Seoul: The interior ministry announced it has bolstered security measures for online government systems following the detection of hacking attempts on the government's administration platform.
According to Yonhap News Agency, the decision came two months after Phrack, a cybersecurity publication, reported in August that several South Korean government branches and companies were targeted by hackers. In mid-July, signs were confirmed through the National Intelligence Service (NIS) that an external internet PC had accessed the Onnara system via the Government-Virtual Private Network (G-VPN).
The Onnara system serves as the government's online work platform, managing official documents and handling internal workflow. In response to the hacking signs, the ministry has implemented enhanced security measures, requiring officials to undergo additional authentication procedures when connecting to G-VPN for remote work.
The ministry further reported that the government public key infrastructure (GPKI) certificates of 650 officials were presumed to have been targeted. While most of these certificates had expired, three that remained valid were invalidated as of August 13. Officials suspect that the leakage of certificate information resulted from user negligence.
To counter such vulnerabilities, the ministry plans to replace the GPKI-based authentication system with a biometric system for public officials accessing the government's internal administrative system.
Earlier reports by Phrack indicated that the North Korean hacking group Kimsuky was responsible for the attack. Signs of hacking were detected in various government sectors, including the interior and foreign ministries, the military, and major companies such as Kakao Corp., Naver Corp., KT Corp., and LG Uplus Corp.