks, broadcasters, and government-facing online services, with incidents ranging from distributed denial-of-service activity against public websites to destructive attacks that knocked out internal computer networks. In one wave, attackers targeted major South Korean institutions including a leading bank, a national newspaper, and the country’s intelligence service, while related attacks also hit U.S. government websites such as the White House, Pentagon, and State Department. Officials described those operations as primarily disruptive to public-facing services rather than breaches of internal systems.
In a later major incident, computer networks at broadcasters KBS, MBC, and YTN, along with Shinhan Bank and Nonghyup, were crippled, interrupting ATMs, payment terminals, and mobile banking even as television broadcasts remained on air. South Korean authorities raised cyber alert levels, sent investigative teams, and increased military cyber readiness amid heightened regional tensions and longstanding concern over North Korea’s cyber capabilities, though officials said attribution remained unconfirmed and warned that identifying the true source could take months; some compromised machines reportedly displayed messages from a group calling itself "WhoisTeam."

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
Following the March 2013 disruption, authorities raised the national cyber alert level, dispatched investigative teams, and increased military cyber readiness while investigating the cause of the attack.
Computer systems at broadcasters KBS, MBC, and YTN and banks Shinhan and Nonghyup were disrupted in a suspected cyberattack, affecting ATMs, payment terminals, and mobile banking while television broadcasts remained on air. Some compromised machines displayed messages from a group calling itself 'WhoisTeam,' though attribution was not established.
In response to the 2009 attacks, South Korea said it would speed up plans to establish a cyber warfare unit to improve its ability to counter similar incidents.
By the third day of the 2009 campaign, suspected coordinated attacks were targeting additional South Korean sites including a major bank, a leading newspaper, and the national intelligence service. Officials said the attacks were disruptive to websites rather than internal systems, and no evidence had confirmed speculation of North Korean involvement.
A wave of denial-of-service attacks began earlier in the week, disrupting public-facing websites in both the United States and South Korea, including U.S. government sites such as the White House, Pentagon, and State Department.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
theguardian.com
Open sourcenytimes.com
Open sourceweb.archive.org
Open sourcenews.bbc.co.uk
Open sourcenews.bbc.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.