Cyberattacks Surge Across South Korea’s Public Sector
South Korean public agencies confirmed more than 353,000 cyberattacks in the first seven months of 2026, as mounting incidents across government and business sharpen concerns over national digital security.
Cyberattacks against South Korean government agencies and local authorities rose sharply in the first seven months of 2026, adding pressure on officials to strengthen defenses across the country’s public digital infrastructure.
Security systems operated by 44 central government agencies and 17 metropolitan and provincial governments flagged 1.57 billion suspected attacks between January and July. That was equivalent to roughly 7.4 million alerts a day and already 33 percent more than the number recorded during all of 2025.
After screening out false positives and irrelevant activity, officials confirmed 353,748 cases as actual attacks. Central government agencies accounted for 90 percent of those cases. Nineteen of the 44 agencies had surpassed their full-year 2025 totals by July, while the confirmed attack count across the central government was up 26.3 percent overall.
The figures emerged amid scrutiny of a separate claim by a hacker believed to be Chinese. The hacker said earlier this month that 88 Korean government bodies and more than 20 companies had been breached over six days, with personal, financial and military information among the material allegedly taken. Authorities have not confirmed the full scope of the claim and are examining the material, while some companies named in the account have disputed parts of it.
Earlier incidents have also highlighted how long intrusions may remain undetected. Seoul’s Ttareungi public bicycle service was hacked in June 2024, exposing information linked to about 4.62 million users. The breach was discovered later during an unrelated police investigation. An Interior Ministry official said agencies notify the National Intelligence Service when hacking occurs, while police or prosecutors generally become involved only when there is clear evidence of a criminal offense.
The rise in attacks on public institutions follows major private-sector breaches. Coupang disclosed in November 2025 that information tied to 33.7 million customer accounts had been exposed. Lotte Card reported a breach affecting 2.97 million customers, and KT identified a network intrusion involving about 20,000 subscribers and unauthorized mobile payments. A government investigation this month also found that a June attack on streaming platform TVING compromised about 39.54 million accounts, including multiple accounts held by individual users.
Separate Korea Internet & Security Agency data showed 8,565 cyber incidents reported by companies and other organizations from 2021 through June 2026. Annual reports climbed from 640 in 2021 to 2,383 in 2025, with another 1,236 filed in the first half of this year. Small and medium-sized businesses represented 81.6 percent of the total.
South Korea tightened its data protection law on Sept. 11, allowing fines of up to 10 percent of total revenue in certain repeated or large-scale breaches involving intentional misconduct or gross negligence. The escalating volume of attacks suggests enforcement will need to be matched by faster detection, information sharing and security investment across both government and business.
