Qilin RaaS Exposed 1 Million Files and 2 TB of Data Linked to Korean MSP Breach
ID: 95a4d336-7439-5b22-a99b-2bad27a9f344
STIX ID: report--95a4d336-7439-5b22-a99b-2bad27a9f344
Feed Name: cybersecurityNews.com
**Korean Leaks** is a supply-chain style ransomware campaign that exploited a compromised MSP to rapidly breach multiple South Korean asset management firms; operated by Qilin RaaS affiliates and reportedly partnered with North Korea–linked Moonstone Sleet, the operation published victims in three waves (September 2025), impacted 33 organizations (28 public), and exfiltrated over 1 million files (~2 TB), with recommended defenses including MFA, network segmentation, and EDR/XDR/MDR.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
