South Korea’s cyber threat was visible on two fronts by September 18, 2026: government systems were registering enormous numbers of suspected attacks, while breaches at public services and private companies exposed personal information. Those figures describe different things. An alert, a reported incident, a compromised account and an affected person should not be counted as interchangeable.
2
7
41
50
Government alerts rose sharply—but they were not confirmed breaches
Data obtained by Democratic Party lawmaker Park Jung-hyun showed that security systems at 44 central government agencies and 17 metropolitan and provincial governments flagged 1.57 billion suspected attacks from January through July 2026. That is about 7.4 million a day and 33% more than the total recorded during all of 2025. The figures measure suspected activity detected by security systems, not 1.57 billion successful intrusions.
2
Separately, a hacker suspected of being Chinese claimed to have attacked 88 government bodies and about 20 companies over six days and taken financial, personal and military information. The person reportedly notified the science ministry, KISA, financial regulators, the Defense Ministry and the National Intelligence Service in early September. Authorities were examining the material supplied, but neither the claimed intrusions nor the extent of any damage had been verified. The allegation should not be added to the confirmed-breach count.
34
Breaches reached a public service and major companies
The consequences were clearer in the case of Seoul’s Ttareungi bike-sharing service. Two teenagers were accused of breaking into its server in June 2024 and leaking information associated with approximately 4.62 million users. In August 2026, 23 users sued the operator, alleging inadequate safeguards and delayed disclosure. Those are allegations in a lawsuit, not findings that establish why the breach was discovered or disclosed when it was.
9
7
The private-sector cases varied in what investigators had established. Coupang suffered a data breach in 2025 that was followed by numerous South Korean investigations; a U.S. House committee’s later allegation that the company was treated discriminatorily remains an allegation.
32 Lotte Card and KT were both identified in reporting on 2025 hacking incidents. Reporting on KT described unauthorized small payments involving subscribers and an unregistered small base station that accessed its internal network.
18
35
The largest clearly quantified example in the supplied reporting is TVING. A joint investigation announced in September 2026 found 39.54 million accounts and 361 technical assets, including source code, compromised. Reporting said the account total included active, dormant and former members’ accounts, with names, birthdates, phone numbers and identification codes among the exposed information. It does not establish that 39.54 million distinct people were affected.
41
38
Reported incidents provide a second measure of the trend
KISA figures supplied to a lawmaker recorded 8,565 cyber-infringement incident reports from 2021 through June 2026. Annual reports rose from 640 in 2021 to 1,142 in 2022, 1,277 in 2023, 1,887 in 2024 and 2,383 in 2025; another 1,236 were reported in the first half of 2026. These are incident reports, not the automated government alerts counted in Park’s January–July figures.
50
2
After the TVING findings, President Lee Jae-myung called on September 11 for tighter data-protection obligations and corporate accountability. The cited report describes that instruction; it does not establish that a law authorizing fines of up to 10% of revenue had taken effect. The available sources also do not substantiate a precise confirmed-attack total for the government systems, the share concentrated on central agencies, the proportion of KISA reports involving small and medium-sized businesses, or a full government incident-reporting and criminal-referral procedure.
36
2
50