logo

A ransomware attack disrupted operations at South Korean conglomerate Kyowon

ID: 2d0966aa-494e-5b96-8422-af1ea7a53ffe

STIX ID: report--2d0966aa-494e-5b96-8422-af1ea7a53ffe

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-01-15

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Kyowon Group confirmed a ransomware intrusion detected on January 10 that disrupted services across core subsidiaries, infected an estimated 600 of 800 servers, and may have exposed up to 9.6 million user accounts; the attacker leveraged an exposed external port to gain access, move laterally, and deploy ransomware, and investigators including KISA and external cybersecurity experts are assessing the impact and data breach scope.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.