Wednesday, September 16, 2026

7.4 Million ‘Hacking Attempts’ a Day... Cyberattacks on Public Institutions Surge

Input
2026-09-16 14:25:13
Updated
2026-09-16 14:25:13
File photo. Yonhap News Agency

[Financial News] Cyberattacks targeting the public sector, including central government agencies and local governments, have surged this year. Attacks detected by security equipment surpassed last year’s annual total in just seven months, while the number of incidents confirmed as actual attacks by officials reached nearly twice the level recorded during the same period last year. As attack attempts continue to rise and cases emerge in which breaches were discovered only months or even years later, calls are growing to reassess the public sector’s incident detection and response systems.
According to data obtained on the 16th by Park Jung-hyun, a lawmaker of the Democratic Party of Korea on the National Assembly’s Security and Public Administration Committee, security equipment at 44 central administrative agencies and 17 metropolitan local governments automatically detected 1.57 billion cyberattacks from January through July this year. That amounts to approximately 7.4 million attacks per day. In just seven months, the figure was about 33% higher than the 1.17965 billion attacks detected throughout last year.
The number of “confirmed cases”—incidents that officials determined to be actual attacks after filtering out false positives following automatic detection—reached 353,748. That was nearly twice the 173,053 cases calculated by simply converting last year’s annual total into a seven-month figure. The number of confirmed cases can vary not only with the increase in attack attempts but also depending on the level of monitoring and verification conducted by each institution.
The increase was particularly pronounced among central government agencies. Confirmed cases at central agencies rose from 156,269 in 2022 to 161,214 in 2023, 247,141 in 2024 and 251,720 last year. This year, the total had already reached 317,726 by July, equivalent to 126.2% of last year’s full-year figure.
By institution, the Ministry of the Interior and Safety (MOIS) recorded the highest number, at 57,442 cases. It was followed by the National Tax Service (NTS) with 43,845, the Anti-Corruption and Civil Rights Commission (ACRC) with 26,373, the Korean National Police Agency with 23,233 and the Ministry of Data and Statistics with 16,440. Of the 44 central administrative agencies surveyed, 19 had already exceeded their full-year totals from last year in the first seven months of this year.
A similar trend appeared among metropolitan local governments. The 17 metropolitan local governments recorded a combined 36,022 confirmed cases from January through July this year, about 1.4 times the 26,217 cases obtained by simply converting last year’s annual figure into a seven-month total. Eleven of the 17 local governments exceeded their totals for the same period last year. Gangwon State saw the sharpest increase, rising from 4,221 to 10,318 cases.
The increase in attacks has also led to actual damage in a number of cases. From 2022 through July this year, 16 hacking incidents occurred at central government agencies and two at local governments.
In 2022, the Ministry of Foreign Affairs (MOFA) suffered a hacking attack, while the Ministry of Employment and Labor (MOEL) was hit by a ransomware attack. The official YouTube channel of the National Museum of Modern and Contemporary Art, Korea (MMCA), under the Ministry of Culture, Sports and Tourism (MCST), was hacked, and a malware infection occurred between servers at the Rural Development Administration (RDA). The following year, MCST was targeted in a web vulnerability attack, resulting in the personal information of 879 users being leaked.
The problem is not limited to the breaches themselves; cases in which attacks went undetected for extended periods have also continued to emerge. Personal information belonging to 4.62 million people was stolen from the server of Seoul’s public bicycle service, “Ttareungi,” but the breach was not discovered until two years later.
The On-nara System, the Ministry of the Interior and Safety’s employee work system, was exposed for about three years from September 2022 to attacks believed to have been carried out by a North Korean hacking group. The damage was discovered only later. In the process, personal information was also leaked from the academic administration system of the Korea National University of Arts, affecting more than 18,000 enrolled students, and from the “119 Gosi” firefighter recruitment website, affecting more than 50,000 applicants.
Cybersecurity incidents have also increased in the private sector. According to the Korea Internet & Security Agency (KISA), 2,383 cyber incident reports were filed in the private sector last year, the highest number on record. A further 1,236 incidents were reported in the first half of this year, up 19.5% from the same period last year.
In October last year, the government announced a comprehensive interagency information security plan and began inspecting more than 1,600 critical systems in the public, financial and telecommunications sectors. However, critics say it remains difficult to assess the scale of attacks and damage consistently because central government agencies and local governments within the public sector compile cyberattack statistics according to different standards.
Park Jung-hyun said, “The bigger problem is that attacks are increasing, yet even after incidents occur, authorities remain unaware for months or years. We must first reassess the incident detection, reporting and management systems covering both central government agencies and local governments.”

[email protected] Yoon Hong-jip Reporter