Skip to main content

Hacking attack on South Korea traced to China, officials say

By Michael Pearson. K.J. Kwon and Jethro Mullen, CNN
March 21, 2013 -- Updated 0241 GMT (1041 HKT)
STORY HIGHLIGHTS
  • NEW: Attack traced to IP address in China, officials say
  • North Korea has staged similar attacks in the past, expert says
  • Banks, broadcasters targeted; government networks unaffected, Yonhap reports
  • South Korean military steps up its cyberdefense efforts in response

Seoul, South Korea (CNN) -- The suspected cyberattack that appeared to target South Korean banks and broadcasters Wednesday originated from an IP address in China, South Korea's Communications Committee said in a statement Thursday.

The attack damaged 32,000 computers and servers of media and financial companies, the committee said.

South Korean officials are analyzing the cause and are working to prevent any further damage, the committee said.

The attack infected banks' and broadcasters' computer networks with a malicious program that slowed or shut systems down, officials and the semiofficial Yonhap News Agency said.

Suspicion immediately fell on North Korea, which has recently renewed threats to go to war with the South amid rising tensions over Pyongyang's nuclear weapons and missile testing and international efforts to stop them.

South Korea's military stepped up its cyberdefense efforts in response to the widespread outages, which hit nine companies, Yonhap reported, citing the National Police Agency.

Government computer networks did not seem to be affected, Yonhap cited the National Computing and Information Agency as saying.

Experiencing a potential cyberattack
Cybersecurity concerns for China, U.S.

A joint team from government, the military and private industry was responding, a presidential spokeswoman said, according to Yonhap.

A South Korean official close to the investigation told CNN that malicious computer code spread through hacking caused the outages.

How the hackers got in and spread the code remains under investigation, and analysts are examining the malware, the official said.

U.S. flies B-52s over South Korea

Wednesday's attack is consistent with what North Korea has done in the past, said Adam Segal, a cybersecurity expert with the Council on Foreign Relations.

"It's happened before in similar circumstances where there have been tensions on the peninsula," Segal said.

South Korea has accused the North of similar hacking attacks before, including incidents in 2010 and 2012 that also targeted banks and media organizations.

The outages come amid heightened tensions on the Korean Peninsula, with the North angrily responding to a recent U.N. Security Council vote to impose tougher sanctions on Pyongyang after the country's latest nuclear test last month.

Last week, North Korea invalidated its 60-year-old armistice with the South. It has threatened to attack its neighbor with nuclear weapons and has also threatened the United States.

The armistice agreement, signed in 1953, ended the three-year war between North and South but left the two nations technically in a state of war.

The saber-rattling prompted the United States to deploy B-52 bombers to conduct high-profile flyovers of its South Korean ally and announce that it would deploy new ground-based missile interceptors on its West Coast against the remote possibility that North Korea could strike the United States with long-range weapons.

Under threat, South Koreans mull nuclear weapons

Last week, North Korea complained that it was the victim of "intensive and persistent virus attacks" from the United States and South Korea, according to KCNA, the official North Korean news agency.

Yonhap said Wednesday's outages affected three broadcasters, four banks and two insurance companies.

The three broadcasters -- KBS, MBC and YTN -- reported varying levels of trouble containing the virus. While the networks remained on the air, cable network YTN said editing equipment had been affected and it expected to experience broadcasting problems, Yonhap reported.

Computer networks stopped working entirely at three banks -- Shinhan, Nonghyup and Jeju -- around 2 p.m. Wednesday, Yonhap reported, citing the National Police Agency. Another financial institution, Woori Bank in Seoul, reported it was able to fend off a hacking attack about the same time.

The banks that were affected reported problems with a variety of systems, including Internet banking, ATMs and telecommunication services, and some branches stayed open late because of the slowdown, Yonhap said.

CNN's K.J. Kwon reported from Seoul, Jethro Mullen reported from Hong Kong and Michael Pearson wrote from Atlanta. Judy Kwon and Hilary Whiteman in Hong Kong contributed to this report.

ADVERTISEMENT
Part of complete coverage on
July 30, 2014 -- Updated 1458 GMT (2258 HKT)
While aspects of the fighting in Gaza resemble earlier clashes, this time feels different, writes military analyst Rick Francona.
July 30, 2014 -- Updated 1438 GMT (2238 HKT)
The death of an American from Ebola fuels fears of the further global spread of the virus.
July 30, 2014 -- Updated 1206 GMT (2006 HKT)
Nearly two weeks after MH17 was blown out of the sky, Dutch investigators have yet to lay eyes on the wreckage. How useful will it be now?
July 30, 2014 -- Updated 1510 GMT (2310 HKT)
The U.S. and EU are imposing new sanctions on Moscow -- but will they have any effect?
This looks like a ghost ship, but it's actually the site of a tense international standoff between the Philippines and China.
July 26, 2014 -- Updated 1555 GMT (2355 HKT)
The reported firing of artillery from Russian territory is a sign Vladimir Putin has escalated the Ukraine battle, says CNN's military analyst Rick Francona.
July 27, 2014 -- Updated 0846 GMT (1646 HKT)
The young boy stops, stares, throws ammunition casings at the reporter's feet without a word.
July 26, 2014 -- Updated 0048 GMT (0848 HKT)
Sure, Fido is a brown Lab. But inside, he may also be a little green.
July 28, 2014 -- Updated 1303 GMT (2103 HKT)
Photograph of an undisclosed location by Patrycja Makowska
Patrycja Makowska likes to give enigmatic names to the extraordinarily beautiful photographs she shoots of crumbling palaces.
July 23, 2014 -- Updated 0804 GMT (1604 HKT)
When the Costa Concordia and its salvage convoy finally depart Giglio, the residents will breathe a sigh of relief -- and shed a tear.
CNN joins the fight to end modern-day slavery by shining a spotlight on its horrors and highlighting success stories.
Browse through images from CNN teams around the world that you don't always see on news reports.
ADVERTISEMENT