Ransomware Attacks on Korean Companies More Than Triple in First Half
Confirmed ransomware cases involving Korean companies rose to 36 in the first half of 2026, more than three times the year-earlier level, as a widening field of criminal groups targeted local businesses.
Ransomware attacks affecting South Korean companies rose sharply in the first half of 2026, highlighting the expanding reach and organization of cybercrime groups targeting the country’s businesses.
S2W, a South Korean cyber threat intelligence company, said 36 ransomware cases involving domestic organizations were confirmed during the six-month period. That was more than 3.3 times the level recorded a year earlier. The increase was not attributed to a single burst of activity by one group. Instead, S2W found that multiple ransomware operators had continued to target Korean companies, suggesting that local businesses have become established targets within the global ransomware market.
The rise in Korea formed part of a broader international increase. S2W counted 5,984 victim organizations worldwide in the first half, up by 1,555 from the same period in 2025. It identified 119 active ransomware groups, including 44 that had newly emerged.
The growth of ransomware-as-a-service has helped widen the pool of attackers. Under that model, developers provide malicious software and supporting infrastructure to affiliates, who carry out intrusions and share the proceeds. The arrangement lowers the technical barrier to launching attacks and allows specialized participants to handle different stages, including access, data theft, negotiations and publicity.
Despite the large number of operators, attacks remained concentrated among the biggest groups. The 10 most active organizations accounted for 54.3 percent of the total. A newcomer identified as 0APT was linked to attacks on about 481 organizations during the first half alone. S2W also named Qilin, PLAY, LockBit, Interlock and INC among the period’s major high-risk ransomware groups.
Manufacturing sustained the largest number of reported incidents globally. The sector recorded 612 victims, compared with 330 a year earlier. Manufacturers are particularly exposed because production and logistics often depend on continuously available information technology systems, making operational disruption costly.
Attack methods have also moved beyond simply encrypting systems. Criminal groups increasingly steal internal data before demanding payment, using the threat of disclosure as additional leverage. Some groups now operate with a division of labor resembling a business, assigning separate teams to development, penetration, negotiations, analysis of stolen files and promotion of leaked information.
The figures indicate that ransomware risk for Korean companies is broadening across both the number of potential attackers and the sophistication of their operations. The trend raises the importance of resilient backups, rapid detection, access controls and incident-response planning, particularly for businesses whose operations can be halted by system outages.
