Reports of domestic cyber intrusion incidents rose about 20 percent in the first half of this year from a year earlier. [Photo: Shutterstock]

Reports of domestic cyber intrusion incidents rose about 20 percent in the first half of this year from a year earlier. Damage from DDoS attacks by international hacktivists and ransomware increased sharply, and attacks abusing generative AI and open source also emerged as key threats.

The Ministry of Science and ICT and the Korea Internet & Security Agency (KISA) on July 30 released a report titled "Domestic Cyber Threat Trends in the First Half of 2026" containing those findings.

The report said KISA received 1,236 incident reports in the first half, up 19.5 percent from 1,034 a year earlier. That was down 8.4 percent from 1,349 in the second half of last year, the highest on record. The ministry and KISA assessed that reporting surged in the second half of last year as companies became more aware of reporting following intrusion incidents involving the three telecom operators last year.

DDoS and ransomware reports both increase

By type, the rise in DDoS and ransomware reports stood out.

Reports of DDoS attacks rose 56.7 percent to 373 from 238 a year earlier. Their share of total incidents increased to 30.2 percent from 23 percent over the same period. Ransomware reports came to 145, up 76.8 percent from 82 a year earlier. Ransomware accounted for 72.1 percent of the 201 reports of malware infections.

Server hacking still accounted for the largest share, but the number of reports fell 8.3 percent to 487 from 531 a year earlier.

The ministry and KISA worked with experts from 15 information security companies at home and abroad to classify key cyber threats in the first half into five types. The main threats identified included security threats tied to the spread of generative AI, open-source supply-chain attacks, DDoS attacks by international hacktivists, double extortion ransomware, and personal data leaks exploiting application programming interfaces (APIs) and account takeovers.

Attack surface expands with spread of AI agents; supply-chain attacks also grow more sophisticated

AI was assessed as boosting productivity in security work such as vulnerability detection, malware analysis and code review, while also reducing attackers' preparation time and costs. The analysis said AI agents are connected to external systems such as email, code repositories, cloud and collaboration platforms and autonomously perform tasks, widening the attack surface. Risks cited included malicious prompt injection, abuse of privileges, leakage of sensitive information, calling malicious tools and incorrect automatic execution.

The ministry and KISA recommended centrally managing API keys and tokens and service accounts used by AI services and minimizing the use of long-term credentials. They also stressed the need for sensitive information filtering, management of input and output logs, and procedures for staff verification of AI-generated code and automated actions.

In the open-source ecosystem, attacks are increasing that steal developer accounts and access tokens to abuse legitimate software and distribution systems.

Attackers use information-stealing malware to steal passwords for GitHub, npm and PyPI accounts, personal access tokens and cloud access keys. They then abuse administrative privileges for legitimate projects or continuous integration and deployment (CI/CD) environments to distribute malicious packages and exfiltrate corporate information. If a single developer account or token is compromised, malware can spread in a chain to the build servers and operating environments of many companies.

Recommendations included using software composition analysis and software bills of materials (SBOM) to identify components and versions and applying multi-factor authentication to developer accounts. The ministry and KISA also said code signing, deployment approvals and detection of anomalous activity on developer devices and build servers are needed.

International hacktivists expand DDoS attacks on South Korean institutions

DDoS threats are also expanding as international hacktivist groups single out South Korean public institutions and private companies as targets. Some hacking groups were found to have warned via messenger channels of targets in South Korea or claimed they carried out actual attacks.

Their main aim is not information theft but to reduce the availability of external services and post outage screens on social networking services (SNS) to increase social confusion and psychological pressure.

Companies should establish emergency response procedures with internet service providers, cloud service providers and KISA, and link content delivery networks, web application firewalls and cloud DDoS defense services. Small and medium-sized companies can prevent such damage by using KISA's free "DDoS Cyber Shelter."

Ransomware methods that demand money in return for decryption and keeping information private continue to pose a threat across industry. As the division of labor structure of ransomware-as-a-service and initial access brokers spreads, even attackers without expertise can buy compromised accounts or remote access rights and join attacks.

The ministry and KISA stressed that critical data should be separated from operational networks and managed through immutable backups or offline backups, and that regular recovery drills should be conducted.

Personal data theft attacks are expanding from database server breaches to methods that exploit external APIs and user accounts. Attackers target weaknesses in API authentication and authorization checks or carry out credential stuffing attacks that automatically enter account information leaked in the past.

To prevent this, companies should separately review authentication and authorization systems for each API and apply multi-factor authentication, risk-based login and detection of abnormal bulk queries.

Choi Woo-hyuk (최우혁), director general for Information Security Network Policy at the Ministry of Science and ICT, said, "AI-based cyber threats are becoming a reality and sophisticated attacks targeting cloud vulnerabilities are continuing." He added, "The government will build an AI-based prevention and response system and create a cyber environment where the public can feel safe through proactive vulnerability discovery."

Keyword

#Ministry of Science and ICT #Korea Internet & Security Agency #DDoS #ransomware #SBOM
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.