Seoul National University Hospital is facing renewed scrutiny over its cybersecurity posture after reports highlighted that it did not submit cybersecurity disclosures from 2022 through the current year, even as it dealt with major security incidents. The hospital, identified as the only one among South Korea’s "Big 5" hospitals not to file such disclosures during that period, had previously suffered a North Korea-linked breach confirmed in 2023 that exposed personal information belonging to about 830,000 patients and staff.
Reports said the hospital was exempt from the disclosure requirement because it is classified as a public institution, complicating claims of non-compliance. Even so, the lack of filings has drawn attention because another patient-affecting breach was reported several months ago, and the case has intensified broader concerns about whether the more serious issue is not disclosure paperwork but the adequacy of cybersecurity protections at a major medical institution amid rising attacks on South Korea’s healthcare sector.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
The hospital's breach exposing personal information of about 830,000 patients and staff was confirmed in 2023 and attributed to a North Korean cyberattack. The incident is cited as a major example of the hospital's security problems.
An investigation found that Seoul National University Hospital did not file cybersecurity disclosures from 2022 through the current year, making it the only one among South Korea's Big 5 hospitals not to do so during that period. The hospital was described as exempt from the requirement because it is classified as a public institution.
The reporting says another breach affecting patients at Seoul National University Hospital occurred several months before the article. No more precise date is provided in the references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.