logo

Qilin RaaS Exposed 1 Million Files and 2 TB of Data Linked to Korean MSP Breach

ID: 95a4d336-7439-5b22-a99b-2bad27a9f344

STIX ID: report--95a4d336-7439-5b22-a99b-2bad27a9f344

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-11-27

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Korean Leaks** is a supply-chain style ransomware campaign that exploited a compromised MSP to rapidly breach multiple South Korean asset management firms; operated by Qilin RaaS affiliates and reportedly partnered with North Korea–linked Moonstone Sleet, the operation published victims in three waves (September 2025), impacted 33 organizations (28 public), and exfiltrated over 1 million files (~2 TB), with recommended defenses including MFA, network segmentation, and EDR/XDR/MDR.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.