Don’t do SECURITY. Do business SECURELY.

Cyber attack wipes computers at South Korean banks and broadcasters

A coordinated attack disabled thousands of computers at three South Korean broadcasters and two banks; Seoul later blamed North Korea.

A coordinated cyber attack disabled thousands of computers at South Korean broadcasters KBS, MBC, and YTN and at Shinhan Bank and Nonghyup Bank. Malware erased data on hard drives, leaving machines unable to start.

What happened

  • The attack struck on the afternoon of 20 March 2013, disrupting banking services and broadcasters’ internal systems.
  • Affected screens displayed boot errors after the malware deleted files and operating system data.
  • In April 2013, South Korean investigators concluded that North Korea’s military-run Reconnaissance General Bureau was responsible, citing reused malware and overlapping IP addresses from earlier attacks.
  • Investigators said the malware had been planted in some organisations months before it was triggered.

Why it mattered

The incident was one of the most prominent destructive attacks of its time, showing that wiper malware could disrupt financial services and media at national scale. It also highlighted the long dwell time attackers can achieve before striking.

Lessons for organisations

Organisations should keep tested, offline backups and plan for recovery from destructive attacks, not just data theft. Monitoring for unusual activity on central software distribution and patch management systems can help detect attackers preparing a large-scale strike.

Sources: NBC News, Computer Weekly

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights