A coordinated cyber attack disabled thousands of computers at South Korean broadcasters KBS, MBC, and YTN and at Shinhan Bank and Nonghyup Bank. Malware erased data on hard drives, leaving machines unable to start.
What happened
- The attack struck on the afternoon of 20 March 2013, disrupting banking services and broadcasters’ internal systems.
- Affected screens displayed boot errors after the malware deleted files and operating system data.
- In April 2013, South Korean investigators concluded that North Korea’s military-run Reconnaissance General Bureau was responsible, citing reused malware and overlapping IP addresses from earlier attacks.
- Investigators said the malware had been planted in some organisations months before it was triggered.
Why it mattered
The incident was one of the most prominent destructive attacks of its time, showing that wiper malware could disrupt financial services and media at national scale. It also highlighted the long dwell time attackers can achieve before striking.
Lessons for organisations
Organisations should keep tested, offline backups and plan for recovery from destructive attacks, not just data theft. Monitoring for unusual activity on central software distribution and patch management systems can help detect attackers preparing a large-scale strike.
Sources: NBC News, Computer Weekly
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.