South Korea Targeted by Ransomware as Damage Rises 3.3-Fold in One Year
- Input
- 2026-09-27 16:06:18
- Updated
- 2026-09-27 16:06:18

[Financial News] Nearly 6,000 companies and institutions worldwide were found to have suffered ransomware attacks in the first half of this year. The number of victims targeted in South Korea also surged more than 3.3-fold in one year.
According to the 2026 first-half ransomware trends report released by S2W on the 27th, a total of 5,984 companies and institutions were publicly listed on ransomware leak sites worldwide as victims between January and June this year.
That was an increase of 1,555 from the first half of last year. Attack frequency rose sharply year over year in every monthly statistic.
In February alone, the number of victims surged 72.9% from the same month a year earlier as a large number of new ransomware groups emerged.
South Korea was also found to be no longer a safe haven from ransomware.
The number of ransomware incidents targeting South Korean companies and institutions totaled 36 in the first half of this year, more than 3.3 times the figure recorded during the same period last year.
By attacker, a total of 119 ransomware groups were confirmed to have been active in the first half of this year.
The top 10 groups accounted for 54.3% of all attacks, representing more than half of the total.
The top 10 groups attacked an average of 325 companies each, about 13 times more than the average of 25 attacks recorded by the other 109 groups.
In addition, 44 new groups emerged in the first half alone, expanding the division of labor underpinning the ransomware-as-a-service model.
Qilin, PLAY, LockBit, Interlock and INC were identified as the five highest-risk groups among the threat organizations.
Emerging groups such as The Gentlemen, which appeared in mid-last year, rapidly expanded their influence by actively recruiting skilled hackers with the promise of high revenue-sharing rates and introducing dedicated tools to disable security solutions.
Attacks were concentrated in major developed countries with high gross domestic product (GDP).
The 10 countries with the most victims accounted for 71.7% of all victims, and every one of them ranked among the world's top 15 economies by GDP.
The United States was hit most heavily, accounting for 45.9% of all victims.
This reflects attackers' tendency to target organizations with ample financial resources and a high likelihood of paying a ransom because business disruptions can cause substantial economic damage.
By industry, manufacturing suffered the most attacks because disruptions to production processes can cause devastating losses.
Rather than relying solely on the traditional method of encrypting data on internal networks to paralyze systems, attackers have adopted multiple-extortion tactics as their standard approach, threatening to leak critical confidential data stolen in advance.
The report identified monitoring zero-day vulnerabilities in virtual private networks (VPNs) and remote-access equipment directly exposed to the internet as the top priority.
It also recommended blocking intrusion tools that forcibly disable endpoint security products and establishing an immutable backup system so that attackers cannot tamper with backup files even after infiltrating an organization.
[email protected] Jang Min-kwon Reporter