The “Korean Leaks” campaign has rapidly become one of the most significant and sophisticated supply chain attacks to hit South Korea’s financial sector in recent years.
This operation combined the efforts of the Qilin Ransomware-as-a-Service (RaaS) group with suspected support from North Korea–aligned threat actors known as Moonstone Sleet. By compromising a Managed Service Provider (MSP), the attackers gained a single, powerful entry point into multiple financial organizations.
In September 2025, South Korea rose to the second most-targeted nation for ransomware attacks, with Qilin claiming 25 victims in just one month. The group heavily focused on financial services, especially asset management firms. Out of 33 confirmed victims, 28 have been publicly identified so far, with more than 1 million files and 2 TB of data verified as stolen.
Bitdefender researchers found that Qilin operates like a gig-based cybercrime ecosystem. Core operators handle branding, development, and infrastructure—retaining 15% to 20% of profits—while affiliates carry out the intrusions and earn the bulk of the revenue. The partnership formed in early 2025 between Qilin and Moonstone Sleet added a layer of geopolitical concern, blurring boundaries between criminal ransomware activity and state-linked espionage.
The campaign unfolded in three public data-release waves.
- Wave 1 (September 14, 2025): Ten victims were listed, with Qilin framing the leaks as an effort to expose corruption.
- Wave 2: The group escalated its rhetoric, threatening the broader Korean stock market.
- Wave 3: Nine more victims were exposed before the attackers shifted back to traditional extortion messaging.
Investigators found that the concentration of affected firms within the same financial niche pointed to a shared underlying vulnerability. Reports on September 23, 2025 confirmed that more than 20 asset management companies were breached after attackers infiltrated servers operated by a common domestic IT service provider. This MSP compromise enabled the adversaries to hit multiple targets rapidly and systematically.
To mitigate risks from similar supply chain attacks, experts recommend implementing multi-factor authentication (MFA), segmenting networks to limit lateral movement and deploying EDR, XDR, or MDR solutions to reduce attacker dwell time.
These measures are critical for disrupting large-scale ransomware operations that exploit trusted service providers as a single point of compromise.

















Comments