Safeware Glasswall APAC Partner
Book a demo

Explore

What is CDRZero TrustThe detection gapCapabilitiesUse cases

Products

ProductsIntegrationFile support

Compliance

Control alignmentAPAC regulatory landscape
Country guidesSingaporeAustraliaJapanSouth KoreaIndiaIndonesiaMalaysiaThailandVietnamPhilippinesTaiwanNew ZealandMongolia

More

Trust & certificationsInsightsPartnersAboutDocumentation Book a demo

Language

EnglishBahasa Indonesia日本語한국어Bahasa MelayuไทยTiếng Việt简体中文繁體中文

File-borne breach events · East Asia

South Korea: documented file-borne breach events

Korea's record runs from prosecutor-documented weaponised HWP documents at a nuclear operator to the privacy regulator's recent penalties over malicious files uploaded straight through web upload functions, including a decision issued in August 2026.

Overview

What the record shows

South Korea documents two distinct file-borne patterns, through two different kinds of authority. The older pattern is the targeted email: the December 2014 attack on Korea Hydro and Nuclear Power was investigated by the Seoul Central District Prosecutors' Office, which counted the campaign in thousands of emails carrying malicious code, with the payload in weaponised Hangul Word Processor documents. That format detail matters, because a domestic document format in universal government and enterprise use became the carrier, exploited faster than signature-based controls could describe it.

The newer pattern comes from the Personal Information Protection Commission, and it is the upload rather than the inbox. Its penalty decisions repeatedly describe attackers uploading malicious files through a site's own file upload function and then executing the code inside them, with the commission faulting the absence of file type validation and execution restrictions. Those decisions are recent, name the companies and state the mechanism, which is rarer than it should be.

Korea's largest recent penalties are not on this page. The commission's decisions against several household names record only that an employee device was infected with malware, without stating how, and one major case is documented as voice phishing. This record does not fill those silences in.

Documented events

File-borne incidents in South Korea

Most recent first. Every entry cites the public record it is drawn from.

  1. File uploadHigh impact

    Modetour Network Inc.: Three million records taken after web shell files were uploaded through the site's own upload function

    Personal data of about 3.06 million members and non-members was exfiltrated from the travel agency following the June 2024 intrusion. In March 2025 the commission imposed penalties totalling about 757 million won, and found that notification had been made two months late.

    The documented vector. Multiple web shell files uploaded through a file upload vulnerability, then executed. The Personal Information Protection Commission's decision records that the attacker exploited a file upload vulnerability to upload multiple web shell files, and executed the malicious code present in those files. The commission found neither file extension validation nor restrictions on execution permissions were in place.

    How this class of vector is removed

    This class of vector arrives through the upload form rather than the inbox, and it is the case a CDR hop on the ingestion path is built for: every uploaded file is routed for rebuild to its format's known good specification, and content with no document format to be rebuilt against, which is what a web shell script is, is blocked or quarantined by policy rather than written to a location that can execute it. Foresight scores structure ahead of that decision. This is a stronger form of the file type validation the commission found absent, because it does not rely on the declared extension.

    ICAP ClientContent Disarm and ReconstructionForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight

    • travel

    Source: Personal Information Protection Commission

  2. File uploadMedium impact

    HD Korea Shipbuilding & Offshore Engineering and HD Hyundai Construction Equipment: Web shell uploaded through a mobile device management server exposed employee records

    Names and employee identifiers of 9,503 employees and partner staff were exposed following the March 2024 intrusion at the two group companies. The commission issued its decision on 26 August 2026, imposing penalties totalling about 78 million won.

    The documented vector. Web shell file uploaded by exploiting a vulnerability in a mobile device management server. The Personal Information Protection Commission's decision records that the attacker uploaded a web shell file by exploiting a vulnerability in the mobile device management server, and then moved laterally. The commission penalised the file upload safeguard failure alongside the absence of network segmentation.

