Hacking Attempts Targeting Government Systems More Than Double in a Year
- Input
- 2026-10-05 16:30:37
- Updated
- 2026-10-05 16:30:37

Data obtained from the National Information Resources Service by Choi Hyung-du, a People Power Party lawmaker on the Science, ICT, Broadcasting, and Communications Committee of the National Assembly, showed that hacking attempts targeting central government ministries increased from 80,554 in 2023 to 161,208 in 2024, more than doubling.
The figure reached 69,982 in the first half of last year. The data covered approximately 5,300 systems operated by 52 central government ministries managed by the National Information Resources Service (NIRS).
Attacks targeting government systems are rising rapidly. From 2020 through June last year, there were 634,090 hacking attempts against systems operated by 52 central government ministries. In 2024, the number reached 161,208, more than double the 80,554 recorded the previous year.
Actual intrusions are also spreading across core national systems. Actors presumed to be the North Korean hacking group Lazarus Group infiltrated the court computer network for more than two years, from before January 2021 through February 2023, and were found to have exfiltrated 1,014GB of data. Documents confirmed to have been leaked included handwritten statements, marriage certificates and medical certificates. The documents also contained sensitive information, including resident registration numbers, financial information and military service records.
The Ministry of National Defense's military medical imaging storage system (PACS) also experienced anomalous access, while the Ministry of Foreign Affairs' (MOFA) Korea National Diplomatic Academy (KNDA) online education system was subject to unauthorized access for an extended period. The Ministry of the Interior and Safety's (MOIS) On-nara System and Government24, the Ministry of SMEs and Startups' Everyone's Startup platform, the Rural Development Administration (RDA) and the Institute for Information and Communications Technology Planning and Evaluation (IITP) were no exception.
Hacking accounted for 29 cases of personal information leaks at public institutions, while negligence in work and other causes accounted for 67. This means that a significant number of public-sector incidents stemmed not from unavoidable external attacks but from lax management.
Choi said, "Whenever an incident occurs at a private company, the government strongly demands security investment and preventive measures, vulnerability management, incident detection and response, and even management accountability for executives. If the government demands the highest level of management from the private sector but ends public-sector incidents with an explanation that they are 'victims of external attacks,' citizens may feel that different standards of accountability are being applied. The starting point for cybersecurity in the public sector is for the government itself to first uphold the level of protection it demands of citizens."
[email protected] Yeon Ji-an Reporter