145 Cases Reported, Putting Year on Track for Record High
Attacks Spread Across Multiple Industries
AI Automation Adds to Growing Threat

The number of ransomware incidents reported in South Korea during the first half of the year rose nearly 80% from a year earlier, highlighting how ransomware is becoming a growing business risk across industries.
According to data from the Korea Internet & Security Agency (KISA) obtained by Electronic Times on Tuesday, companies reported 145 ransomware incidents in the first half of the year on a preliminary basis, up 76.8% from 82 cases a year earlier. The figure already exceeds half of last year's annual total of 274 cases, putting this year's total on track to reach a record high.
The actual number of ransomware incidents is likely higher because some companies did not report attacks, creating a gap between official figures and the full extent of the damage.
KISA did not identify the companies involved but said ransomware attacks were reported across all industries.

The attacks targeted not only consumer-facing companies handling large volumes of personal data but also business-to-business firms, including manufacturers.
Kyowon Group was hit by a ransomware attack in January. The attack affected systems at major affiliates, including Kumon Learning and Red Pen, and encrypted about 600 virtual servers. The company also found signs that data had been leaked and reported the incident to the relevant authorities. An investigation is under way.
The pharmaceutical industry also suffered IT disruptions and data leaks. Hyundai Pharmaceutical said its drug ordering, distribution and enterprise resource planning (ERP) systems were disabled in April. International Pharmaceutical also reported a hacking attack that month, resulting in partial data leaks and IT disruptions.
Ransomware groups also claimed attacks against manufacturers. In March, the Everest ransomware group said it had stolen 1.1 terabytes of data from Hyundai Elevator, including manufacturing drawings and elevator safety certificates, and published part of the stolen files. Companies including Comico, Daechang Solution and Doosan Bobcat were also listed as victims on ransomware groups' dark web leak sites.
Companies in the IT and professional services sectors were also targeted, including smart factory and digital twin solutions provider STNI, data integration and cybersecurity company Bytec System, and intellectual property law firm Re International.
Park Myung-seo, a professor in the Department of Convergence Security at Hansung University, said ransomware operators are no longer limited to encrypting files but now steal data and use the threat of public disclosure to extort victims. He added that recent attempts to automate the entire attack process using artificial intelligence are further increasing the threat.