    How this class of vector is removed

    The same class of vector as the upload cases the commission has penalised elsewhere: a file written through a management interface and then executed. A CDR hop on that ingestion path rebuilds accepted files to their format's known good specification and gives content that cannot be rebuilt, such as a server side script, no route to a location where it can run. The mapping is held at medium confidence because the upload here ran through a management server interface rather than a user facing upload form.

    ICAP ClientContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • manufacturing

    Source: Personal Information Protection Commission · Source: Seoul Economic Daily

  3. Email attachmentHigh impact

    Interpark: Over 10 million customers' data stolen after one tailored malware attachment was opened

    Attackers intruded into the online retailer Interpark in May 2016; the breach was discovered on 11 July 2016 after a 3 billion won bitcoin extortion demand. Personal data of more than 10 million customers, around 26.6 million data items including identifiers, phone numbers and addresses, was stolen. The ICT Ministry and the Korea Communications Commission published investigation findings, and the National Police Agency attributed the operation to North Korea's Reconnaissance General Bureau.

    The documented vector. Malware attachment on a spear-phishing email crafted to match a targeted employee's routine correspondence. Attackers studied a specific Interpark employee's email patterns and delivered malware in an attachment styled as routine correspondence. The published investigation account states that once the employee opened the malware attachment, the infection spread through Interpark's networked computers.

    How this class of vector is removed

    This class of vector, a malware attachment tailored to look like routine correspondence, is removed by deterministic CDR rebuild precisely because the control does not judge the lure: every inbound attachment is rebuilt to the format's known-good specification and stripped of active content, however convincing the email around it is. The Email CDR Relay places that rebuild on the mail path before delivery.

    Content Disarm and ReconstructionEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • retail

    Source: The Korea Herald · Source: Security Affairs

  4. Email attachmentHigh impact

    Korea Hydro & Nuclear Power Co.: Nuclear operator hit by thousands of spear-phishing emails carrying weaponised HWP documents

    Attackers targeted Korea Hydro and Nuclear Power with a mass spear-phishing wave in December 2014, then leaked reactor blueprints, manuals and personal data of about 10,000 employees online alongside threats against the plants. The prosecutors' joint investigation concluded in March 2015 that the malicious code matched the Kimsuky malware family attributed to North Korea.

    The documented vector. Hangul Word Processor (HWP) documents exploiting a parser vulnerability to drop a disk-wiping payload. Between 9 and 12 December 2014, attackers sent 5,986 phishing emails containing malicious code to 3,571 KHNP employees, figures published by the Seoul Central District Prosecutors' Office joint investigation. Contemporaneous technical analysis documents the carrier as HWP documents exploiting a Hangul Word Processor vulnerability and delivering a master boot record wiper.

    How this class of vector is removed

    This class of vector, a document weaponised against its own parser, is removed by deterministic CDR rebuild: the file is reconstructed to the format's known-good specification, so a document built to trigger a parser flaw does not survive the rebuild intact, and no prior signature for the exploit is needed. The Email CDR Relay applies the rebuild to inbound attachments before delivery, and Foresight scores structural anomalies of exactly this kind, malformed construction that exists to exploit, before anything runs.

    Content Disarm and ReconstructionEmail CDR RelayForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight

    • energy

    Source: Reuters · Source: Trend Micro · Source: 38 North

Scope

How to read this page

Every event on this page meets three tests before it is published. It is documented by reliable public sources: a regulator, an official inquiry, the affected organisation's own disclosure, or reputable press with named confirmation, and each entry links to those sources. The initial access or payload delivery travelled as a file, as the public record states it. An email is itself a file, so malicious code in a message and deceptive-hyperlink phishing carried by a message both count; credential attacks and pure network exploits are excluded. And the prevention analysis is conditional: where we say a capability removes a class of vector, that is a statement about how the control treats that class of content, not a claim about what any organisation ran, and not a judgement on the people who dealt with the incident.

This page is a working reference, not an incident report or legal advice. Details reflect the public record on the review date and organisations named here are cited from that record alone.

Elsewhere in the region

Other APAC territories

Files cross your boundary every day