North Korean hackers had breached the network of Seoul National University Hospital (SNUH), one of the largest hospitals in Seoul, to steal sensitive medical information and personal details.
The incident occurred between May and June 2021 by using seven servers in South Korea and other countries to launch the attack on the hospital’s internal network.
The Korean National Police Agency (KNPA) conducted an analytical investigation during the past two years to identify the perpetrators.
The attack was attributed to North Korean hackers based on the intrusion techniques, the IP addresses that have been independently linked to North Korean threat actors, the website registration details and the use of specific language and North Korean vocabulary.
Even though the police’s report does not mention any particular threat group, the local media in South Korea linked the attack to the Kimsuky hacking group.
The breach resulted in data exposure for 831,000 individuals, most of whom were patients. Also, 17,000 of the impacted people are current and former hospital employees.
The KNPA press release warns that North Korean hackers might try to infiltrate information and communication networks across various industries. It emphasized the need for enhanced security measures and procedures, such as implementing security patches, managing system access, and encrypting sensitive data.
Image Credits : Cybercrime Magazine














Comments